OANDA
Learn why OANDA has been a leading broker for over 25 years. Everyone at OANDA is focused on our vision to transform how our customers can meet all their currency needs. We are revolutionising the world of currency trading by providing innovative trading experiences, currency data and analytics solutions. Dare to be open, bold, focused - own it and apply! The future is now!
Join us and:
1. Work on an award-winning platform that processes billions of dollars every day.
2. Be on a team that’s responsible for company-wide top priority projects.
3. Contribute innovative ideas to improve the daily trading experience of thousands of customers.
4. Improve yourself and your team through education and continuous learning.
How do we work?
This is a hands-on position where you’ll have the opportunity to suggest, evaluate, take ownership, implement, configure and maintain numerous security solutions, investigate security incidents, perform application security reviews, vendor security assessments, write code for security sensitive applications, and other activities that can help improve OANDA’s security posture.
In this role, you will:
1. Act as the point of contact for Secure Software Engineering activities and reviews.
2. Help define Security processes and standards; own the education, implementation, and monitoring of them, especially application-security standards.
3. Drive the Vulnerability Management process; develop and implement procedures, and best practices to enhance the organization's security posture.
4. Conduct security assessments and audits to identify vulnerabilities and recommend remediation strategies.
5. Collaborate with cross-functional teams to ensure compliance with security policies and regulations.
6. Work with our engineering, ITSM, and project management teams to embed security components into our secure SDLC.
7. Respond to security incidents and perform investigations.
8. Spread Security Awareness across the company, by attending guild meetings, demos, and presenting at engineering all-hands and corporate townhalls.
9. Find opportunities for automating security.
10. Assist in audit and compliance activities.
11. Perform internal penetration tests.
12. Monitor and implement strategies and technologies to secure our Google Cloud environment, including the deployment and configuration of CSPM tools to monitor and manage the security posture of cloud environments.
What skillset you need, to be successful in this role:
1. Strong knowledge of at least one of the following scripting languages (Bash, Python, PowerShell).
2. Ability to work autonomously, and multi-task multiple projects at a time.
3. Deep knowledge of at least two Operating Systems (Linux, and at least one of Windows or macOS).
4. Excellent understanding of network, web, authentication, cryptography and security protocols, including tools used to perform their analysis.
5. Good knowledge in general security principles and best practices; and how to leverage them in a global, financial and regulated environment.
6. Knowledge of infrastructure, including firewalls, networks, load balancers, servers, and their security considerations in both on-premise and cloud environments.
7. Experience in improving the security of software development process.
8. Working experience with compliance standards and frameworks such as CIS, NIST, PCI-DSS, GDPR, SOC2 and ISO27001.
Nice to have:
1. Certifications with emphasis on Information Security such as CIPP, CISSP, CompTIA Security+ and CRISC.
2. Knowledge of additional programming languages (.NET, Go).
3. Experience with Google Cloud Platform (GCP).
4. Experience working in a regulated environment, particularly with financial regulators (NFA, MAS, FCA, CIRO, JFSA, KNF, ASIC).
OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.
Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy.
#J-18808-Ljbffr