Quick Overview
Job Description
Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 11 countries, and more than 170 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as retail and neo banks. Our research led approach and continual innovation is powered by the passion and creativity of our colleagues.
We are always looking for talented people to join us on our mission to orchestrate the financial ecosystem and democratize access to wealth management. Avaloq offers the opportunity to work closely with some of the world’s leading financial institutions as we jointly develop and shape careers. Championing a collaborative, supportive and flexible work environment empowers our colleagues to reach their full potential.
The Avaloq Security team is an international team of senior and expert software engineers. The team develops and maintains central application security frameworks, platforms, and tools across company-wide technology stacks and consults business and technology teams on best-practice implementations for context-specific security requirements.
The team operates group-wide application security assessments, monitors and manages security vulnerabilities, and supports business teams in defining and implementing effective risk mitigation measures.
As a Senior Software Engineer in the Security Assurance team, you will play a key role in developing and maintaining the automation, tooling, and CI/CD capabilities that embed security into the software development and release lifecycle. You will work across software engineering, DevOps, cloud, application security, and vulnerability management to build scalable solutions that enable development teams to deliver secure and high-quality software.
Your key tasks
- Design, implement, and maintain internal CI/CD pipelines and automation tooling supporting vulnerability management, security assurance, reporting, and efficient software development workflows.
- Develop and maintain security integrations across the software delivery lifecycle, including source-code, repository, dependency, and container security scanning.
- Develop and maintain backend services and APIs supporting security scanning, vulnerability analysis, event processing, reporting, and integration with internal platforms.
- Monitor and maintain the daily automated build and security validation processes, analyse security warnings and findings, and provide guidance or implement fixes as required.
- Evaluate and validate detected vulnerabilities, assess exploitability and risk, investigate false positives, and support or develop appropriate remediation solutions.
- Maintain and enhance automated security analysis and vulnerability-processing workflows, including event-driven processing and integration with issue-management systems such as Jira.
- Develop and maintain security reporting and dashboards that provide actionable insights into vulnerabilities, remediation status, security risks, and compliance.
- Work with containerized applications and cloud-native environments, including Kubernetes, OpenShift, and Oracle Cloud Infrastructure (OCI).
- Coordinate security-related actions across multiple teams to ensure the quality, security, and timely remediation of Avaloq products.
- Participate in internal technical discussions, sharing knowledge on secure software development, vulnerabilities, security implementation, and opportunities for continuous improvement.
- University degree in Information Technology, Computer Science, Mathematics, Physics, or a related technical discipline.
- Strong experience designing, implementing, and maintaining internal CI/CD pipelines, developer tooling, and automation platforms.
- Senior-level software engineering expertise with hands-on experience in several of the following:
- Java / Spring Boot
- Python
- JavaScript / TypeScript
- Gradle
- Jenkins / Groovy
- REST APIs and service integration
- Event-driven architectures and messaging technologies
- Strong understanding of containerized applications and practical experience with Docker and Kubernetes and/or OpenShift, or similar container orchestration platforms.
- Knowledge and practical experience with Oracle Cloud Infrastructure (OCI) and cloud-native technologies is highly desirable.
- Deep understanding of application security concepts, security standards, secure software development practices, and industry best practices.
- Practical experience with vulnerability management platforms, security scanning tools, and automated security testing solutions.
- Experience integrating security tooling into CI/CD and software delivery pipelines.
- Understanding of software composition analysis, source-code security scanning, container security, and vulnerability lifecycle management is an advantage.
- Strong analytical and problem-solving skills, with excellent attention to detail and a commitment to delivering high-quality, reliable solutions.
- Ability to explain complex technical and security topics clearly to non-technical stakeholders.
- Positive and collaborative mindset, with the ability to work effectively across teams and promote engineering and security best practices throughout the organization.
- Experience or exposure to financial markets and financial products is an advantage.
We realize that managing work life balance is a challenge we all face in our daily lives and in order to support with this we are pleased to offer hybrid and flexible working for most of our Avaloqers to maintain work life balance and still continue our fantastic Avaloq culture in our global offices.
In Avaloq we are proud to embrace diversity and understand the success of our business is built on the power of different opinions, we are whole heartedly committed to fostering an equal opportunity environment and inclusive culture where you can be your true authentic self.
We hire, compensate and promote regardless of origin, age, gender identity, sexual orientation or any other fantastic traits that make us all unique, we have done our best to write this advert in an inclusive and neutral way.
Please be aware that we will not accept speculative CV submissions for any of our roles from recruitment agencies, and any unsolicited candidate submissions will be exempt from any payment expectations.