Company

AsicSee more

addressAddressSydney, NSW
salary SalaryPermanent
CategoryIT

Job description

  • ASIC is seeking a full time Application Security Engineer to join their Transformation Office Digital, Data and Technology Team
  • Permanent position based in Sydney or Melbourne
A future with ASIC means that your work will contribute to ASIC's vision for a fair, strong and efficient financial system for all Australians. We value what you will bring. We value those with sharp, analytical minds and are open to challenging the way things are done.The teamCyber Security provides a wide range of services including security architecture & design, incident response and cyber assurance for ASIC. We make use of the latest security technology with an increasing focus on automation and analytics to secure and support ASIC on its journey to be a 'best in class regulator supporting the Australian financial markets.The role
  • working closely with application development teams to help design secure solutions and integrate security into their software development practices.
  • providing the application development, support, and engineering teams with timely guidance on securing applications, APIs, middleware, and the development pipeline
  • educating developers on secure coding approaches and the use of the ASIC Application Security testing tools suite
  • leading threat modelling and application architecture review sessions to identify, assess, and address security threats at various stages of the design & development process.
  • coordinating and performing Application Security testing activities, including penetration testing, vulnerability scanning, and Application Security assessments.
  • collaborating with the development and engineering teams to perform application and cloud infrastructure secure code reviews.
  • assisting the IT teams with the analysis and remediation of security vulnerabilities, design flaws, and security weaknesses in application code, configurations & product architecture
  • assessing and quantifying the vulnerabilities and cyber risks of third-party software and components, and maintaining up-to-date software component registers (SBOMs)
  • collaborating with IT on technology selection and designing the hardened application SOE
  • working with the Application Security Team Lead to drive the continual improvement of the AppSec processes and tooling.
  • supporting the Cyber Assurance team in performing Application Security assurance reviews, creating appSec metrics and maintaining appSec policies and procedures
  • championing the DevSecOps and secure SDLC practices across the development, support, and engineering teams
  • assisting the Cyber Security leadership team drive improvements in the cyber security tools, processes, culture, and service provision
About you
  • A bachelor's degree in computer science or related field and/ or 5+ years of Software Development experience together with demonstrated experience as an Application Security Engineer or equivalent.
  • ​Demonstrated knowledge & experience in:
- securing applications based on modern software architecture patterns such as Microservices, Single-Page Application, and Serverless- secure coding practices to avoid common security vulnerabilities such as those in the OWASP Top Ten: SQLi, XSS, and CSRF- security testing frameworks and platforms such as OWASP ASVS and Snyk- securing applications in cloud and containerised environments- securing CI/CD automation pipelines- securing APIs- developing threat models and facilitating threat modelling workshops with developers and solution architects- performing penetration testing and application vulnerability scanning- using SAST, SCA, DAST and IAST Application Security testing tools
  • Experience in at least one of the following programming and scripting languages - Java, .Net, Python, and JavaScript
  • Experience in one or more of the following web technologies – Node.js, ReactJS, AngularJS, JSON
  • ​Demonstrable skills in assessing, analysing, and resolving complex client and stakeholder related queries
  • ​Formal security certifications are desired but not essential. Examples include Certified Secure Software Lifecycle Professional (CSSLP), Certified Information Systems Security Professional (CISSP), or related secure coding or offensive security certification.​
About ASICASIC's remit is one of the broadest of regulators across the world.ASIC regulates corporations, markets, financial services and consumer credit and monitors and promotes market integrity and consumer protection in the Australian financial system.Through our enforcement work, we hold to account those who contravene the law, working to achieve strong outcomes that address the greatest consumer and investor harms.Through Moneysmart, we aim to improve the skills and knowledge of Australians and provide information and tools to help them in their decision making.A future with ASIC means that your work will contribute to achieving ASIC's vision for a fair, strong, and efficient financial system for all Australians.ASIC is committed to a providing a diverse and inclusive workplace where the very best talent in Australia chooses to work. Indigenous Australians are encouraged to apply as well as applicants from all backgrounds and with different abilitiesTo work with us, you need to be an Australian citizen, and be prepared to complete an ASIC Suitability and Baseline Assessment which is issued ASIC's Security team.View the position description for more information or click ‘apply' to start your application.Applications for this role will close at 11:59pm on Tuesday 2 April 2024
Refer code: 1899785. Asic - The previous day - 2024-03-30 03:48

Asic

Sydney, NSW

Share jobs with friends

Software Engineer, Application Security - Crypto Authentication

Crypto Recruit

Sydney, NSW

3 months ago - seen

Application Security Engineer Team Lead

Asic

Permanent

Sydney, NSW

3 months ago - seen

Application Security Engineer

Tal

Permanent

Sydney, NSW

3 months ago - seen

Application Security Engineer

Tal

Sydney, NSW

3 months ago - seen

Application Security Engineer (AppSec) Internship - ANZ

Canva

Sydney, NSW

3 months ago - seen

Application Security Engineer

Hunter Water Cooperation

Newcastle, NSW

3 months ago - seen