MUFG Investor Services
Financial Services
DevSecOpsEngineer
Neural analysis suggests this role is
optimal for mid candidates.
“DevSecOps Engineer at MUFG Investor Services. Skills: Application Security, DevSecOps, Automation. Foster secure by design approach. Support identification of vulnerabilities”
What You'll Achieve.
Enhance application security; Enhance API security; Enhance infrastructure security; Reduce risk; Maintain comprehensive coverage; Ensure compliance; Identify potential risks early; Prevent security incidents; Identify source code risks; Maximise testing coverage; Provide visibility into runtime security
Industry & Context.
Identify risks; Remediation of findings; Identify security defects; Root cause analysis
What They're Looking For.
Must Have
Application security experience, Software development experience, DAST tools experience, SAST/SCA tools experience, Python proficiency, JavaScript proficiency, .NET proficiency, Java proficiency, Open source vulnerability analysis, SDLC knowledge, Agile methodologies knowledge, REST API testing experience, GraphQL API testing experience, GitLab/GitHub experience, Datadog experience, Jira experience, Docker experience, IDE experience, Development team collaboration, DevOps team collaboration, Security-focused code reviews, Custom security tooling creation, Custom security scripts creation
Nice to Have
Financial sector experience, AWS experience, WAF experience, Cognito experience, Infrastructure as Code experience, Kubernetes experience, Containers experience, Open ID Connect experience, OAuth experience, Identity providers experience, CI/CD pipeline job creation
What You'll Do.
Foster secure by design approach
Support identification of vulnerabilities
Analyze web application vulnerabilities
Oversee application security platforms
Conduct threat modelling
Review application architectures
Implement application security controls
Implement preventative measures
Implement SAST tooling
Implement SCA tooling
Scale automated DAST solutions
Provide security guidance
Provide remediation advice
Carry out penetration testing
Review third-party vendor security
Assess third-party vendor security
Validate remediation of security issues
Coordinate external penetration testing
Arrange external penetration testing
Build collaboration with development teams
Build collaboration with IT teams
Maintain collaboration with development teams
Maintain collaboration with IT teams
How You'll Work.
Team & Collaboration
Engineering teams; IT teams; Development teams; DevOps teams
Process & Methodology
Agile methodologies
Full Job Description
MUFG Investor Services is a trusted partner to many of the world’s largest public and private funds, providing asset servicing and operational solutions built for alternatives. With over $1 trillion in client assets under administration, we offer fund administration, banking, payments, fund financing, foreign exchange overlay, corporate and regulatory services, custody, business consulting, and more. Operating from 17 locations worldwide, we help clients mitigate risk, enhance efficiency, and navigate the operational complexities of today’s investment management landscape. As a division of Mitsubishi UFJ Financial Group (MUFG), one of the world’s largest financial institutions with approximately $3 trillion in assets, we combine deep expertise with the strength and stability of a leading financial institution. To learn more, visit us at [www.mufg-investorservices.com](http://www.mufg-investorservices.com/). #LI-Hybrid We are seeking a proactive and collaborative Application Security Engineer who speaks the language of developers, thrives in the purple team space and is an automation advocate. The successful candidate will work closely with engineering & IT teams to enhance the security of our applications, API’s and infrastructure by implementing preventative controls and identifying risks through security testing. You Will: * Act as a security champion to foster the secure by design approach across the business. * Support the identification and analysis of web application security vulnerabilities across the business to reduce risk. * Oversee daily management of application security platforms to maintain comprehensive coverage, ensure compliance and remediation of findings. * Conduct threat modelling and review application architectures to identify potential risks early in the SDLC. * Implement application security controls and proactive measures to prevent security incidents. * Implement and manage SAST/SCA tooling across our application repositories to identify so
Applying for this DevSecOps Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on SmartRecruiters
- SmartRecruiters often includes a video screening step — check camera and mic permissions.
- Link your GitHub or portfolio directly in the profile section for technical roles.
- Applications may be reviewed by AI scoring before reaching a recruiter — use keywords from the job description.
ANONYMOUS · UNFILTERED
What do employees actually say about MUFG Investor Services?
Real rants from real employees. Read before you apply.