Назад
Company hidden
3 часа назад

Product Security Engineer (Fintech)

80 000 - 105 000
Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
UK/Singapore/US +2 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (Fintech): Building and strengthening application security for cloud-native banking and payments technology with an accent on threat modeling, vulnerability assessment, data privacy, and secure software development. Focus on designing production-scale security controls, automating security tooling, and protecting distributed systems against complex application security risks.

Location: Lisbon, Portugal; on-site four days per week

Salary: €80K–€105K per year

Company

hirify.global develops cloud-native core banking and payments technology designed to replace legacy banking systems.

What you will do

  • Improve product security through strategic planning and collaboration with development and infrastructure teams.
  • Design production-scale application security for web-based banking products.
  • Review data privacy and financial regulatory requirements in functional and non-functional designs.
  • Conduct design reviews, threat modeling, vulnerability assessments, security testing, and code reviews.
  • Provide security and privacy expertise throughout the software development lifecycle while mentoring and educating development teams.
  • Contribute to security strategy, tooling selection, and development of automated security tools.

Requirements

  • Expertise in a programming language such as Python, Go, or Java.
  • Experience with security in DevOps environments and distributed systems at scale.
  • Experience in web application penetration testing and security tooling, including Burp Proxy, web and network scanners, and static code analyzers.
  • Experience automating and integrating security tools and creating security tooling.
  • Knowledge of cloud and container technologies such as AWS, GCP, Kubernetes, and Docker.
  • Experience with security design reviews, threat modeling, risk assessments, and application security issues.

Nice to have

  • Professional security qualifications such as CISSP, Offensive Security, or SANS Institute certifications.
  • Contributions to the security community through research, blogging, or presentations.
  • Awareness of the Data Protection Act, ISO 27001, and PCI-DSS.

Culture & Benefits

  • Permanent full-time employment with a voluntary pension plan matching contributions up to 5%.
  • Private healthcare and comprehensive life insurance.
  • 25 days of annual leave plus public holidays and two charity days.
  • Daily meal allowance, subsidised sports and hobby clubs, and access to learning materials and courses.
  • Modern equipment, snacks and drinks, and an environment that supports learning and professional development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →