Senior Software Security Engineer
- Full-time
Company Description
Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 10 countries, and more than 160 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as retail and neo banks. Our research led approach and continual innovation is powered by the passion and creativity of our colleagues.
We are always looking for talented people to join us on our mission to orchestrate the financial ecosystem and democratize access to wealth management. Avaloq offers the opportunity to work closely with some of the world’s leading financial institutions as we jointly develop and shape careers. Championing a collaborative, supportive and flexible work environment empowers our colleagues to reach their full potential.
Job Description
The Avaloq Security team is an international team of analysts, senior and expert software engineers and architects. The Avaloq Security team develops and maintains central application security frameworks and tools for all companywide technology stacks and consults the business teams on best practice implementations for context specific security requirements. It furthermore operates the group-wide application security assessments, monitors the security vulnerabilities and supports the business teams in related risk mitigation plans.
Your key tasks
- Analyse, design, and develop requirements in collaboration with Product Development, customers, business analysts, and software partners.
- Design, implement, and maintain internal CI/CD pipelines and automated tools to support vulnerability management, security reporting, and efficient development workflows.
- Contribute to and collaborate across departments on cross-functional projects.
- Check and maintain the daily automated build process, analysing security warnings and providing guidance or fixes as required.
- Monitor third-party library enrolment, updates, and removals using in-house tools and Mend (or similar solutions).
- Evaluate and validate detected vulnerabilities, assess exploitability, provide expert analysis on false positives, and develop potential fixes.
- Maintain configuration control and ensure accuracy of the release baseline.
- Coordinate security-related actions across multiple teams to ensure the high quality and security of Avaloq products.
- Prepare and distribute documentation and reports related to security risks, findings, and remediation progress.
- Conduct periodic reviews to verify compliance with internal security policies, guidelines, and best practices.
- Participate in internal technical discussions, sharing knowledge on security implementation, vulnerabilities, and opportunities for improvement.
Qualifications
- University degree in IT, Mathematics, Physics, or a related technical discipline.
- Must have at least 3-5 years of relevant work experience
- Strong experience in designing, implementing, and maintaining internal CI/CD pipelines and automation tooling.
- Senior-level engineering expertise with hands-on skills in Python, Java, JavaScript, Gradle, Jenkins (or other CI/CD tools).
- Knowledge of containerized applications and experience with Kubernetes and/or OpenShift (or similar container orchestration platforms).
- Deep understanding of security concepts, industry standards, and best practices.
- Practical experience with vulnerability management tools and automated security scanning solutions.
- Ability to communicate technical information effectively to non-technical stakeholders.
- Exposure to financial markets and understanding of financial products is an advantage.
- Strong analytical capabilities, attention to detail, and commitment to delivering high-quality results.
- Positive, collaborative mindset with the ability to promote best practices across the organization.
Additional Information
We realize that managing work life balance is a challenge we all face in our daily lives and in order to support with this we are pleased to offer hybrid and flexible working for most of our Avaloqers to maintain work life balance and still continue our fantastic Avaloq culture in our global offices.
In Avaloq we are proud to embrace diversity and understand the success of our business is built on the power of different opinions, we are whole heartedly committed to fostering an equal opportunity environment and inclusive culture where you can be your true authentic self.
We hire, compensate and promote regardless of origin, age, gender identity, sexual orientation or any other fantastic traits that make us all unique, we have done our best to write this advert in an inclusive and neutral way.
Please be aware that we will not accept speculative CV submissions for any of our roles from recruitment agencies, and any unsolicited candidate submissions will be exempt from any payment expectations.
#LI-Hybrid