обновлено 6 дней назад
Application Security Engineer (Purple Team)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer (Purple Team): Enhancing the security of applications, APIs, and infrastructure through preventative controls, security testing, and automation with an accent on threat modelling, SAST/SCA, DAST, and penetration testing. Focus on identifying and remediating vulnerabilities, reviewing application architectures and third-party software, and integrating security controls into development workflows.
Location: Dublin, Ireland
Company
provides asset servicing and operational solutions for public and private funds as part of Mitsubishi UFJ Financial Group.
What you will do
- Promote secure-by-design practices as an application security champion.
- Identify, analyze, and remediate web application, API, infrastructure, and third-party software vulnerabilities.
- Manage application security platforms and implement SAST, SCA, and DAST tooling across application repositories.
- Conduct threat modelling, architecture reviews, penetration testing, and security-focused code reviews.
- Provide remediation guidance to engineering, IT, development, DevOps, and third-party teams.
- Coordinate external penetration tests and validate remediation of identified issues.
Requirements
- Experience in application security with red, blue, or purple team activities.
- Experience with DAST tools such as Burp Suite or OWASP ZAP and SAST/SCA tools such as Snyk, Veracode, or Checkmarx.
- Proficiency in Python, JavaScript, .NET, or Java.
- Strong knowledge of REST and GraphQL API security, SDLC, agile methodologies, and open-source vulnerability analysis.
- Experience with GitLab or GitHub, Datadog, Jira, Docker, IDEs, and collaboration with development and DevOps teams.
- Experience creating custom security tooling, scripts, or CI/CD security jobs.
Nice to have
- Experience in financial services or another heavily audited industry.
- Experience with AWS services, Infrastructure as Code, Kubernetes, and containers.
- Knowledge of OpenID Connect, OAuth, and identity providers.
Culture & Benefits
- Connected and collaborative working environment.
- Focus on innovation, client service, and learning and development.
- Permanent full-time employment within a global financial group.
Hiring process
- Only candidates progressing to the interview stage will be contacted.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →