The ideal candidate will be a hands-on security professional with strong experience in security engineering, penetration testing, ethical hacking, application security, cloud security, and vulnerability management. You should be able to think like an attacker while working collaboratively with Engineering, DevOps, Infrastructure, and Product teams to identify and mitigate real-world security threats.
- Design and implement security controls across applications, infrastructure, networks, cloud environments, and digital banking systems.
- Plan and execute authorised penetration tests across web applications, APIs, mobile applications, networks, cloud infrastructure, and internal systems.
- Conduct ethical hacking and manual security testing to identify vulnerabilities beyond automated scanning.
- Assess web applications and APIs for authentication, authorisation, access control, session management, and other security vulnerabilities.
- Assess and strengthen AWS cloud and infrastructure security, including IAM, network configurations, exposed services, storage, and access controls.
- Manage vulnerability assessments, prioritisation, remediation, and validation across technology environments.
- Investigate security alerts, suspicious activities, and potential breaches, supporting incident response and root-cause analysis.
- Conduct threat modelling, attack-surface assessments, and security reviews for new products and system changes.
- Work closely with developers and technical teams to resolve vulnerabilities and promote secure development practices.
- Prepare clear security reports, communicate risks, and recommend practical remediation measures.
- Continuously improve the organisation's overall security posture and security processes.
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related discipline.
- 5+ years of professional cybersecurity experience, with strong hands-on experience in security engineering, penetration testing, offensive security, or application security, within banking, fintech, payments, financial services, or other regulated environments is an advantage.
- Proven experience conducting penetration tests and security assessments.
- Strong knowledge of web application, API, mobile, network, cloud, and infrastructure security.
- Strong understanding of OWASP principles and common security vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Nmap, Wireshark, Metasploit, Nessus/OpenVAS, or equivalent.
- Strong knowledge of AWS security and cloud security controls.
- Knowledge of Linux and Windows security.
- Scripting experience with Python, Bash, PowerShell, JavaScript, or similar languages.
- Ability to understand source code and identify security vulnerabilities.
- Strong analytical, problem-solving, and communication skills.
- Experience working with Engineering, DevOps, Infrastructure, and technical teams.
- Knowledge of PCI DSS, ISO 27001, NIST, and OWASP is desirable.
- Professional certifications such as OSCP/OSCP+, CEH, PNPT, CISSP, CISM, GIAC, or AWS Certified Security - Specialty are an added advantage.
We are looking for someone who can:
- Think beyond automated vulnerability scanners.
- Identify and validate real-world security weaknesses.
- Demonstrate the business impact of vulnerabilities.
- Recommend practical and scalable security solutions.
- Work effectively with technical teams to resolve security issues.
- Respond effectively to security incidents.
- Make ownership of strengthening the organisation's security posture.
- Maintain high standards of integrity, confidentiality, and responsible security practice