- Bachelor’s or Master’s degree in Information Security, Computer Science, or related field
- 4+ years of experience in application or software security, preferably in a financial institution or regulated environment
- Strong knowledge of secure software development practices (OWASP Top 10, CWE/SANS Top 25)
- Experience with application security tools: SAST, DAST (e.g., Burp Suite, OWASP ZAP), and SCA tools
- Deep knowledge of programming languages (e.g., Java, C#, Python, JavaScript) and web/mobile app architectures
- Knowledge of container security and cloud security practices (Azure, AWS, or GCP).
- Understanding of SDLC, Agile, DevOps, and CI/CD environments
- Analytical mindset with strong problem-solving skills
- Excellent communication and collaboration skills
Certifications (a plus):
- CSSLP, OSCP, Microsoft Cybersecurity Architect Expert or other relevant security certifications