Job description
We're seeking a key member who have had a proven track record of running critical shared application platforms in a production cloud environment. The purpose is to improve the security of NAB applications and DevOps practices through standards, education & awareness with developers, consultation on best practices, development of secure reusable capabilities, and supporting review and remediation of vulnerabilities
YOUR RESPONSIBILITIES
- Ensure respective policy, standards, processes and controls meet regulator and compliance expectations
- Support meeting departmental budgets
- Ensure controls and timely completion of findings and treatment plans
- Ensure and drive security outcomes relating to software development and devops practices
- Ensure and optimize dynamic application security testing tools and API security solutions
- Ensure tools are configured correctly and operating efficiently to provide maximum protection
- Utilise a variety of testing methodologies and tools to uncover potential threats and risks while eliminating the false positives
- Enhancing and updating application dynamic testing methodologies, processes and standards documentation
- Document and evangelise secure API design patterns
- Build and promote code libraries for API security
- Automate continuous security testing of APIs
- Consult with development teams to educate and improve awareness of secure standards and practices
- Support and champion the development of secure and reusable code across development teams to eliminate gaps identified in dynamic and API security testing
- Develop or use tooling to identify security vulnerabilities within our web application footprint
- Produce clear and accurate reporting for stakeholders
- Work with Cyber Engineering & Platforms teams to expand coverage and integrate dynamic and API security testing
- Work with Detection & Response and other Cyber Security teams to ensure critical exposures are mitigated in a timely manner
- Extend support on remediation of dynamic application testing and API vulnerabilities discovered through scanning and security testing
- Help manage the organization's vulnerability intake and remediation process
- Support incident response efforts as required
- Stay abreast of current and emerging technologies, threats and vulnerabilities, and best practice protection methods
- Research and analyse application behaviours to improve security and stability
- Contribute to the evolution of the organization's application security functions and services
- Other activities as required by management
Why you'll love working here
THE BENEFITS AND PERKS
1. Generous compensation and benefit package
- Attractive salary and benefits
- 20-day annual leave and 7-day sick leave, etc.
- 13th month salary and Annual Performance Bonus
- Premium healthcare for yourself and family members
- Monthly allowance for team activities
- Premium welcome kit and frequent appreciation gifts
- Extra benefits for long-term employees
2. Exciting career and development opportunities
- Large scale products with modern technologies in banking domain
- Clear roadmap for career advancement in both technical and leadership pathways
- Well-structured learning and development programs (technical and soft skills)
- Sponsored certificates in both IT and banking/finance
- Premium account on Udemy
- English learning with native teachers
- Opportunity for traveling & training in Australia
3. Professional and engaging working environment
- Hybrid working model and good work-life balance
- Well-equipped & modern Agile office with fully stocked pantry
- Special programs to improve your physical and mental health
- Annual company trip and events
- A solid talented team behind you – great people who love what they do
If this excites you, let's have a chat over a cup of coffee!