- Provide security techniques and expertise to ensure the infrastructure and software services meet specific customer security requirements/certifications
- Collaborate with members of the team and product owners to solve operational issues and develop enhancements such as automation.
- Ensure applications stay compliant by integrating application and DevSecOps processes and CI/CD pipelines from early stages of the lifecycle.
- Collaborate with team members on continuous improvement to both the Security DevOps pipelines and processes, and to the Information Security tools, services, and processes.
- Understand technical and business requirements to develop tactical and strategic roadmaps to address and implement Secure SDLC controls (Data Privacy, SAST, DAST, etc).
REQUIREMENTS
- Bachelor Degree in information security, computer science.
- Experience working in an Agile, DevOps/SecDevOps environment.
- Experience working in a Security role handling on premise and cloud infrastructures.
- Experience with security testing at scale by building and implementing static and dynamic analysis tools, integrating security into CI/CD workflows for everyday deployments.
- Experience with Authentication and Authorization solutions.
- Experience with static code analysis for software or infrastructure as code, including SonarQube,Terraform.
- Experience with vulnerability scanners, including Tenable Nessus, Qualys, ...
- Understanding of secure software development practices - AppSec - Security and/or regulatory experience desired, OWASP 10 and Web Application Security, Mobile Application Security, API Security.
- Good knowledge of threat modeling, risk assessment techniques, code reviews, and with the latest security best practices
- Require good knowledge of CI/CD tools
- Require good knowledge in automatic configuration management tool
- Good knowledge of containers and orchestration platforms. Need to know how to create, build, deploy and manage containers in development and production environments
- Experience in developing integration APIs and WebServices (REST/SOAP), API Development
Finviet là công ty Fintech theo mô hình kinh doanh B2B2C với trọng tâm là các điểm bán lẻ trải dài trên khắp cả nước. Finviet tự hào là đơn vị được ngân hàng nhà được cấp giấy phép trung gian thanh toán (Ví điện tử, Cổng thanh toán, Thu hộ chi hộ). Chúng tôi xây dựng hệ sinh thái công nghệ giúp kết nối giữa các nhà cung cấp dịch vụ/ hàng hoá, ngân hàng/ các đơn vị tài chính với các điểm bán lẻ, từ đó có thể cung cấp hàng hoá dịch vụ đến tận tay người dùng cuối ở khắp mọi nơi một cách nhanh chóng và tiện lợi nhất.
34 Hoàng Việt, Phường 4, Tân Bình, Thành phố Hồ Chí Minh, Việt NamView map