TRCI-26-05030
Security Champion / Security Engineer (DevSecOps) – FEC Workflow Management
Primary security point of contact for the FEC Workflow Management area, responsible for embedding secure-by-design practices across the SDLC in an Agile/DevOps environment. The role drives threat modelling and architecture reviews, defines security requirements and acceptance criteria, integrates security testing (SAST/DAST/SCA) into CI/CD, and leads vulnerability, incident, and remediation activities. It also supports governance and compliance (audits, evidence, reporting KPIs/risks) and enables teams through training and coaching, with preference for regulated/banking context, Azure cloud security, and Pega/Pega Cloud exposure.
Position summary
- Location
- Netherlands
- Workplace
- On-site
- Employment
- Contract
- Experience
- Minimum 3 years and Maximum 5 years
Role overview
Why This Role Matters.
Primary security point of contact for the FEC Workflow Management area, responsible for embedding secure-by-design practices across the SDLC in an Agile/DevOps environment. The role drives threat modelling and architecture reviews, defines security requirements and acceptance criteria, integrates security testing (SAST/DAST/SCA) into CI/CD, and leads vulnerability, incident, and remediation activities. It also supports governance and compliance (audits, evidence, reporting KPIs/risks) and enables teams through training and coaching, with preference for regulated/banking context, Azure cloud security, and Pega/Pega Cloud exposure.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Promote security awareness, ownership, and secure-by-design practices.
Represent the area in security forums, governance bodies, and Security Champion communities.
Advise engineering, architecture, risk, and business stakeholders on security matters.
Embed security throughout the SDLC, from requirements to production.
Define security requirements and acceptance criteria.
Facilitate threat modelling and architecture reviews.
Promote secure coding practices and security-focused code reviews.
Integrate security testing (SAST, DAST, SCA) into CI/CD pipelines.
Ensure effective monitoring, logging, resilience, and disaster recovery controls.
Lead vulnerability reviews and remediation activities.
Support penetration testing and security assessments.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
DevSecOps
Secure SDLC
CI/CD
SAST
DAST
SCA
OWASP Top 10
Threat modelling
IAM
Authentication
Authorization
Encryption
Key management
Vulnerability management
Security monitoring
Logging
Operational resilience
Disaster recovery
Zero Trust
Defence-in-depth
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
3–5 years experience in cyber security/security engineering/DevOps/software engineering/IT risk management
Agile and DevOps ways of working
Stakeholder management and cross-functional collaboration
Secure SDLC / DevSecOps practices
Defining security requirements and acceptance criteria
Threat modelling and architecture/security reviews
Secure coding practices and security-focused code reviews
Integrating security testing into CI/CD (SAST, DAST, SCA)
Vulnerability management and remediation
Security controls and security monitoring/logging basics
Incident investigation/response support (security incidents, fraud-related threats)
Identity & Access Management (IAM) fundamentals
Authentication, authorization, encryption and key management fundamentals
Understanding of OWASP Top 10
Operational resilience basics (monitoring, logging, DR controls)
Preferred
Nice to Have
Banking/financial services or other regulated environments
Fraud prevention or sanctions exposure
Microsoft Azure cloud security
DevSecOps tooling and automation depth
Penetration testing and security assessments
Audit, risk assessments, and control reviews
Pega and/or Pega Cloud security knowledge
Zero Trust and defence-in-depth
Network security depth
SaaS security / cloud architecture security
Relevant certifications (Security+, AZ-900, SC-900, PenTest+, GISF, CISSP, CISM, CEH, CCSP, Microsoft Security certs, GIAC)
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Security Champion / Security Engineer (DevSecOps) – FEC Workflow Management
One page, about two minutes. We only ask for what we actually need to have a first conversation.