Job Seeker Reactivate Your Account
Thank you, this account has been Deactivated.
Do you want to Reactivate your account?
No
Yes
X

Senior Offensive Security Engineer

Yoma Bank
Thanlyin | Yangon
  1 Post
Verified This Job has been Verified as
Real by the Company.
This Job has been Verified as
Real by the Company.
Today
Recruiter active1 day ago This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
Sorry, Unable to Apply
x
55%
Please Upload CV Attachment, or update your JobNet Profile to at least 55% of completion.
Upload CV
Update Profile
Senior Offensive Security Engineer
Yoma Bank, Thanlyin | Yangon

Senior Offensive Security Engineer

Yoma Bank

Senior Offensive Security Engineer

Yoma Bank
Recruiter active1 day ago This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
This Company is Actively
Hiring. Your CV will be Sent
Directly to the Company.
Myanmar - Yangon
Verified This Job has been Verified as
Real by the Company.

Experience level

Experienced Non-Manager

Job Function

IT Hardware, Software

Job Industry

Banking/ Insurance/ Microfinance

Min Education Level

Bachelor Degree

Job Type

Full Time

Job Description

A Fantastic Opportunity for ...

Collaborating with Developers and Operations Teams

  • Work closely with development and operations teams to integrate security best practices throughout the software development lifecycle.

  • Provide guidance on secure coding practices and assist in the design of secure systems.

Security Reviews and Threat Modeling

  • Conduct regular security reviews and assessments to identify vulnerabilities in applications and infrastructure.

  • Perform threat modeling exercises to anticipate potential security threats and develop mitigation strategies.

Integrating Security Tools and Processes

  • Implement and manage security tools to automate security testing and monitoring.

  • Ensure seamless integration of security processes into CI/CD pipelines to maintain a secure development workflow.

Web, Mobile, Infra, Cloud Penetration Testing

  • Conduct comprehensive penetration tests on web applications, mobile applications, infrastructure, and cloud environments.

  • Document findings and provide actionable recommendations to address security vulnerabilities.

Leading DevSecOps Initiatives

  • Champion security in DevSecOps practices by embedding security measures within CI/CD pipelines.

  • Collaborate with DevOps teams to ensure continuous security monitoring and testing.

Training and Awareness

  • Provide security training and awareness programs for development and operations teams.

  • Promote a culture of security within the organization by sharing knowledge and best practices.

Policy and Standards Development

  • Develop and enforce security policies and standards to ensure compliance with industry best practices.

  • Stay current with emerging security trends and technologies to continuously enhance the security posture.

Incident Response Support

  • Participate in security incident response efforts, particularly those related to application and infrastructure security.

  • Provide expert analysis and recommendations during security incidents to minimize impact and prevent recurrence.

Open To

Male/Female

Job Requirements

Knowledge & Skills

  • In-depth technical knowledge of application security principles for web, mobile, and cloud platforms.

  • Proven and demonstrated knowledge of secure software development practices and DevSecOps methodologies.

  • Demonstrated experience in implementing security controls, including secure coding, application vulnerability management, penetration testing, and threat modeling.

  • Strong penetration testing skills for web, mobile, infrastructure, and cloud environments, with the ability to identify and remediate vulnerabilities.

  • Proficiency with security tools and technologies such as SAST, DAST, SCA, and penetration testing tools (e.g., Burp Suite, Metasploit, OWASP ZAP).

  • Ability to communicate effectively with all stakeholders, including technical teams and management.

  • High ownership, passion, and the ability to work with a sense of urgency to address security issues.

  • Knowledge of security standards and frameworks (e.g., OWASP, ISO 27001, NIST Cybersecurity Framework) and regulations (particularly in financial services) is preferred.

 

Education & Special Training

Essential 

  • Degree/Diploma in Computer Technology, Computer Science, Information Security, Cybersecurity, Computing, Software Engineering, IT or equivalent.

Desirable

  • Equivalent experience and certifications (e.g., OSCP, CPENT, eCPPT, CDP) are also considered.

 

Experience 

Essential  

  • 3+ years of experience in application security, including web, mobile, and cloud environments.

  • Experience with SAST, DAST, and SCA tools for identifying and mitigating security vulnerabilities.

  • Hands-on experience conducting penetration tests and security assessments for web applications, mobile apps, and cloud infrastructures.

  • Proven experience integrating security practices into CI/CD pipelines and DevSecOps workflows.

  • Strong understanding of secure coding practices, OWASP Top Ten, and common security frameworks.

Desirable

  • Experience in the financial or banking sector.

 

Languages

  • Good communication skills in English (written and spoken).

What we can offer

Benefits

• Ferry Provided
• Mobile Phone Allowance
• Life Insurance
• Limited Medical Cover

Highlights

• Empowered Working Environment
• Diverse Team

Career Opportunities

• Learning and Development Platform
• Opportunities to Explore Multiple Career Paths