A2Z-CM N.V. logo

Security & Vulnerability Assessor (Secure Coding)

A2Z-CM N.V.

Amstelveen
Contractor
5-10 years experience
Hybrid

Key Skills

Secure coding
Application security
SAST
SCA
Fortify
Nexus Lifecycle
Software development
Vulnerability assessment
Risk management
AI-driven threats
Agentic development
Communication
Stakeholder management
Tooling improvement

Job Description

Introduction 36 hours per week Start date: ASAP Duration: 1-year assignment with the possibility of extension Hybrid working. ZZP is allowed. Relocation is not possible. Job description The Development Services department is the knowledge center for everything concerning software development. It's goal is to continuously improve the quality of the software development process and it's deliverables. To accomplish that mission, we harvest best practices from the development community and translate these into standards and guidelines. Common for all technologies is the need for strong security. The Secure Coding (SECO) team takes care of all matters concerning the security of software development. A Domain Expert for SECO helps development teams in the organization with improving the quality of security of their products. In this role, you’ll work closely with development teams across the bank. You’ll help them understand and fix security findings, improve how our tooling works, and contribute to solutions that make secure development easier. You’ll also be involved in looking at new topics like AI-driven threats and agentic development. You’ll be working at the intersection of security and development, helping teams deal with vulnerabilities in an efficient and effective way. What you’ll be doing: - Maintain and improve our security posture. - Maintain Secure Coding Standards. - Triage and analyse findings from SAST & SCA tools like Fortify and Nexus Lifecycle. - Help developers understand what a security finding really means, and how they can solve it. - Support teams in fixing vulnerabilities in their code. - Improve and fine-tune rulesets to reduce noise and increase quality. - Contribute to internally developed tools such as our Repository Scanner (RESC). - Think along about how we handle new risks, including AI-driven attacks. - Share knowledge and help teams become more secure over time No two days are exactly the same some days you’ll be deep in code, other days you’ll be discussing solutions with teams or improving tooling. Requirements You’re someone who’s comfortable working with code and enjoys helping others improve. You don’t need to know everything, but you’re curious and pragmatic. What we’re looking for: - Experience in secure coding and application security. - Proficient in software development in at least one programming language. - Experience with SAST & SCA tools like Fortify, Nexus Lifecycle, or similar. - Experience in analysing and prioritising secure coding findings. - Able to communicate well with developers and explain things clearly. - Large corporate organisational sensitivity. - Fluent English.

Core Responsibilities

The role involves maintaining security standards and triaging findings from SAST and SCA tools to improve the organization's security posture. You will collaborate with development teams to remediate vulnerabilities and contribute to the development of internal security tooling.

Requirements

Candidates must have experience in secure coding, application security, and proficiency in at least one programming language. Strong communication skills and experience with SAST/SCA tools like Fortify or Nexus Lifecycle are required.

About A2Z-CM N.V.

Industry: Business Consulting and Services

Company size: 51-200 employees

A2Z-CM is an independent private company founded in 2012 with offices in Amsterdam and United Kingdom. A2Z-CM is a vendor-neutral, fully-compliant company offering consultancy services, contract management and international brokering to suppliers and agencies in the Netherlands and other countries according to the principle of think global, act local. The A2Z-CM team assist clients by analysing their organisational issues and implementing realistic and cost-effective development plans. Think global, act local. At A2Z-CM, our specialists offer a combination of IT and technical experience, plus a thorough knowledge of compliance and risk mitigation. Our thorough grasp of both fields means that you get solutions tailored to meet your specific needs - solutions that are fully compliant. A2Z-CM provides Clients and contractors with clear, friendly and professional advice on all aspects of the local fiscal and legal regulations. It's our job to deliver a comprehensive range of services, leaving you free to focus on your core business or project.

Added Today