The Financial Crime Compliance team provides proactive guidance to mitigate risks such as corruption, financial crime, fraud, and cybercrime. Leveraging global expertise, we help organizations swiftly respond to crises and protect brand reputation through actionable advice and effective risk management strategies.
Seeking a Manager/Deputy Manager with strong experience in application security, SDLC governance, and application-level control analysis. The role focuses on evaluating how applications are built, configured, and used through technical testing, control reviews, and transaction/log analysis.
Key Responsibilities: • Evaluate application architecture and design from a controls perspective • Assess SDLC processes including requirement definition, workflow configurations, change management, and release governance • Review application controls such as access management, maker-checker, and system validations • Perform application testing (functional, logic, and security-focused) using manual and automated approaches • Identify gaps in business logic, workflows, and control configurations • Review APIs, integrations, and data flows for consistency and control weaknesses • Analyze application logs, audit trails, and transaction datasets to trace end-to-end flows and identify anomalies • Document findings and provide practical recommendations to business, operations, and technology stakeholders • Manage engagement delivery, lead/mentor junior team members, and contribute to practice development
Technical Expertise: Hands-on Experience: • Application testing (manual and automated) • Application logging and monitoring architectures • Secure coding concepts (Java, .NET, Python, or similar) Strong Understanding: • OWASP Top 10 vulnerabilities (control/design validation lens) • Authentication, authorization, and session management • API security and microservices architecture Tools & Platforms: • Burp Suite / AppScan / Fortify / Checkmarx • SIEM / log analysis tools (e.g., Splunk, QRadar)
Required Qualifications
5 to 8 years of experience
Applications security
SDLC governance including forensic review of codes, applications and system logs
BRDs, functional specification documents, UATs specific to applications fraud scenarios in FinTech space
Exposure to high transaction environments (BFSI, fintech, e-commerce)
Preferred Qualifications
CEH certification
CISSP certification
CFE certification
Skills Required
Application TestingSecure Coding (Java/.NET/Python)OWASP Top 10API SecurityMicroservices ArchitectureBurp SuiteAppScanFortifyCheckmarxSplunkQRadarSDLC GovernanceApplication Logging & MonitoringAccess Control & Session ManagementFinancial Crime Compliance