Back to Jobs

Principle Security Software Engineer

Principle Security Software Engineer
Ho Chi Minh
Tech/Engineer

ABOUT THE ROLE

We're building the Authentication & Authorization platform for a new FSA-regulated digital bank in Japan. The platform powers OAuth 2.0/OIDC-based login, token lifecycle, and identity management across four banking channels — officer dashboards, customer-facing apps, BaaS APIs, and third-party service provider integrations.

The team is located in Vietnam HCM city with high ownership. You'll own entire auth flows end-to-end — not just write tickets.

WHAT YOU WILL BUILD

  • Token lifecycle — DPoP-bound access tokens, token exchange (RFC 8693), silent refresh, session management
  • Passkey/FIDO2 — WebAuthn registration & login flows, step-up authentication for sensitive operations mTLS integrations — certificate-based service-to-service auth with external financial platforms
  • Shared security library — Spring Boot starter providing standardized auth filters across all backend services
  • Integration testing — Karate-based test suites covering all auth flows at scale
  • Monitoring — Auth event observability, anomaly detection, audit trail completeness

MUST HAVE

Backend

  • Over 10 years in server-side engineering, including 5 to 7 years specializing in Kotlin or Java with Spring Boot development.
  • Redis — session management, distributed locking, caching
  • PostgreSQL — schema design, migrations
  • REST API design and HTTP security headers
  • English proficiency (reading, writing, and verbal) — the primary working language across the team and organization for daily communication, code reviews, and technical documentation.

Security & Auth

  • Strong Spring Security expertise — filter chains, OAuth2 Resource Server
  • Working knowledge of OAuth 2.0 / OIDC — authorization code, client credentials, token exchange, introspection
  • Understanding at least one: DPoP (RFC 9449), mTLS (RFC 8705), PKCE, FIDO2/WebAuthn
  • Familiarity with JWT structure — claims, JWKS, key rotation
  • Strong knowledge of authentication, authorization, session management, and secure web application development.
  • Strong understanding of the OWASP Top 10 — common web vulnerabilities, mitigation, and secure coding practices
  • This role expects a strong security mindset, with a clear understanding of data privacy, credential protection, device security, and the responsible use of corporate systems, tools, and accounts.

Infrastructure

  • AWS — ECS/Fargate, Secrets Manager, VPC basics
  • Terraform or similar IaC
  • API integration testing (Karate preferred)

NICE TO HAVE

  • Experience with Authlete
  • FAPI 2.0 Security Profile or financial-grade API standards
  • Microsoft Entra ID — SAML/OIDC federation, FIDO2 key enforcement
  • Cloudflare/ Akamia — mTLS termination, WAF, client certificate forwarding
  • WebAuthn/FIDO2 ceremonies — attestation, assertion, discoverable credentials
  • Fintech/banking background — FSA regulations, maker-checker patterns, audit logging
  • Japanese language ability (reading/basic communication) — a plus for requirement docs

WHY THIS ROLE

🏦 Real regulated bank — not a fintech startup, not a toy project. FSA-supervised, launching in Japan.

🔐 Cutting-edge security standards — FAPI 2.0, DPoP, WebAuthn/FIDO2. Few teams globally work at this intersection.

🚀 High ownership — small team, big scope. You'll own entire authentication channels, not just implement tickets.

🌏 Global collaboration — work with engineers across Japan, Vietnam, and India on a greenfield digital banking platform.
 


Our benefits
Our benefits

Caring Mental & Physical Recreation:

  • Hybrid working: 2 days at the office and 3 days WFH
  • Working hour: Flexible start 8AM-9AM from Mon-Fri
  • Full salary in probation
  • Insurance: Applied from Probation period:
    • Social Insurance, Health Insurance, Unemployment Insurance (on 100% salary)
    • Private health insurance & accident insurance. From Managing level: extra for family members
  • Bonus: 13th month salary
  • 16 - 24 paid days off and more
  • Paternity leave: Extra 5 days
  • Annual company trip; Quarterly team building
  • Billiards & Running club
  • Annual health check
  • Well-equipped facility: Macbook pro, additional monitor,..

Caring Career & Development:

  • Clear Career path
  • Foreign language & International technology-related certifications sponsoring
  • External & internal training courses
  • Soft-skill workshops
  • Tech seminars
  • Monthly and biannual Recognition Awards
  • Performance & salary review: twice/year (Jun & Dec)
banner apply
banner apply mobile
Not found any
ideal
position yet?
Just leave your CV and we will
contact you for upcoming
opportunities.