IT Security Architect, Security Integrator, Security Consultant, Authentication, Entitlements, Identity Management, Data Protection, Mobile Security Vulnerabilities, Hashing, Fortify, OunceLabs, HK recruitment

My client is a leading global investment bank that is looking to hire an IT Security Architect/Integrator who is a subject matter expert in IT security.

This role is very much focusing on the security networks across the bank, focusing predominately on the application systems (70%) and the rest of the time on the Infrastructure (30%).

It will be looking at software authentications, software vulnerabilities, surveillance, high level testing, best securities practices, vulnerability assessments, architecture etc. The candidate will monitor security before systems are released into a production environment.

This person must have strong communication skills as they will need to liaise with development teams, infrastructure teams and vendors, on a global scale.

You will need to have:
• Minimum of 5 years of relevant IT security work experience
• Solid experience architecting and implementing successful enterprise IT security projects
• Knowledge of the common application and infrastructure level vulnerabilities - ability to explain these risks to developers and senior management.
• Knowledge of the common mobile security vulnerabilities and security products available on the market.
• Ability to evaluate technical and functional specifications early within the software development process, identify possible threats or areas of weakness.
• Experience in taking part and contributing to design sessions.
• Knowledge of network technologies: SFTP, firewall, DMZ design, IPSec, VPN, Wireless, Network topologies and protocols
• Knowledge of Single Sign On technologies: SAML, Kerberos, Siteminder
• Knoweldge of entitlements and access controls as well as the various protocols for tracking records, such as LDAP

Platform: Although this role is not systems administration position, the candidate must have deep knowledge of at least one primary operating system (Unix or Windows), the configuration and management of that platform at an enterprise scale, the security risks to that platform, and how to mitigate those risks.

Mobile: The candidate will be expected to understand thoroughly the basic architecture of mobile applications, how the Apple iOS works and the common threats that effect any mobile device.

Network security: The candidate will be expected to understand the standard network model and the risks present at each layer, the functions of network equipment such as switches, routers, firewalls, proxies, vpn, and load-balancers, and to understand network architecture.

Testing tools: at least one of Fortify, OunceLabs, AppScan, WebInspect, Burp. The successful candidate will be able to explain the ‘hows and whys’ of the tools, as well as being experienced in using them.

Desirable skills:
• Technology background in the financial sector
• Frameworks, protocols and subsystems: J2EE, .NET, Spring, RPC, SOAP, MQSeries, JMS, RMI, JMX, Hibernate, Applet.
• Ability to review code of enterprise applications (Java required, prefer candidates with C/C++ and .NET) and identify possible security vulnerabilities
• N-Tier application design and implementation, particularly web-based applications that cross company boundaries.
• Knowledge of JSP /Servlet/EJB or ASP.NET, HTTP/HTTPS,[INVALID-WORD]s, AJAX, JavaScript, Flex / Silverlight.
• Knowledge of mobile computing
• Database design and programming experience
• Experience presenting complex security problems to senior management
• Experience of liaising with external penetration testing vendors
• Experience in conducting penetration tests, dynamic vulnerability assessments and static vulnerability assessments
• Experience in delivering a developer training for software security
• CISSP or other industry qualification

Compensation will match the criticality of the hire = HIGH.

If you would like to apply for this opening or discuss any other positions within banking and finance technology in Asia, please send an email to Amanda Leung at amanda.leung@bahpartners.com or call +852 2850-4877. For more roles, please visit our website: http://bahpartners.com/liveroles/