At Julius Baer, we celebrate and value the individual qualities you bring, enabling you to be impactful, to be entrepreneurial, to be empowered, and to create value beyond wealth.
Let’s shape the future of wealth management together.
Julius Baer Group Ltd.
acts in the sector Private Banking and is present in over 25 countries and around 60 locations.
With the Headquartered in Zurich, we have offices in key locations including Bangkok, Dubai, Dublin, Frankfurt, Geneva, Hong Kong, London, Luxembourg, Madrid, Mexico City, Milan, Monaco, Mumbai, Santiago de Chile, São Paulo, Shanghai, Singapore, Tel Aviv and Tokyo.
Join our global team and play a critical role in safeguarding our digital landscape as a Web Application Security Engineer.
We're seeking a skilled expert to maintain and enhance the protection of our online platforms, ensuring the highest level of security for our clients worldwide.
YOUR CHALLENGE
Main Job Responsibilities
Work closely with our global team of engineers to ensure the smooth operation and maintenance of the Web Application Firewall (WAF) infrastructureEnhance the security of web applications and APIs by implementing advanced protective measures on the WAF and configuring custom application-specific security policiesOnboard new web applications and APIs onto the WAF infrastructure, ensuring seamless integration and optimal securityEvaluate new or changed business requirements and assess their feasibility, as well as their impact on surrounding systems, standards, and guidelinesTroubleshoot technical issues related to WAF, identifying root causes and developing effective solutionsParticipate in the 2nd and 3rd level support organization, providing on-duty support and collaborating with other teams to resolve incidentsContinuously improve the service reliability, security, performance, monitoring, and automation of the WAF infrastructure, with a focus on enhancing overall system availability and efficiencyClient Management (internal & external)
Various IT functions, both regionally and globallyLocal Legal and Compliance functionsBusiness Management
Key local stakeholders include IT Service Owners, IT Infrastructure, IT Application Managers, IT Architecture and Project ManagersCRO functions – including Business Operational Risk, Information Security and Compliance functionsGlobal functions – IT Security Solutions, Security ArchitectureEstablish strong relationship with key stakeholders and across the internal ITRegulatory Responsibilities &/OR Risk Management
Ensure appropriate ethical and compliant behaviour within the area of responsibility by clear demonstration of appropriate values and behaviours including but not limited to standards on honesty and integrity, due care and diligence, fair dealing (treating customers fairly), management of conflicts of interest, competence and continuous development, adequate risk management, and compliance with applicable laws and regulations
RANK APPLICABLE TO THE POSITION
Rank: ADYOUR PROFILE
Professional and Technical
Profound understanding of security best practices of web applications and APIsSolid understanding of web communication protocols such as HTTP, TLS, Websocket, etcHands-on operational experience with highly available and scalable web infrastructureHands-on experience with operating WAF or reverse-proxy solutions such as F5, Imperva, Nevis, Cloudflare, or open-source alternatives like ModSecurityExperience in software engineering (Java, Spring Boot, React, Typescript) and operational experience with Kubernetes-based environmentsStrong troubleshooting and structured problem-solving skillsSkilled in log analytics and correlation, with hands-on experience in Splunk, Elastic or similar toolings, to investigate incidents and identify root causesFamiliarity with the implementation of authentication and federation mechanisms such as SAML, OAuth and OIDC and FIDOGood technical foundation of Linux operating systems and its command line toolsRelevant academic background (e.g., Bachelor's or Master's degree in Computer Science, Cybersecurity, or related field) or industry-recognized certifications (e.g. CISSP) with relevant practical knowledge is desiredPersonal and Social
Team player, strong collaborator with the willingness to take ownershipExcellent communication skills in spoken and written formStrong desire to learn and develop new skillsMethodical and results-driven approach to new challenges and tasksIndependent and self-drivenAbility to thrive in a globally distributed team environmentRegulatory
Good understanding of the technology regulatory framework in Singapore and Hong KongWe are looking forward to receiving your full job application through our online application tool.