Skip to content
Tuyển Dụng
← ITviec Recruitment Consulting

Lead/Senior Security Engineer

ITviec Recruitment Consulting · Hồ Chí Minh
Apply on official site ↗
Type
Full-time
Work mode
On-site
Level
Staff
Industry
Engineering / Mechanical
Salary
Thương lượng
Location
Not Available, Hồ Chí Minh, Hồ Chí Minh

Overview

  • Develop and maintain security automation tools and scripts using Python to support application security and DevSecOps processes
  • Perform secure code reviews across platforms (Kotlin, Node.js, Android, iOS, Python), with strong emphasis on Python-based systems
  • Integrate and automate security controls into CI/CD pipelines (e.g., GitHub Actions)
  • Work closely with engineering teams to embed secure coding practices into the SDLC
  • Implement and manage SAST/SCA/DAST tools and automate vulnerability detection and remediation workflows
  • Support API and application security (REST, GraphQL), including authentication, authorization, and encryption practices
  • Conduct basic penetration testing and vulnerability validation (mobile, web, APIs) – depth is not required, focus is on remediation and automation
  • Perform threat modelling (e.g., STRIDE) and risk assessment for applications, especially in banking systems
  • Collaborate with infrastructure teams to ensure secure deployment on AWS cloud environments
  • Contribute to application security standards, policies, and best practices aligned with OWASP
  • Monitor and respond to emerging security threats, including risks related to AI-enabled systems
  • Support BAU security operations, vulnerability management, and continuous improvement initiatives
  • Your Skills and Experience

Requirements

  • 5+ years of hands-on experience in Python development (mandatory, strong coding capability is critical)
  • 8 years of experience in application security/DevSecOps
  • Experience working in banking/financial services domain
  • Strong experience with AWS cloud services and cloud security practices
  • Solid understanding of secure coding practices and code review methodologies
  • Experience integrating security tools into CI/CD pipelines
  • Familiarity with SAST/SCA/DAST tools
  • Basic understanding of penetration testing concepts and tools (e.g., Burp Suite, MobSF, Frida)
  • Knowledge of API security, authentication mechanisms, and cryptographic fundamentals
  • Experience working in Agile/DevOps environments
  • Experience with security automation frameworks and tooling in Python
  • Exposure to AI/ML application security (e.g., prompt injection, model abuse)
  • Certifications such as AWS Security Specialty, CSSLP, OSCP (optional)
  • Experience with container security (Docker, Kubernetes) and IaC scanning
  • Familiarity with banking security standards and compliance requirements
  • Why You'll Love Working Here

Benefits

  • A Top-Tier World-Ranking Corporation: Join a leading global IT powerhouse that drives digital transformation for the world’s top financial institutions and insurance companies.
  • Latest Technology Updates: Work with the most updated and cutting-edge technologies, including Cloud migration, Next-Generation Mainframe, AI, and modern software architectures.
  • Clear Career Progression Roadmap: Enjoy a transparent and clearly defined path for your career advancement within an agile, collaborative, and fast-growing international environment.

Summary of facts from the official posting. View original ↗

Interested in this role?

You'll be taken to the employer's official application page.

Apply on official site ↗
Is this your business? Claim this page, request edits or removal