The Role
- Collaborate with application development teams to design secure solutions and embed security throughout the software development lifecycle.
- Lead threat modelling and architecture review sessions to identify and mitigate security risks during design and development phases.
- Support Shift-Left initiatives by integrating security early in the SDLC, with hands-on experience in SAST and IAST tools.
- Manage and coordinate penetration testing activities to validate application security posture.
- Assess vulnerabilities and cyber risks in third-party software and components, maintaining accurate and current SBOMs.
- Advocate for DevSecOps principles and promote secure SDLC practices across development, support, and engineering teams.
- Partner with Cyber Security leadership to enhance tools, processes, culture, and overall service delivery.
Requirements
- A bachelor's degree in computer science or related field and/or 2+ years of software development experience, together with demonstrated experience as an application security engineer or equivalent.
- Secure coding practices to avoid common security vulnerabilities such as those in the OWASP Top Ten: SQLi, XSS, and CSRF.
- Security testing frameworks and platforms such as OWASP ASVS and Snyk.
- Securing Azure DevOps, CI/CD automation pipelines.
- Developing threat models and facilitating threat modelling workshops with developers and Leads
- Familiarity with web proxies such as Burp, OWASP ZAP, or Fiddler.
- Experience in at least one of the following programming and scripting languages: .NET, Python, and JavaScript.
- Demonstrable skills in assessing, analysing, and resolving complex client- and stakeholder-related queries, utilizing all relevant sources of information, media, and stakeholder channels, data, reporting, systems, and/or databases.
- Exposure to core banking systems, Open Banking, or digital wallet platforms. added advantage.
- Having prior work experience in the banking industry will be anextra advantage.
Benefits
Hybrid work model, Flexible working culture, foreign exposure & more celebrations... (T&C applied).
Generating Apply Link...