Application Security Engineer

  • Full-time

Company Description

Natixis in Portugal is fully integrated in the global organization of Natixis, a French multinational financial services firm specialized in Asset & Wealth Management, Corporate & Investment Banking, Insurance and Payments. A subsidiary of Groupe BPCE, Natixis counts nearly 16.000 employees across 38 countries.

Based in Porto, Natixis Centre of Expertise mission is to transform traditional banking by developing innovative solutions for the bank’s business, operations and work culture worldwide, as a key driver of the company’s culture of agility and innovation. Teams of IT and Banking Support Activities work in an integrated, inclusive and transversal way, supporting all the business lines and country platforms.

Natixis in Portugal is the best combination of a “start-up mindset” with a large, solid structure. Its unique culture gives true meaning to a “beyond banking” personality: to be a real entrepreneur, self-challenging, ever striving to excel and go that extra mile

Job Description

We are looking for a Application Security Engineer( local contract) to join our Infrastruture, Production & Security business unit. 

Main Tasks & Responsibilities:

Within the DIS/CAD security team of the IT Security department of Natixis Bank, the candidate will be responsible for:

  • Collaborating with developers and performing code security reviews for the bank’s applications;
  • Perform application security scans of business applications (both SAST and DAST scanning);
  • Evaluating risk and suggesting mitigations;
  • Collaborating with DevOps and other Security teams to automate application security into the development & release pipelines (CI/CD);
  • Support business lines in understanding issues related with the protection of their sensitive data;
  • Support in the drafting of application security guidelines for both on-premise and cloud development.

 

Qualifications

Main Technical Requirements:

  • Minimum 3 years exp. in similar roles;
  • Solid experience with one or more development languages (Java, .NET, PHP);

  • Good knowledge of applicational security and code vulnerabilities;

  • Basic experience in CI/CD tools, like Jenkins, TFS, XLRelease, Artifactory;

  • Knowledge of HTTP and API protocols;

  • Previous experience with static or dynamic security scanning tools (Checkmarx, Qualys, ZAP, SonarQube) is a plus;

  • Nice-to-have: experience in Cloud technologies (at least one of GCP, AWS, Azure).

 

Other Requirements:

  • Very good level of English;

  • The candidate must have a real interest in all areas of security & automation;

  • Capable of summarizing findings and presenting them to management;

  • Capable of collaborating with diverse teams & integrating diverse areas of knowledge;

  • Autonomous and innovative;

  • Good communication skills.

Additional Information

#MuchMoreThanJustAJob

Early morning. Campo 24 de Agosto. In 4 minutes, you are clocking in at the office. After grabbing a cup of coffee and fresh fruit, pick up your laptop and choose your spot for the day. It's going to be a busy one: French class before lunch and, just after, quick medical appointment at Natixis doctor's office.

Lunch break. Outside in the big terrace (look at your crops at the Urban Garden; ready to harvest!) or, if you feel like stretching your legs, walk downtown to grab lunch.

Back inside. Quick sprint review (working together anywhere means virtual happy birthday to that colleague in Paris that just turned 35). The afternoon went flying (tasks, reports, calls, some jokes with your teammates). End it on a high note: just one PlayStation game or the final match for that ping-pong tournament.

Tomorrow, you complete that certified technical training and the day after, you will work from home, taking advantage to finally do that online course on Udemy. Once you are done with your tasks for the day, you can visit the office for a board games session or show up at the rehearsal of one of Natixis bands. If that is too steady for you, meet your colleagues to surf some waves or join them in a football match.

Privacy Policy