Security & Vulnerability Assessor (Secure Coding)
- Plaats
- Amstelveen, Noord-Holland
- Start
- ASAP
- Werkplek
- Hybride
- Opdrachtgever
- niet vermeld
Kies je bemiddelaar
A2Z-CM
- Wie betaalt de fee
- niet vastgesteld
- Tarief bij deze opdracht
- geen tarief
- Beoordelingen
- nog geen
Omschrijving
Introduction 36 hours per week Start date: ASAP Duration: 1-year assignment with the possibility of extension Hybrid working. ZZP is allowed. Relocation is not possible. Function The Development Services department is the knowledge center within ABN AMRO for everything concerning software development. It’s goal is to continuously improve the quality of the software development process and it’s deliverables. To accomplish that mission, we harvest best practices from the development community and translate these into standards and guidelines. Common for all technologies is the need for strong security. The Secure Coding (SECO) team takes care of all matters concerning the security of software development.
A Domain Expert for SECO helps development teams in the organisation with improving the quality of security of their products. In this role, you’ll work closely with development teams across the bank. You’ll help them understand and fix security findings, improve how our tooling works, and contribute to solutions that make secure development easier. You’ll also be involved in looking at new topics like AI-driven threats and agentic development. You’ll be working at the intersection of security and development, helping teams deal with vulnerabilities in an efficient and effective way. What you’ll be doing: – Maintain and improve ABN AMRO’s security posture. – Maintain Secure Coding Standards. – Triage and analyse findings from SAST & SCA tools like Fortify and Nexus Lifecycle. – Help developers understand what a security finding really means, and how they can solve it. – Support teams in fixing vulnerabilities in their code. – Improve and fine-tune rulesets to reduce noise and increase quality. – Contribute to internally developed tools such as our Repository Scanner (RESC). – Think along about how we handle new risks, including AI-driven attacks. – Share knowledge and help teams become more secure over time No two days are exactly the same some days you’ll be deep in code, other days you’ll be discussing solutions with teams or improving tooling.
Requirements You’re someone who’s comfortable working with code and enjoys helping others improve. You don’t need to know everything, but you’re curious and pragmatic. What we’re looking for: – Experience in secure coding and application security. – Proficient in software development in at least one programming language. – Experience with SAST & SCA tools like Fortify, Nexus Lifecycle, or similar. – Experience in analysing and prioritising secure coding findings. – Able to communicate well with developers and explain things clearly. – Large corporate organisational sensitivity. – Fluent English. Information Jobs A2Z-CM +31(0)20-3337629 Application Jobs A2Z-CM +31(0)20-3337629 Apply Back to overview Your contact Information Jobs A2Z-CM +31(0)20-3337629 Vacancy number 4214
Interested? Answer a few short questions and you will be redirected to the correct office.
First of all, what’s your name? Got it Chloe, which A2Z-CM Office would you like to contact? Amsterdam, the Netherlands or London, UK ? Select Office Amsterdam,the Netherlands London, UK Great, now what’s your email ? Great, and your contact phone number? Last question please describe briefly what you would like to talk about?
… lees de volledige omschrijving bij A2Z-CM.