15 hours ago
Edinburgh, United KingdomSenior
Responsibilities
- Design, implement, and maintain internal CI/CD pipelines and automation tooling for vulnerability management, security assurance, reporting, and software development workflows.
- Develop and maintain source-code, repository, dependency, and container-security integrations across the software delivery lifecycle.
- Build and maintain backend services and APIs for security scanning, vulnerability analysis, event processing, reporting, and internal-platform integration.
- Monitor automated build and security-validation processes, analyze findings, and provide guidance or implement fixes.
- Evaluate vulnerabilities, assess exploitability and risk, investigate false positives, and support or develop remediation solutions.
- Maintain vulnerability-processing workflows and integrations with issue-management systems such as Jira.
- Develop security reports and dashboards covering vulnerabilities, remediation status, security risks, and compliance.
- Work with containerized applications and cloud-native environments including Kubernetes, OpenShift, and Oracle Cloud Infrastructure.
- Coordinate security-related actions across teams and contribute to technical discussions and secure software development practices.
Requirements
- University degree in Information Technology, Computer Science, Mathematics, Physics, or a related technical discipline.
- Strong experience designing, implementing, and maintaining internal CI/CD pipelines, developer tooling, and automation platforms.
- Senior-level software engineering expertise with hands-on experience in several of Java, Spring Boot, Python, JavaScript, TypeScript, Gradle, Jenkins, and Groovy.
- Experience with backend services, APIs, service integration, event-driven architectures, and messaging technologies.
- Strong understanding of containerized applications and practical experience with Docker and Kubernetes and/or OpenShift.
- Knowledge and practical experience with Oracle Cloud Infrastructure and cloud-native technologies is highly desirable.
- Deep understanding of application security, security standards, secure software development, vulnerability management, and security-scanning tools.
- Experience integrating security tooling into CI/CD and software delivery pipelines.
- Understanding of software composition analysis, source-code security scanning, container security, and vulnerability lifecycle management is advantageous.
- Strong analytical, problem-solving, communication, collaboration, and attention-to-detail skills.
- Experience or exposure to financial markets and financial products is advantageous.
Benefits
- Hybrid and flexible working arrangements are available for most employees.
- The company promotes an inclusive, equal-opportunity culture and supports work-life balance.
- The role is based within Avaloq’s global office environment.
Tech Stack
Categories
About Avaloq
Avaloq develops core banking and digital wealth management platforms and provides banking-operations outsourcing for financial institutions, delivered via cloud SaaS, BPaaS, or on-premises deployments. Its clients include private, retail and investment banks; more than 170 institutions use its systems. Founded in 1985 and headquartered in Zürich, Avaloq is a subsidiary of NEC Corporation.
