Application Security - DAST API Security Posture
Hạn nộp hồ sơ: 15/09/2026 (Còn 34 ngày)
Ứng tuyển sớm để được ưu tiên
Kết nối với Nhà tuyển dụng để tìm hiểu thông tin và gia tăng cơ hội trúng tuyển
Nhà tuyển dụng đang online
Mô tả công việc
Tóm tắt công việc
We're seeking a key member who have had a proven track record of running critical shared application platforms in a production cloud environment. The purpose is to improve the security of NAB applications and DevOps practices through standards, education & awareness with developers, consultation on best practices, development of secure reusable capabilities, and supporting review and remediation of vulnerabilities
YOUR RESPONSIBILITIES
Ensure respective policy, standards, processes and controls meet regulator and compliance expectations
Support meeting departmental budgets
Ensure controls and timely completion of findings and treatment plans
Ensure and drive security outcomes relating to software development and devops practices
Ensure and optimize dynamic application security testing tools and API security solutions
Ensure tools are configured correctly and operating efficiently to provide maximum protection
Utilise a variety of testing methodologies and tools to uncover potential threats and risks while eliminating the false positives
Enhancing and updating application dynamic testing methodologies, processes and standards documentation
Document and evangelise secure API design patterns
Build and promote code libraries for API security
Automate continuous security testing of APIs
Consult with development teams to educate and improve awareness of secure standards and practices
Support and champion the development of secure and reusable code across development teams to eliminate gaps identified in dynamic and API security testing
Develop or use tooling to identify security vulnerabilities within our web application footprint
Produce clear and accurate reporting for stakeholders
Work with Cyber Engineering & Platforms teams to expand coverage and integrate dynamic and API security testing
Work with Detection & Response and other Cyber Security teams to ensure critical exposures are mitigated in a timely manner
Extend support on remediation of dynamic application testing and API vulnerabilities discovered through scanning and security testing
Help manage the organization's vulnerability intake and remediation process
Support incident response efforts as required
Stay abreast of current and emerging technologies, threats and vulnerabilities, and best practice protection methods
Research and analyse application behaviours to improve security and stability
Contribute to the evolution of the organization's application security functions and services
Other activities as required by management
THE BENEFITS AND PERKS
1. Generous compensation and benefit package
Attractive salary and benefits
20-day annual leave and 7-day sick leave, etc.
13th month salary and Annual Performance Bonus
Premium healthcare for yourself and family members
Monthly allowance for team activities
Premium welcome kit and frequent appreciation gifts
Extra benefits for long-term employees
2. Exciting career and development opportunities
Large scale products with modern technologies in banking domain
Clear roadmap for career advancement in both technical and leadership pathways
Well-structured learning and development programs (technical and soft skills)
Sponsored certificates in both IT and banking/finance
Premium account on Udemy
English learning with native teachers
Opportunity for traveling & training in Australia
3. Professional and engaging working environment
Hybrid working model and good work-life balance
Well-equipped & modern Agile office with fully stocked pantry
Special programs to improve your physical and mental health
Annual company trip and events
A solid talented team behind you - great people who love what they do
We're seeking a key member who have had a proven track record of running critical shared application platforms in a production cloud environment. The purpose is to improve the security of NAB applications and DevOps practices through standards, education & awareness with developers, consultation on best practices, development of secure reusable capabilities, and supporting review and remediation of vulnerabilities
YOUR RESPONSIBILITIES
Ensure respective policy, standards, processes and controls meet regulator and compliance expectations
Support meeting departmental budgets
Ensure controls and timely completion of findings and treatment plans
Ensure and drive security outcomes relating to software development and devops practices
Ensure and optimize dynamic application security testing tools and API security solutions
Ensure tools are configured correctly and operating efficiently to provide maximum protection
Utilise a variety of testing methodologies and tools to uncover potential threats and risks while eliminating the false positives
Enhancing and updating application dynamic testing methodologies, processes and standards documentation
Document and evangelise secure API design patterns
Build and promote code libraries for API security
Automate continuous security testing of APIs
Consult with development teams to educate and improve awareness of secure standards and practices
Support and champion the development of secure and reusable code across development teams to eliminate gaps identified in dynamic and API security testing
Develop or use tooling to identify security vulnerabilities within our web application footprint
Produce clear and accurate reporting for stakeholders
Work with Cyber Engineering & Platforms teams to expand coverage and integrate dynamic and API security testing
Work with Detection & Response and other Cyber Security teams to ensure critical exposures are mitigated in a timely manner
Extend support on remediation of dynamic application testing and API vulnerabilities discovered through scanning and security testing
Help manage the organization's vulnerability intake and remediation process
Support incident response efforts as required
Stay abreast of current and emerging technologies, threats and vulnerabilities, and best practice protection methods
Research and analyse application behaviours to improve security and stability
Contribute to the evolution of the organization's application security functions and services
Other activities as required by management
THE BENEFITS AND PERKS
1. Generous compensation and benefit package
Attractive salary and benefits
20-day annual leave and 7-day sick leave, etc.
13th month salary and Annual Performance Bonus
Premium healthcare for yourself and family members
Monthly allowance for team activities
Premium welcome kit and frequent appreciation gifts
Extra benefits for long-term employees
2. Exciting career and development opportunities
Large scale products with modern technologies in banking domain
Clear roadmap for career advancement in both technical and leadership pathways
Well-structured learning and development programs (technical and soft skills)
Sponsored certificates in both IT and banking/finance
Premium account on Udemy
English learning with native teachers
Opportunity for traveling & training in Australia
3. Professional and engaging working environment
Hybrid working model and good work-life balance
Well-equipped & modern Agile office with fully stocked pantry
Special programs to improve your physical and mental health
Annual company trip and events
A solid talented team behind you - great people who love what they do
Yêu cầu
3 years of experience working in a Application Security, consulting or related role
Delivery / execution of API security and dynamic security testing across NAB
Implement security controls across API Gateways.
Stakeholder management
Risk management and compliance
Experience in securing APIs and Dynamic/Runtime security scanning
DevOps operating model and technologies
Development skills
Vulnerability management
Working experience in Cloud technologies - AWS and/or Azure
Hands on with coding: Scripting using Java/Python
Excellent verbal and written communication skills
Experience with security tools in SAST (static code testing), SCA (software composition analysis), CSS (container security), DAST (dynamic security testing)
Tertiary qualified with a Degree in Information Technology or related.
Having a industry leading cyber security certifications will be a plus
Delivery / execution of API security and dynamic security testing across NAB
Implement security controls across API Gateways.
Stakeholder management
Risk management and compliance
Experience in securing APIs and Dynamic/Runtime security scanning
DevOps operating model and technologies
Development skills
Vulnerability management
Working experience in Cloud technologies - AWS and/or Azure
Hands on with coding: Scripting using Java/Python
Excellent verbal and written communication skills
Experience with security tools in SAST (static code testing), SCA (software composition analysis), CSS (container security), DAST (dynamic security testing)
Tertiary qualified with a Degree in Information Technology or related.
Having a industry leading cyber security certifications will be a plus
Thông tin khác
Cyber Security
DevSecOps
Security Testing
Java
CSS
Python
MS Azure
DevOps
AWS
API Gateway
DAST
SCA
SAST
DevSecOps
Security Testing
Java
CSS
Python
MS Azure
DevOps
AWS
API Gateway
DAST
SCA
SAST
Thông tin chung
- Thu nhập: Thỏa Thuận
Nơi làm việc
- Ho Chi Minh City, Ho Chi Minh
Việc làm tương tự khác
Công Ty Dịch Vụ Kế Toán Odyssey Resources
Hồ Chí Minh, Phú Thọ, Phú Yên
Thương lượng
CÔNG TY TNHH GALAXY DIGITAL HOLDINGS
Hồ Chí Minh, Phú Yên
Cạnh tranh
CHI NHÁNH CÔNG TY CỔ PHẦN XÂY DỰNG VÀ TRANG TRÍ NỘI THẤT VIỄN ĐÔNG
Hồ Chí Minh, An Giang, Đồng Nai, Vĩnh Long
15-20 triệu VND
NAB Innovation Centre Vietnam
Xem trang công ty- Địa chỉ công ty: District 4, Ho Chi Minh
- Quy mô: Từ 501 - 1000 nhân viên
- Lĩnh vực: IT phần mềm
Thông tin công việc
Vị trí:
Nhân viên
Hình thức làm việc:
Toàn thời gian
Việc làm tương tự
Cảnh báo dấu hiệu lừa đảo tuyển dụng
Đội ngũ hỗ trợ của JobOKO sẵn sàng đồng hành, tư vấn và giới thiệu những cơ hội việc làm phù hợp, giúp Ứng viên tự tin phát triển sự nghiệp và chinh phục mục tiêu nghề nghiệp bền vững.
Hotline CSKH
1900.63.63.84
Công ty Cổ phần JobOKO Toàn cầu
Đội ngũ hỗ trợ của JobOKO luôn chủ động tư vấn các giải pháp tuyển dụng tối ưu, cam kết đồng hành và hỗ trợ Quý Nhà tuyển dụng đạt được hiệu quả tuyển dụng bền vững.
Hotline CSKH
0962.107.888
Công ty Cổ phần JobOKO Toàn cầu