MUFG Investor Services

Application Security Engineer (Experienced in applications security focusing on red, blue or purple team activities)

MUFG Investor Services
Apply
2 months ago
Dublin, IrelandSenior

Responsibilities

  • Act as a security champion and promote secure-by-design practices across the business.
  • Identify and analyze web application vulnerabilities and provide remediation guidance to engineering teams.
  • Manage application security platforms and maintain coverage, compliance, and remediation tracking.
  • Conduct threat modeling and application architecture reviews to identify risks early in the SDLC.
  • Implement application security controls and preventative measures.
  • Implement and manage SAST and SCA tooling across application repositories.
  • Scale automated DAST solutions to improve testing coverage and runtime security visibility.
  • Perform penetration testing on internally developed applications and coordinate external penetration tests.
  • Review third-party application configurations and hardening, and validate remediation of security issues.
  • Collaborate closely with development, IT, and DevOps teams to resolve security issues.
  • Create custom security tooling, scripts, and CI/CD pipeline jobs for security reviews and scans.

Requirements

  • Experience in application security with a focus on red-team, blue-team, or purple-team activities.
  • Experience in software development or contributing to open-source projects.
  • Experience with DAST tools such as Burp Suite or OWASP ZAP.
  • Experience with SAST and SCA tools such as Snyk, Veracode, or Checkmarx.
  • Proficiency in one or more of Python, JavaScript, .NET, or Java.
  • Strong understanding of open-source and third-party library vulnerabilities.
  • Knowledge of the software development life cycle and agile development practices.
  • Experience testing REST and GraphQL APIs.
  • Experience with GitLab or GitHub, Datadog, Jira, Docker, and development IDEs.
  • Experience working with development and DevOps teams to resolve security issues.
  • Experience conducting security-focused code reviews and creating custom security tooling or scripts.
  • Preferred experience in the financial sector or another heavily audited industry.
  • Preferred experience with AWS services such as WAF and Cognito, Infrastructure as Code, Kubernetes, containers, OpenID Connect, OAuth, identity providers, and security-focused CI/CD pipeline jobs.

Benefits

  • Collaborative and connected team culture.
  • Learning and development opportunities.
  • Innovation-focused environment and client-focused work.
  • Equal opportunity employer.

Tech Stack

Categories

MUFG Investor Services

About MUFG Investor Services

1,001-5,000 employees
Contact me