Principal Security Software Engineer (Digital Banking)
Top 3 reasons to join us Hybrid working; Flexible time; Macbook Pro L&D programs; 17 days off 13.7 million B2C users; 140,000+ business customer Job description About the Role We're building the Authentication & Authorization platform for a new FSA-regulated digital bank in Japan. The platform powers OAuth 2.0/OIDC-based login, token lifecycle, and identity management across four banking channels — officer dashboards, customer-facing apps, BaaS APIs, and third-party service provider integrations. The team is located in Vietnam HCM city with high ownership. You'll own entire auth flows end-to-end — not just write tickets. What You'll Build Token lifecycle — DPoP-bound access tokens, token exchange (RFC 8693), silent refresh, session management Passkey/FIDO2 — WebAuthn registration & login flows, step-up authentication for sensitive operations mTLS integrations — certificate-based service-to-service auth with external financial platforms Shared security library — Spring Boot starter providing standardized auth filters across all backend services Integration testing — Karate-based test suites covering all auth flows at scale Monitoring — Auth event observability, anomaly detection, audit trail completeness Your skills and experience Must-Have Backend Over 10 years in server-side engineering, including 5 to 7 years specializing in Kotlin or Java with Spring Boot development. Redis — session management, distributed locking, caching PostgreSQL — schema design, migrations REST API design and HTTP security headers English proficiency (reading, writing, and verbal) — the primary working language across the team and organization for daily communication, code reviews, and technical documentation. Security & Auth Strong Spring Security expertise — filter chains, OAuth2 Resource Server Working knowledge of OAuth 2.0 / OIDC — authorization code, client credentials, token exchange, introspection Understanding at least one: DPoP (RFC 9449), mTLS (RFC 8705), PKCE , FIDO2/WebAuthn Familiarity with JWT structure — claims, JWKS, key rotation Strong knowledge of authentication, authorization, session management, and secure web application development. Strong understanding of the OWASP Top 10 — common web vulnerabilities, mitigation, and secure coding practices Infrastructure AWS — ECS/Fargate, Secrets Manager, VPC basics Terraform or similar IaC API integration testing (Karate preferred) Nice-to-Have Experience with Authlete FAPI 2.0 Security Profile or financial-grade API standards Microsoft Entra ID — SAML/OIDC federation, FIDO2 key enforcement Cloudflare/ Akamia — mTLS termination, WAF, client certificate forwarding WebAuthn/FIDO2 ceremonies — attestation, assertion, discoverable credentials Fintech/banking background — FSA regulations, maker-checker patterns, audit logging Japanese language ability (reading/basic communication) — a plus for requirement docs Why This Role Real regulated bank — not a fintech startup, not a toy project. FSA-supervised, launching in Japan. Cutting-edge security standards — FAPI 2.0, DPoP, WebAuthn/FIDO2. Few teams globally work at this intersection. High ownership — small team, big scope. You'll own entire authentication channels, not just implement tickets. Global collaboration — work with engineers across Japan, Vietnam, and India on a greenfield digital banking platform. Why you'll love working here Caring Mental & Physical Recreation: Hybrid working Full salary in probation & 13th month salary Social insurance on full salary from probation Premium Health insurance from probation Flexible start 8AM-9AM from Mon-Fri 16 days off annually + 1 Birthday Leave Paternity leave extra 5 days Annual company trip; Quarterly team building activities Club activities Annual health check Caring Career & Development: Clear Career path Foreign language & International technology-related certifications sponsoring Well-equipped facility: Macbook pro, additional monitor,.. Soft skill workshops Tech seminars Monthly and biannually Recognition Awards Performance review twice/year
Наблюдалась 2026-09-15, впервые 2026-09-08, источник — Indeed.