At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.
Senior Security Specialist
Location
United Kingdom
Posted
56 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Specialist
Zensar
Role Description We are currently looking for an experienced Senior Security Specialist (m/w/d) to drive our Securities Finance Trading & Collateral technology and services roadmap to the global Securities Finance & Collateral industry. Working closely with the Product Development management to deliver on our mission to deliver future state cloud-native solution together with simplifying the integrations with open API’s and provide seamless integrations. As a Senior Security Specialist, you are part of the Securities Finance Trading and Collateral core development team. You will be responsible for ensuring the security aspects of the platform. You will be required to investigate any potential security finding by automated tools, based on dependencies as well as other sources such as penetration testing. You will be interacting with central security teams to explain false positives and ensure vulnerabilities are resolved. Qualifications - At least 7+ year’s hands-on professional experience in the Java enterprise environment. - Experience building enterprise financial solutions. - Experience with Agile and test-driven development. - Experience in working in a distributed global environment. - Experience in investigating and resolving security related findings. - Experience in upgrading and working with 3rd party open source dependencies. - Very good expertise in Java SE/JEE, TypeScript. - Very good expertise in software design patterns, integration patterns and enterprise architectural concepts. - Hands-on experience with Spring Framework and Middleware, JMS and JPA/Hibernate. - Good understanding of web frontend technologies: Angular v2+, Observables, Redux. - Experience integrating with Identity and Access Management (IAM) systems, with good understanding of concepts like OAuth, OpenID Connect and Single Sign-on. - Adapting and integrating open-source frameworks and technologies. - Very strong communication skills and fluent in English. - Team player, Willingness to take responsibility. - Passionate about software development. Requirements - Investigate and resolve security findings across multiple versions of SFTC. - Ensure false positives are properly explained to central security team and approved as false positives. - Upgrade dependencies both Java as well as Typescript/Javascript libraries. - Resolve security vulnerabilities in no longer supported open source libraries. - Ensure any security related changes will not break existing functionality. Benefits - A varied, responsible job with a wide range of opportunities to contribute and to be innovative. - A modern, international working environment in committed and motivated teams.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Support the OLX Security Operations Center (SOC) by assisting with the incident response and its lifecycle • Contribute to incident response training for the organization • Assist in integrating our platforms and services with the SOC • Participate in “protect, detect, and respond” engineering tasks • Participate in Threat Hunting tasks • Participate in improving our threat intelligence system • Help develop, improve, and manage alerts of automated escalation processes • Work on custom integrations, which may require development skills in Python and Bash in containerized environments such as Kubernetes • Collaborate with other teams to streamline security across OLX, including Tech, Privacy, and Compliance teams.
Senior Cybersecurity Engineer at Convera Pune- WFH About the role: As part of the Security Operations team, you’ll be working with fellow team members and other engineering groups to implement new security solutions and ensure that our current processes and tools are running smoothly. This is a hands-on role that will help shape and develop our new cloud infrastructure security monitoring. This position reports into the Director of Security Operations who reports into the CISO. What we’re really looking for: We’re looking for a motivated security professional who enjoys building systems, integrating toolsets and AWS cloud security best practices. As mentioned, this is a hands-on role which will be crucial to building out and maturing our SIEM solutions. Job Responsibilities - Responsible for the implementation, administration, and maintenance of the SIEM platform. - Ensure data quality and identify any gaps in the security event collection. - Detect and respond to company-wise security incidents when needed. - Monitor SIEM health, monitor usage, and data growth. Desired background - 5+ years of experience in a security operational or analyst role preferably in a cloud native or hybrid cloud organization. - Strong background in cybersecurity, particularly in Security Information and Event Management (SIEM) systems related roles. - Detailed functional knowledge in developing security playbooks and implementing for orchestration, automation, and response. - Familiarity with SumoLogic is a plus but not a requirement. - High level software development skills: basic scripting, functional programming experience, familiarity with code repositories and deploy pipelines, etc. About Convera Convera is the largest non-bank B2B cross-border payments company in the world. Formerly Western Union Business Solutions, we leverage decades of industry expertise and technology-led payment solutions to deliver smarter money movements to our customers – helping them capture more value with every transaction. Convera serves more than 30,000 customers ranging from small business owners to enterprise treasurers to educational institutions to financial institutions to law firms to NGOs. Our teams care deeply about the value we bring to our customers which makes Convera a rewarding place to work. This is an exciting time for our organization as we build our team with growth-minded, results-oriented people who are looking to move fast in an innovative environment. As a truly global company with employees in over 20 countries, we are passionate about diversity; we seek and celebrate people from different backgrounds, lifestyles, and unique points of view. We want to work with the best people and ensure we foster a culture of inclusion and belonging. We offer an abundance of competitive perks and benefits including: • Competitive salary • Opportunity to earn an annual bonus. • Great career growth and development opportunities in a global organization • A flexible approach to work There are plenty of amazing opportunities at Convera for talented, creative problem solvers who never settle for good enough and are looking to transform Business to Business payments. Apply now if you’re ready to unleash your potential. #LI-AK1
• Proactively monitor Marqeta’s environment for cyber threat activity and manage day-to-day security alerts through timely analysis, triage, and appropriate response actions • Serve as incident commander during security events, directing investigation strategies and coordinating cross-functional response efforts • Execute incident response activities aligned with the NIST Incident Response Lifecycle to detect, contain, eradicate, recover, and learn from cybersecurity incidents • Contribute to the maintenance and improvement of the Cybersecurity Incident Response Plan (CIRP), playbooks, runbooks, and standard operating procedures to ensure consistent and effective response operations • Participate in 24x7x365 on-call rotations, providing skilled guidance during security incidents and contributing to thorough post-incident reviews • Research threat intelligence sources and contribute to hypothesis-driven threat hunting initiatives to uncover threats in corporate and production environments • Work closely with Security Engineering to tune security solutions, enhance detection capabilities, and leverage business knowledge to improve security monitoring • Design, develop, and maintain detection logic using a detections-as-code approach, collaborating with Security Solution Engineering to deploy detections through CI/CD pipelines into our SIEM and EDR platforms • Contribute to detection coverage mapped to MITRE ATT&CK framework, identifying gaps in visibility and supporting detection development prioritization based on threat intelligence and business risk • Coordinate with HR, law enforcement, response retainers, and cyber insurers as required, including support on cyber-crime financial fraud use cases • Support the development of less-experienced security team members through knowledge sharing, pair investigations, and leading by example • Partner with Fraud, Compliance, and Risk teams on security events involving payment systems, cardholder data, or regulatory reporting obligations under PCI DSS and related frameworks
Senior Security Engineer – Detection & Response
MarqetaYou see a card. We see endless possibilities.™
• Proactively monitor Marqeta’s environment for cyber threat activity and manage day-to-day security alerts through timely analysis, triage, and appropriate response actions • Serve as incident commander during security events, directing investigation strategies and coordinating cross-functional response efforts • Execute incident response activities aligned with the NIST Incident Response Lifecycle to detect, contain, eradicate, recover, and learn from cybersecurity incidents • Contribute to the maintenance and improvement of the Cybersecurity Incident Response Plan (CIRP), playbooks, runbooks, and standard operating procedures to ensure consistent and effective response operations • Participate in 24x7x365 on-call rotations, providing skilled guidance during security incidents and contributing to thorough post-incident reviews • Research threat intelligence sources and contribute to hypothesis-driven threat hunting initiatives to uncover threats in corporate and production environments • Work closely with Security Engineering to tune security solutions, enhance detection capabilities, and leverage business knowledge to improve security monitoring • Design, develop, and maintain detection logic using a detections-as-code approach, collaborating with Security Solution Engineering to deploy detections through CI/CD pipelines into our SIEM and EDR platforms • Contribute to detection coverage mapped to MITRE ATT&CK framework, identifying gaps in visibility and supporting detection development prioritization based on threat intelligence and business risk • Coordinate with HR, law enforcement, response retainers, and cyber insurers as required, including support on cyber-crime financial fraud use cases • Support the development of less-experienced security team members through knowledge sharing, pair investigations, and leading by example • Partner with Fraud, Compliance, and Risk teams on security events involving payment systems, cardholder data, or regulatory reporting obligations under PCI DSS and related frameworks


