Back to job search

Security Engineer

finnomena co., ltd. (Bangkok)
Bangkok, Thailand 🇹🇭
FINNOMENA is Thailand’s leading all-in-one digital wealth management platform for investors and financial advisors with over 100k investment accounts opened. Our goal is to “Unlock Your Investment Potential”. Our management team has over 50 years of combined industry experience in global financial institutions like JP Morgan, Krungsri, Citi, CIMB Principal, UOB among others. We utilizes our proprietary ML technology and a hybrid robo-advisory model to generate the above market returns and deliver an amazing tech-enabled user experience. We are the only fully integrated digital wealth management platform in the region that provides professionally generated investment content via our own investor’s knowledge hub (with over 30m in monthly views and >1.2m social media followers). We are different in our non-biased advisory approach by representing over 19 asset management companies and counting. FINNOMENA has achieved significant growth to date and is poised to scale rapidly; we recently raised a $10M Series B from reputed regional and local investors to further build and expand our business. Come join the fastest growing FinTech in Thailand! For more information please visit us at https://www.finnomena.com/ Finnomena in News: https://www.techinasia.com/finnomena-bags-10m https://www.businesstimes.com.sg/asean-business/wealth-management-platform-finnomena-franklin-templeton-to-bring-investment-solutions

About this position

We're looking for a skilled and experienced DevSecOps Engineer to join our team and champion a culture of security excellence. You'll play a pivotal role in automating security testing, collaborating with developers to build secure code, and conducting penetration testing to identify and remediate vulnerabilities before they reach production.

Responsibilities

• Design, implement, and automate DevSecOps processes and tools within our CI/CD pipeline.
• Conduct penetration testing on applications, infrastructure, and APIs, identifying and documenting vulnerabilities.
• Collaborate with developers to understand their needs and integrate security best practices into the development process.
• Analyze security vulnerabilities, prioritize risks, and recommend mitigation strategies.
• Develop and maintain security documentation, including threat models and attack surface diagrams.
• Stay informed about the latest security trends and threats, keeping our team and organization proactive against evolving risks.
• Participate in security incident response and remediation efforts.
• Foster a culture of security awareness within the organization through education and training initiatives.

Requirements

• Proven experience with penetration testing methodologies and tools (e.g., Metasploit, Burp Suite, Nmap, Zap, etc).
• 3+ years of experience as a DevSecOps Engineer or a related role.
• Strong understanding of DevSecOps principles and practices.
• Experience with CI/CD pipelines and automation tools (e.g., Jenkins, GitLab CI).
• Experience in Kubernetes (GKE, KUBECTL, HELM) and containers (Docker).
• Expertise in secure coding practices and application security frameworks.
• Good communication, collaboration, and problem-solving skills.
• Ability to work independently and as part of a cross-functional team.

Benefits

\
Huneety A.I Salary Estimate
30,000 - 45,000 THB per month