x
Get our mobile app
Fast & easy access to Jobstore
Use App
Congratulations!
You just received a job recommendation!
check it out now
Browse Jobs
Companies
Campus Hiring
Download App
Jobs in Singapore   »   Jobs in Singapore   »   Lead, DevSecOps
 banner picture 1  banner picture 2  banner picture 3

Lead, DevSecOps

Standard Chartered Bank

Standard Chartered Bank company logo

Key Responsibilities

Strategy
Towards delivering and living out our TTO Strategy 25 by

· Establish Strong Digital Foundations

· Accelerate Transformation

· Drive Process Excellence

Business

· Contribute to the strategic goals of the organisation through the application of technology.

· Solve problems through the application of technical knowledge and skill, determining when and how technology can solve business problems.

· Scope and create technical solutions that contribute to the business’s strategic goals

Processes

· Identify new areas of focus and activity for both internal and external technology communities

· Develop and roll out best practice in Technology domain of expertise or their specialism.

· Rescue, remediate or provide expertise on initiatives with significant technology challenge

People & Talent

· Lead through being an role model and build the appropriate culture and values.

· Set appropriate tone and expectations from their team and work in collaboration with risk and control partners.

· Ensure the provision of ongoing training and development of people and ensure that holders of all critical functions are suitably skilled and qualified for their roles ensuring that they have effective supervision in place to mitigate any risks.

· Employ, engage and retain high quality people.

· Responsibility to review team structure/capacity plans.

· Set and monitor job descriptions and objectives for direct reports and provide feedback and rewards in line with their performance against those responsibilities and objectives.

· Work with internal business teams, cross-functional engineering teams, and external vendors.

· Effective conflict resolver and strong leadership skills to deliver on commitments and knowing when to say No to stakeholder

Risk Management

· Responsibilities relating to identifying, assessing, monitoring, controlling and mitigating risks to the Group, as well as an awareness and understanding of the main risks facing the Group and the role the individual plays in managing them

· Make recommendations (and/or implement) to relevant stakeholders on possible risk management responses to identified risks and/or findings of concerns from investigations.

· Manage escalations on PEP / Sensitive issues requiring additional assessment and/or controls

Governance

· Responsibilities relating to the direction, planning, structure, frameworks (e.g. processes and policies) and oversight

· Responsible for assessing the effectiveness of the Group’s arrangements to deliver effective governance, oversight and controls in the business and, if necessary, oversee changes in these areas

· Awareness and understanding of the regulatory framework, in which the Group operates, and the regulatory requirements and expectations relevant to the role

· Take personal responsibility for understanding the risk and compliance requirements of the role.

· Understand and comply with, in letter and spirit, all applicable laws, and regulations, including those governing anti-money laundering, terrorist financing, and sanctions; the Group’s policies and procedures; and the Group Code of Conduct.

· Effectively and collaboratively identify, escalate, mitigate and resolve risk and compliance matters.

· Embed the Group’s values and code of conduct to ensure that adherence with the highest standards of ethics, and compliance with relevant policies, processes, and regulations among employee’s form part of the culture

Key stakeholders

· Application Development Community, DevOps Engineering, Security Architecture, Security Engineering, Control Owners

Skills & Experience

· Devops /Devsecops

· Public Cloud

· Containers, Kubernetes

Our Ideal Candidate

· 8+ years of experience in Full Stack development using modern front-end and back-end frameworks

· Bachelor's degree in computer science, information technology, or a related field. Relevant certifications

· Experience in threat modeling (Manual / Automation)

· Experience in creating / consume threat libraries

· Experience with Python, Go, Java, or Ruby

· Experience in Infrastructure as Code (IAC) tools like Terraform, Cloud formation

· Experience working with DevOps tools, for ex. Bitbucket, Jenkins and Artifactory

· Experience with Public Cloud platforms, for ex. AWS, Azure or GCP

· Experience in API layer like security, custom analytics, throttling, caching, logging, monetization, request and response modifications etc.

· Experience with Container platforms, for ex. Kubernetes, OpenShift, EKS, AKS or GKE

· Experience in automation using Cloud services, like AWS Lambda or Step Function

· Experience creating Splunk use cases (SIEM) and Splunk query language

· Critical thinking and problem-solving skills

· Communication skills and Decision-making

· Threat Modeling (Manual / Automation)

· Threat Modeling Framework STRIDE, MITRE

· Data Science

· Artificial Intelligence

· MySQL, MongoDB, or PostgreSQL

· HTML, CSS, React JS, Angular, Java, Python, Perl, Go

Role Specific Technical Competencies

· Communication skills and Decision-making

· Machine Learning – good knowledge of machine learning methods like k-Nearest Neighbors, Naive Bayes, SVM, Decision Forests.

· Data Wrangling – proficiency in handling imperfections in data is an important aspect of a data scientist job description.

· Experience with Data Visualization Tools like matplotlib, ggplot, d3.js., Tableau that help to visually encode data

· Cloud or Container Certifications like CKA, AWS SA, AZ-500, TF Associate

· Certified on Microsoft Azure Security Technologies, AWS security speciality and ATT&CK for Cyber Threat Intelligence are preferred

· Certification on Operationalizing MITRE ATT&CK, Foundations of Breach & Attack Simulation, Application of ATT&CK Navigator, Extending ATT&CK with ATT&CK Workbench

· Cyber Security Certification like CISSP, CCSP, CCSK

· Configuration as Code – Terraform, Ansible, Helm

· Policy as Code – Checkov, Inspec

· Scripting – Bash, Python

· React or Angular, and back-end frameworks, such as Node.js, Express.js and Django

About Standard Chartered

We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.

Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.

Together we:

· Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do

· Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well

· Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term

What we offer

In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.

· Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.

· Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.

· Flexible working options based around home and office locations, with flexible working patterns.

· Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits

· A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.

· Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.

Recruitment Assessments

Some of our roles use assessments to help us understand how suitable you are for the role you've applied to. If you are invited to take an assessment, this is great news. It means your application has progressed to an important stage of our recruitment process.

Visit our careers website www.sc.com/careers

Sharing is Caring

Know others who would be interested in this job?

Similar Jobs
Senior Executive Assistant
Morgan Mckinley Pte. Ltd.
Quick Apply
Logistics Coordinator
Henatenn Holdings Pte. Ltd.
Quick Apply
STRUCTURAL DESIGN ENGINEER – TUAS ( 51/2 DAY)
Union Manpower Services Pte Ltd
Quick Apply
business development director
Spax Engineering Pte. Ltd.
Quick Apply
Job Coach (Hospitality/Retail)
Apsn Ltd.
Quick Apply
Job Coach - Choa Chu Kang
Apsn Education Services Ltd.
Quick Apply
JUNIOR SCHOOL MANDARIN SUPPLY TEACHER
Dulwich College (singapore) Pte. Ltd.
Quick Apply
Warehouse/Logistics Assistant (Pharma/Biotech)
Nusantara Prime Consulting Pte. Ltd.
Quick Apply
Steel Structural Supervisor
Dara Engineering Pte. Ltd.
Quick Apply
General Manager, Business Development & Japan Desk
Logisteed Asia-pacific Pte. Ltd.
Quick Apply