Domain Expert – Secure Coding (SECO) - 10826782
Itproposal · Amstelveen, North Holland, Netherlands · Hybrid
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Requirement ID: 10826782
Job Title: Domain Expert – Secure Coding (SECO)
Location: Amstelveen / Amsterdam, Netherlands (Hybrid)
Contract Duration: 6 Months
Start Date: 1 September 2026
Experience Required: 6–8 Years
Industry: Banking / Financial Services
Employment Type: Contract
Job Summary
We are seeking an experienced Domain Expert – Secure Coding (SECO) to join the Development Services department within a large-scale regulated banking environment.
The Secure Coding (SECO) team acts as the knowledge center for software security, helping development teams improve the security, quality, and resilience of their applications. The successful candidate will work at the intersection of application security and software development , supporting engineering teams in identifying, understanding, and resolving security vulnerabilities.
This role focuses on improving secure coding practices, analyzing security findings, enhancing security tooling, and enabling developers to build secure software by design.
The ideal candidate will have strong experience in secure coding, application security, SAST/SCA tooling, software development, vulnerability management, and DevSecOps practices .
Key Responsibilities
Secure Coding & Application Security
Maintain and improve the organization's software security posture.
Define, maintain, and improve secure coding standards and guidelines.
Support development teams in implementing secure software development practices.
Provide guidance on application security best practices.
Help teams understand security risks and implement effective remediation strategies.
Security Findings Analysis & Vulnerability Management
Analyze and triage security findings from tools such as:
Fortify (SAST)
Nexus Lifecycle (SCA)
Similar security scanning tools
Review, prioritize, and categorize vulnerabilities based on risk and business impact.
Help developers understand security findings and provide remediation guidance.
Support development teams in fixing vulnerabilities within applications.
Improve vulnerability remediation processes.
Security Tooling Improvement
Improve and optimize security tooling capabilities.
Fine-tune security rulesets to:
Reduce false positives
Improve detection accuracy
Increase security quality
Contribute to internally developed security tools, including Repository Scanner (RESC).
Support automation initiatives around application security processes.
DevSecOps & Development Enablement
Collaborate closely with development teams across the organization.
Integrate security practices into software development workflows.
Support secure CI/CD practices.
Promote security-by-design principles.
Share knowledge and educate engineering teams on secure development practices.
Emerging Security Topics
Research and contribute to new security challenges, including:
AI-driven security threats
Agentic AI development risks
Emerging application security vulnerabilities
Help…