drjobs Senior Information Security Analyst – Mitigation Proposal Review / Penetration Tester

Senior Information Security Analyst – Mitigation Proposal Review / Penetration Tester

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Singapore - Singapore

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Work Location:

Singapore Singapore

Hours:

40

Line of Business:

Technology Solutions

Pay Details:

Were committed to providing fair and equitable compensation to all our colleagues. As a candidate we encourage you to have an open dialogue with a member of our HR Team and ask compensation related questions including pay details for this role.

Job Description:

Job Summary:

We are seeking a skilled and experienced Secure Code Reviewer / Penetration Tester to join our team. As a Secure Code Reviewer / Penetration Tester you will be responsible for identifying and exploiting vulnerabilities in applications and infrastructure to help improve our cybersecurity posture. You will use a range of tools and techniques to conduct secure code reviews and penetration testing and provide actionable recommendations to enhance security controls.

Responsibilities: Secure Code Review

  • Deliver secure code review assessment on programming languages such as Java C# PHP Python Perl C/C SQL >
  • Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
  • Train and assist developers in writing secure software and remediating existing vulnerabilities.
  • Develop and review custom vulnerability description business impact and remediation content.
  • Develop research and recommend open-source tools assisting in secure code review.
  • Contribute to development and delivery of secure coding and remediation training.
  • Mentor and assist team members in effectively delivering assessments and enhancing skillsets.
  • Key Lead in Release Based Testing Process and Td Mitigation Proposal Review Process.
  • On Call Position to approve change requests if needed.

Responsibilities: Pentesting

  • Conduct thorough and comprehensive penetration testing on various applications networks and infrastructure using both manual and automated techniques.
  • Identify vulnerabilities in a web applications mobile applications and manual code reviews.
  • Document and report findings and provide actionable recommendations to improve security posture.
  • Collaborate with other team members and application development teams to assess security risks and assist in remediation and mitigation strategies.
  • Research and stay up to date with the latest trends threats and vulnerabilities in the cybersecurity industry.
  • Communicate effectively with technical and non-technical stakeholders as well as other team members.

Requirements:

  • Proven experience in conducting penetration testing and vulnerability assessments on various systems networks and applications.
  • Proven experience in Secure Code Review.
  • Expertise in using a range of penetration testing tools and techniques including Burp Suite Metasploit and Nmap.
  • Solid understanding of web applications mobile applications and databases.
  • Experience in detecting analysing and providing recommendation guidance on security vulnerabilities in at least two of the following languages: Java C# PHP Python Perl C/C SQL >
  • Hands-on experience conducting security focused static analysis using commercial SAST tools such as Checkmarx Appscan Source Veracode Coverity Fortify and SonarQube.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work both independently and as part of a team.
  • Relevant industry certifications such as OSCP a plus.

Experience and Education:

  • University degree
  • Information security certification / accreditation an asset
  • 5 years of relevant experience
  • 3 years of experience in application security including secure code review web application penetration testing or threat modelling.
  • Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code.
  • Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience.

Who We Are

TD is one of the worlds leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day we deliver legendary customer experiences to over 27 million households and businesses in Canada the United States and around the world. More than 95000 TD colleagues bring their skills talent and creativity to the Bank those we serve and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers communities and colleagues.


TD is deeply committed to being a leader in customer experience that is why we believe that all colleagues no matter where they work are customer facing. As we build our business and deliver on our strategy we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether youve got years of banking experience or are just starting your career in financial services we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs were here to support you towards your goals. As an organization we keep growing and so will you.

Our Total Rewards Package
Our Total Rewards package reflects the investment we make in our colleagues to help them and their families achieve their well-being goals. Total Rewards at TD includes a base salary and several other key plans such as health and well-being benefits including medical coverage paid time off career development and reward and recognition programs.

Additional Information:
Were delighted that youre considering building a career with TD. Through regular development conversations training programs and a competitive benefits plan were committed to providing the support our colleagues need to thrive both at work and at home.

Colleague Development
If youre interested in a specific career path or are looking to build certain skills we want to help you succeed. Youll have regular career development and performance conversations with your manager as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience or you want to coach and inspire your colleagues there are many different career paths within our organization at TD and were committed to helping you identify opportunities that support your goals.

Training & Onboarding
We will provide training and onboarding sessions to ensure that youve got everything you need to succeed in your new role.

Interview Process
Well reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.

Accommodation

If you require an accommodation for the recruitment / interview process (including alternate formats of materials or accessible meeting rooms or other accommodation) please let us know and we will work with you to meet your needs.


Required Experience:

Senior IC

Employment Type

Full-Time

Company Industry

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.