Nordea: IT Developer - Senior (42961)
Job description
Detailed description of work task to be carried out
The developer will contribute to the ongoing development of the Automated Security Retest Engine, a security retesting platform that automates the analysis of security assessment reports and the verification of remediation actions.
The work includes developing and maintaining a Python-based processing pipeline and the Java Spring Boot web application, which provides a user interface.
Responsibilities will include designing and implementing features, integrating external tools and APIs, improving the reliability and quality of generated tests and analysis, writing automated tests, investigating defects, and maintaining technical documentation. The developer will work with security and product stakeholders to translate requirements into practical, maintainable software.
Security is a core requirement: changes must preserve configured target-scope restrictions, protect credentials and user data, validate inputs, and provide reliable evidence for retest outcomes.
Must-have knowledge and experience
Professional software development experience in Python and/or Java.
Experience developing and maintaining backend applications and REST APIs.
For Java development: familiarity with Spring Boot and common application-development practices.
For Python development: familiarity with modular application design, dependency management, and automated testing.
Experience writing and maintaining automated tests.
Working knowledge of Git and collaborative software-development workflows, including code reviews.
Understanding of secure software development, including input validation, authentication and authorization, and safe handling of secrets.
Ability to analyze an existing codebase, troubleshoot issues, and deliver changes with appropriate documentation.
Good written and spoken English for technical communication.
Nice-to-have knowledge and experience
Experience with both Python and Java/Spring Boot.
Experience integrating LLM APIs or building LLM-assisted workflows, including structured-output validation and error handling.
Familiarity with application security testing, especially DAST and SAST.
Experience with tools such as OWASP ZAP, Nuclei, Semgrep, pytest, or security-test automation.
Experience with PDF processing, OCR, or document extraction.
Familiarity with web technologies such as JavaScript, HTML, CSS, Bootstrap, and Thymeleaf.
Experience with SQL databases, Maven, CI/CD, Docker, or cloud services.
Interest in application security, vulnerability remediation, and security engineering.
Skills mentioned
Apply for this job
Use the application link supplied with this listing to apply to B2B Network. Check the destination before entering personal information.

