Job Posting Description
As the world works and lives faster, FIS is leading the way. Our fintech solutions touch nearly every market, company and person on the planet. Our teams are inclusive and diverse. Our colleagues work together and celebrate together. If you want to advance the world of fintech, we’d like to ask you: Are you FIS?
About the team:
It’s an amazing opportunity to join a Talented team of innovative and committed folks doing interesting work at the world’s largest global provider dedicated to financial technology solutions!
What you will be doing:
Develop policy and standards for API security.Collaborate with internal development teams to build/advocate security controls in Application Programming Interface (API), performing Threat Modeling, Static Application Security Testing (SAST), Software Composition Analysis(SCA).Assist in the strategy, standards, and architecture for the security aspects of the SDLC including application, APIs, DevSecOps, and CICD.Identify the gaps in SAST/SCA tool rule/configuration and work with vendor to engineer them to provide the maximum scanning coverage to applications.Experience and knowledge in Burp Suite tool for dynamic testing (DAST).Primarily responsible for API application security but with a good working knowledge of other security domains (Cryptography, Identity and Access Management, Threat and Vulnerability Management)What you bring:
At least 5 years of working experience in application security that includes API, SAST and DAST along with Checkmarx, VeracodeKnowledge of security technologies (encryption, data protection, design, privilege access, etc.)Proficiency in time management, communications, decision making, presentation and organizational skillsProficiency in planning, reporting, establishing goals and objectives, standards, priorities and schedulesExcellent decision-making, analytical and problem solving skillsExcellent verbal and written communication skills to technical and non-technical audiences of various levels in the organizationExperience establishing and maintaining effective working relationships with employees and/or clientsStrong knowledge of development and application securityHands-on experience performing application API security assessment, static and dynamic security assessments with tools such as: Burpsuite, OWASP ZAP, AppScan, WebInspect, Fortify, Veracode, Checkmarx, etc.Knowledge of OWASP Top 10/ SANS Top 25, identify vulnerabilities via manual and automated testing methods and how to effectively remediate vulnerabilities associated with eachExpert knowledge of information security principles, web applications, and intermediate familiarity with malicious code and common hacking techniques used by malicious actorsExperience conducting risk assessments and performing threat modeling of applicationsAbility to collaborate with teams remotelyWhat we offer you:
A career at FIS is more than just a job. It’s the change to shape the future of fintech. At FIS, we offer you:
A voice in the future of fintechAlways-on learning and developmentCollaborative work environmentOpportunities to give backCompetitive salary and benefitsPrivacy Statement
FIS is committed to protecting the privacy and security of all personal information that we process in order to provide services to our clients. For specific information on how FIS protects personal information online, please see the Online Privacy Notice.
Sourcing Model
Recruitment at FIS works primarily on a direct sourcing model; a relatively small portion of our hiring is through recruitment agencies. FIS does not accept resumes from recruitment agencies which are not on the preferred supplier list and is not responsible for any related fees for resumes submitted to job postings, our employees, or any other part of our company.
#pridepass