Expoint – all jobs in one place
המקום בו המומחים והחברות הטובות ביותר נפגשים
Limitless High-tech career opportunities - Expoint

Td Bank Senior Information Security Analyst – Mitigation 
Singapore, Singapore 
383815864

Today
Singapore, SingaporeTechnology Solutions


Responsibilities: Secure Code Review

  • Deliver secure code review assessment on programming languages such as Java, C#, PHP, Python, Perl, C/C++ , SQL, >
  • Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
  • Train and assist developers in writing secure software and remediating existing vulnerabilities.
  • Develop and review custom vulnerability description, business impact and remediation content.
  • Develop, research, and recommend open-source tools assisting in secure code review.
  • Contribute to development and delivery of secure coding and remediation training.
  • Mentor and assist team members in effectively delivering assessments and enhancing skillsets.
  • Key Lead in Release Based Testing Process and Td Mitigation Proposal Review Process.
  • On Call Position – to approve change requests if needed.

Responsibilities: Pentesting

  • Conduct thorough and comprehensive penetration testing on various applications, networks, and infrastructure using both manual and automated techniques.
  • Identify vulnerabilities in a web applications, mobile applications, and manual code reviews.
  • Document and report findings and provide actionable recommendations to improve security posture.
  • Collaborate with other team members and application development teams to assess security risks and assist in remediation and mitigation strategies.
  • Research and stay up to date with the latest trends, threats, and vulnerabilities in the cybersecurity industry.
  • Communicate effectively with technical and non-technical stakeholders, as well as other team members.

Requirements:

  • Proven experience in conducting penetration testing and vulnerability assessments on various systems, networks, and applications.
  • Proven experience in Secure Code Review.
  • Expertise in using a range of penetration testing tools and techniques, including Burp Suite, Metasploit, and Nmap.
  • Solid understanding of web applications, mobile applications, and databases.
  • Experience in detecting, analysing and providing recommendation guidance on security vulnerabilities in at least two of the following languages: Java, C#, PHP, Python, Perl, C/C++ , SQL, >
  • Hands-on experience conducting security focused static analysis using commercial SAST tools such as Checkmarx, Appscan Source, Veracode, Coverity, Fortify and SonarQube.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work both independently and as part of a team.
  • Relevant industry certifications such as OSCP a plus.

Experience and Education:

  • University degree
  • Information security certification / accreditation an asset
  • 5+ years of relevant experience
  • 3+ years of experience in application security including secure code review, web application penetration testing or threat modelling.
  • Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code.
  • Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience.


If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.


We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.