MUFG Investor Services
Posted 3w ago

Application Security Engineer (Experienced in applications security focusing on red, blue or purple team activities)

MUFG Investor Services
Dublin, Leinster, Ireland
OnsiteFull Time
Responsibilities
  • identifying risks
  • conducting testing
  • providing guidance
Requirements
  • Experience in application security (red/blue/purple team)
  • SAST/DAST/SCA tooling
  • Pen testing
  • API security
  • Secure SDLC
  • Scripting and collaboration with Dev/DevOps teams
Technical tools mentioned
Burp SuiteOWASP ZapSnykVeracodeCheckmarxPythonJavaScript.NETJavaGitLabGitHubDatadogJiraDockerKubernetesAWS WAFAWS Cognito

Job description

Company Description:

MUFG Investor Services is a trusted partner to many of the world’s largest public and private funds, providing asset servicing and operational solutions built for alternatives. With over $1 trillion in client assets under administration, we offer fund administration, banking, payments, fund financing, foreign exchange overlay, corporate and regulatory services, custody, business consulting, and more.

Operating from 17 locations worldwide, we help clients mitigate risk, enhance efficiency, and navigate the operational complexities of today’s investment management landscape. As a division of Mitsubishi UFJ Financial Group (MUFG), one of the world’s largest financial institutions with approximately $3 trillion in assets, we combine deep expertise with the strength and stability of a leading financial institution. To learn more, visit us at www.mufg-investorservices.com.

 

Job Description:

We are seeking a proactive and collaborative Application Security Engineer who speaks the language of developers, thrives in the purple team space and is an automation advocate. The successful candidate will work closely with engineering & IT teams to enhance the security of our applications, API’s and infrastructure by implementing preventative controls and identifying risks through security testing. 

You Will:

  • Act as a security champion to foster the secure by design approach across the business. 
  • Support the identification and analysis of web application security vulnerabilities across the business to reduce risk. 
  • Oversee daily management of application security platforms to maintain comprehensive coverage, ensure compliance and remediation of findings. 
  • Conduct threat modelling and review application architectures to identify potential risks early in the SDLC. 
  • Implement application security controls and proactive measures to prevent security incidents. 
  • Implement and manage SAST/SCA tooling across our application repositories to identify source code risks. 
  • Scale automated DAST solutions across our applications to maximise testing coverage and provide visibility into runtime security posture. 
  • Provide security guidance and remediation advice to engineers where applicable. 
  • Carry out penetration testing on internally developed applications to identify security defects. 
  • Review and assess the security of third-party vendor applications through configuration and hardening reviews. 
  • Validate remediation of security issues by the development team and 3rd parties. 
  • Coordinate and arrange external penetration testing assessments to independently evaluate the security of our applications. 
  • Build and maintain effective collaboration with development and IT teams.

 

Qualifications:

You Have: 

  • Experienced in applications security focusing on red, blue or purple team activities. 
  • Experienced in software development or experience contributing to Open-Source projects.  
  • Experienced with DAST tools such as Burp Suite, OWASP Zap or similar.
  • Experience with SAST/SCA tools such as Snyk, Veracode, Checkmarx or similar. 
  • Proficient in one or more of the following languages - Python, JavaScript, .NET or Java. 
  • Well-versed in analysis of open source and third-party library vulnerabilities. 
  • Well-rounded knowledge of the Software Development Life Cycle (SDLC) and agile methodologies. 
  • Hold a strong understanding and experience testing of both REST and GraphQL APIs. 
  • Demonstrated experience with development tools including GitLab/GitHub, Datadog, Jira, Docker, and various IDEs. 
  • Previously worked very closely with development and DevOps teams to resolve security issues. 
  • Have performed security-focused code reviews to identify code level issues. 
  • Experience in creating custom security tooling or scripts. 

Preferred 

  • Experience in the financial sector or another heavily audited industry. 
  • Experience with cloud services, particularly AWS services like WAF, Cognito etc. 
  • Experience working with Infrastructure as Code, Kubernetes and Containers. 
  • Experience with auth mechanisms like Open ID Connect, OAuth and identity providers. 
  • Experience in creating custom CI/CD pipeline jobs to carry out security related reviews or scans. 
Additional Information:

What’s in it for you to join MUFG Investor Services?   

Take a look at our careers site and you’ll find everything you’d expect from a career with the fastest-growing business at one of the world’s largest financial groups. Now take another look. Because it’s how we defy expectations that really defines us. You’ll feel that difference in all kinds of ways.  Our vibrant CULTURE. Connected team. Love of innovation, laser client focus, and next-level LEARNING & DEVELOPMENT.      

So, why settle for the ordinary?  Apply now for a Brilliantly Different career.   

We thank all candidates for applying; however, only those proceeding to the interview stage will be contacted.

We are an equal opportunity employer.

 

About MUFG Investor Services

Provides fund administration and asset servicing to investment firms.

Year founded
2013
Employees
2000
Organization type
Public
Headquarters
JP

Similar jobs

Application Security Engineer roles near Dublin, Leinster
1mo
Save
Mark Applied
Hide
Application Security Engineer
London or Dublin
HybridFull Time
Intercom
Intercom: AI-first customer service platform for automated and human support.
Proven application/product/security engineering experience in SaaS; strong software engineering skills; deep understanding of application security, threat modelling, auth/identity, architecture reviews, incident response, and building security tooling.
SAML/SSO, Intercom, Claude Code
2mo
Save
Mark Applied
Hide
Senior Application Security Engineer (Remote - Ireland)
Dublin, Leinster, Ireland
RemoteFull Time
Yelp
YelpNYSE: YELP: Platform connecting consumers with local businesses via reviews.
Several years of software engineering experience in application security; strong knowledge of web, mobile, API, and cloud security; familiarity with OWASP Top 10; proficiency in Python, Java, JavaScript/React, Swift, or Objective-C; security research/pen testing a plus.
SAST, Python, Java, JavaScript, React, Swift, Objective-C, OWASP Top 10
2mo
Save
Mark Applied
Hide
Senior Application Security Engineer (Remote - Ireland)
Dublin or Cork or Limerick or Galway or Ireland
RemoteFull Time
Yelp
YelpNYSE: YELP: Online platform for discovering and reviewing local businesses.
Several years of software engineering experience in application security; strong understanding of web, mobile, API, and cloud security; familiarity with OWASP Top 10; proficiency in Python, Java, JavaScript, React, Swift, or Objective-C; security research/pen testing a plus; must be located in the Republic of Ireland.
SAST, OWASP Top 10, Python, Java, Javascript, React, Swift, Objective-C
1y
Save
Mark Applied
Hide
IAM Security Engineer/Application support
Dublin, Dublin, Ireland
OnsiteFull Time
Test Triangle
Test Triangle: IAM security engineering role focusing on application support in technology services.
5+ YOE5+ years in technology; strong IAM and security experience; incident/change/problem management; knowledge of monitoring tools.
Java, Autosys, SQL, Dynatrace, Splunk