Container Security Engineer

  • Full-time

Company Description

Natixis in Portugal is fully integrated in the global organization of Natixis, a French multinational financial services firm specialized in Asset & Wealth Management, Corporate & Investment Banking, Insurance and Payments. As part of Groupe BPCE, Natixis counts nearly 16.000 employees across 38 countries.

 

Based in Porto, Natixis Centre of Expertise mission is to transform traditional banking by developing innovative solutions for the bank’s business, operations and work culture worldwide, as a key driver of the company’s culture of agility and innovation. Teams of IT and Banking Support Activities work in an integrated, inclusive and transversal way, supporting all the business lines and country platforms.

 

Counting with more than 1500 employees, Natixis in Portugal is the best combination of a “start-up mindset” with a large, solid structure. Its unique culture gives true meaning to a “beyond banking” personality: to be a real entrepreneur, self-challenging, ever striving to excel and go that extra mile.

Job Description

We are looking for Container Security Engineers (local contract) to work within our Infrastructures & Security Business Unit.
As a part of one of these teams, you will be expected to develop technical and functional knowledge and handle support for the assigned applications, to be pro-active towards incident management and about identifying effective solutions to recurrent incidents, to continuously improve and automate procedures, to keep documentation up to date and to keep up with the dev team with regular follow-ups.

 

Main Tasks & Responsibilities:

Within the DIS/CAD security team of the IT Security department of Natixis Bank, the candidate will be responsible for:

  • Collaborating with Infrastructure and Security teams to define and implement safe container standards in the bank (image security & automation, openshift & kubernetes secure architecture, microsegmentation, …);
  • Using industrial tools for dynamic and static scanning of both applications and containers;
  • Creating security workflows for deployment & auditing of application security (on-premise and in Cloud);
  • Evaluating application risk and suggesting mitigations;
  • Support business lines in understanding issues related with the protection of their sensitive data.

Qualifications

Main Technical Requirements:

  • Minimum 3 years exp. in similar roles;
  • Solid experience in Openshift configuration and management;
  • Solid experience in container networking and microsegmentation;
  • Experience in Cloud technologies (at least one of GCP, AWS, Azure);
  • Experience in development and/or scripting – Python or others;
  • Basic experience integrating containers in CI/CD tools is a plus (Jenkins pipelines, XLD, Artifactory, …);
  • Solid knowledge in HTTP and API protocols;
  • Basic knowledge of systems & networks;
  • Basic security knowledge.

Other requirements:

  • Good level of English - minimum B2 (mandatory);
  • Real interest in all areas of security & automation;
  • Capable of summarizing findings and presenting them to management;
  • Capable of collaborating with diverse teams & integrating diverse areas of knowledge;
  • Autonomous and innovative;
  • Good communication skills.

Additional Information

#MuchMoreThanJustAJob

Early morning. Campo 24 de Agosto. In 4 minutes, you are clocking in at the office. After grabbing a cup of coffee and fresh fruit, pick up your laptop and choose your spot for the day. It's going to be a busy one: French class before lunch and, just after, quick medical appointment at Natixis doctor's office.

Lunch break. Outside in the big terrace (look at your crops at the Urban Garden; ready to harvest!) or, if you feel like stretching your legs, walk downtown to grab lunch.

Back inside. Quick sprint review (working together anywhere means virtual happy birthday to that colleague in Paris that just turned 35). The afternoon went flying (tasks, reports, calls, some jokes with your teammates). End it on a high note: just one PlayStation game or the final match for that ping-pong tournament.

Tomorrow, you complete that certified technical training and the day after, you will work from home, taking advantage to finally do that online course on Udemy. Once you are done with your tasks for the day, you can visit the office for a board games session or show up at the rehearsal of one of Natixis bands. If that is too steady for you, meet your colleagues to surf some waves or join them in a football match.

Privacy Policy