This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join us as a Security Engineer- Identity Access Management. You will be bringing to life a new digital platform capability, transforming, and modernising our digital estate to build a market-leading digital offering with customer experience at its heart. You will be partnering with business aligned engineering and product teams, to ensure a collaborative team culture is at the heart of what we do.
Job Responsibility:
Development and implementation of protocols, algorithms, and software applications to protect sensitive data and systems
Management and protection of secrets, ensuring that they are securely generated, stored, and used
Execution of audits to monitor, identify and assess vulnerabilities in the banks infrastructure/software and support the response to potential security breaches
Identification of advancements in to support the innovation and adoption of new cryptographic technologies and techniques
Collaboration across the bank, including developers and security teams, to ensure that cryptographic solutions align with business objectives, security policies and regulatory requirements
Development/ Implementation and maintenance of Identity and Access Management solutions and systems
Requirements:
Hands-on IAM (Identity Access Management) engineer background with broad expertise across the IAM (Identity Access Management) domain, including tooling, products, protocols, taxonomy, identity management, authentication, authorization, and identity federation
Experience with single sign on, OAuth2, OIDC, PKI, PSD2 SCA knowledge and possession-based authentication
Experience with ForgeRock developer experience with Ping Gateway, Ping AM, Ping IDM, and Ping DS, including JavaScript coding of Ping Gateway scripted routes, and Ping AM authentication tree nodes is an advantage
Strong hands-on coding across either JavaScript or Java, and you must be comfortable in designing extensible IAM APIs for seamless integration with external and internal applications
Working knowledge of implementing Ping AM custom authentication trees, including downstream API integration with threat sensors (Threat Metrix, Bio Catch, etc.), adaptive authentication and step-up authentication, including the ability to implement data links between internal and external LDAPS, JDBC, SOAP, HTTPS, and other data sources
Experience in implementing Ping Gateway single-sign-on routes, dynamic proxies and filter chains, or implementing Ping IDM based data links
Experience in partnering with security, product, engineering, and compliance teams, to embed identity-first principles into the DevSecOps lifecycle