Application Security Engineer

2 weeks ago


Lahore, Punjab, Pakistan Simplex Technology Solutions Full time 1,200,000 - 3,600,000 per year

Position Impact

As an Application Security Engineer, you will be at the forefront of securing our applications and infrastructure. You will work with cross-functional teams to embed security into the software development life cycle (SDLC), reduce risk exposure, and ensure compliance with industry standards. Your expertise will directly safeguard sensitive data, protect against emerging threats, and strengthen our overall security posture.

Roles & Responsibilities

· Partner with development teams to embed security principles and practices throughout the SDLC.

· Perform code security assessments to uncover vulnerabilities such as SQL injection, cross-site scripting (XSS), and insecure APIs.

· Lead threat modeling sessions and conduct risk assessments for upcoming features and services.

· Deploy, configure, and maintain tools for both static and dynamic application security testing.

· Assess security risks and propose effective mitigation and remediation strategies.

· Ensure sensitive data (e.g., credentials, tokens, keys) remains protected during builds and deployments.

· Collaborate with teams to remediate or replace insecure third-party libraries and components.

· Support internal and external audits concerning application and infrastructure security practices.

· Strengthen CI/CD pipelines and infrastructure by enforcing secure configurations.

· Monitor and stay informed on the latest exploits, vulnerabilities, and application security trends.

· Deliver training and mentorship to developers on secure coding standards and practices.

· Develop and maintain internal playbooks, documentation, and security guidelines.

· Ensure cloud services (AWS, Azure, GCP) are deployed with secure configurations and controls.

· Review, audit, and optimize access permissions, network policies, and identity management practices.

Requirements & Qualifications

· Bachelor's/Master's in Computer Science, Cybersecurity, or related discipline.

· Minimum 5 years of experience in Application Security, Security Engineering, or DevSecOps.

· Strong knowledge of web application vulnerabilities and remediation (OWASP Top 10, CWE Top 25).

· Experience with security testing tools such as Burp Suite, OWASP ZAP, Checkmarx, Veracode, or Fortify.

· Proficiency in secure coding practices across languages (Java, Python, JavaScript, C#, etc.).

· Hands-on experience with CI/CD and security automation (Jenkins, GitLab CI, GitHub Actions).

· Cloud security expertise in AWS, Azure, or GCP (IAM, secrets management, networking).

· Familiarity with container and microservices security (Docker, Kubernetes).

· Experience with compliance standards (ISO 27001, SOC 2, PCI DSS, GDPR).

Preferred Skills

· Security certifications such as OSWE, OSCP, GWAPT, CEH, or CISSP.

· Knowledge of Infrastructure-as-Code security (Terraform, CloudFormation).

· Experience with API security testing and automation.

  • · Strong communication and collaboration skills to bridge technical and non-technical teams.

Microservices Architecture:

  • Develop and maintain microservices-based architectures to ensure scalability and fault tolerance.
  • Implement service-to-service communication using protocols like gRPC or message brokers (e.g., SQS, RabbitMQ).
  • Ensure proper logging, monitoring, and error handling across all services.
  • Strong understanding of AWS Lambda and other microservices related products by AWS will be a plus.

Version Control and CI/CD:

  • Utilize advanced Git branching strategies (e.g., Git Flow, Trunk-Based Development) to manage codebase changes effectively.
  • Participate in code reviews to enforce quality standards and share knowledge within the team.
  • Automate deployment pipelines using CI/CD tools to streamline releases to EC2 instances running Nginx .

API Testing and Quality Assurance:

  • Use API testing frameworks and tools like Postman, Bruno , or Insomnia to validate API functionality and performance.
  • Write automated tests for APIs, including unit tests, integration tests, and end-to-end tests.
  • Collaborate with QA engineers to identify and resolve bugs before they reach production.

Production Support and Incident Management:

  • Monitor production systems to proactively detect and address issues.
  • Troubleshoot and resolve incidents affecting live environments, ensuring minimal downtime.
  • Document root cause analyses and implement preventive measures to avoid recurrence.

Mentorship and Knowledge Sharing:

  • Mentor junior developers and provide guidance on best practices for backend development.
  • Conduct workshops or training sessions to upskill the team on emerging technologies and methodologies.
  • Contribute to internal documentation and knowledge repositories.

Required Qualifications

  • Bachelor's degree in Computer Science, Software Engineering, or a related field (or equivalent experience).
  • 10+ years of professional experience in backend development using and frameworks like NestJS.
  • Proven track record of working on large-scale, multi-client production environments.
  • Expertise in relational databases, specifically MariaDB, including schema design, query optimization, and indexing.
  • Strong understanding of microservices architecture, including inter-service communication, load balancing, and containerization.
  • Proficient in Git workflows, including advanced branching strategies and conflict resolution.
  • Familiarity with API testing tools like Postman, Bruno, or similar frameworks.

Preferred Skills

  • Experience with containerization technologies like Docker and orchestration tools like Kubernetes.
  • Knowledge of message brokers such as SQS, RabbitMQ or Redis for asynchronous processing.
  • Familiarity with observability tools like Prometheus, Grafana, or ELK Stack for monitoring and logging.
  • Demonstrated ability to apply programming principles like SOLID, IoC, and DRY in real-world projects.


  • Lahore, Punjab, Pakistan CureMD Full time 600,000 - 1,200,000 per year

    Job Overview:The Application Security Analyst at CureMD plays a critical role in safeguarding our applications, data, and systems from potential security threats and vulnerabilities. This position involves in-depth technical expertise, and proactive security measures to maintain the integrity, confidentiality, and availability of our applications. As a...

  • Security Engineer

    1 week ago


    Lahore, Punjab, Pakistan Strukture Full time 900,000 - 1,200,000 per year

    We're Hiring: Security EngineerOurUS Clientneeds aSecurity Engineerwho can help him build secure, resilient, and scalable technology solutions. What You'll Do:Design, implement, and monitor security solutions across applications, networks, and cloud environmentsConduct security assessments, penetration testing, and risk analysisRespond to incidents and...

  • Security Engineer

    1 week ago


    Lahore, Punjab, Pakistan Cloud Primero B.V Full time 120,000 - 360,000 per year

    Cloud Primero B.V is looking for an experiencedSecurity Engineerto evaluate and strengthen the security of our infrastructure, applications, and data. The role will ensure all solutions meet regulatory requirements and organisational standards while supporting the design of secure future-state architectures.Key Responsibilities:• Conduct security audits...


  • Lahore, Punjab, Pakistan Simplex Technology Solutions Full time 70,000 - 120,000 per year

    Position Summary:We are seeking a highly skilled Sr. DevOps & Security Engineer with 5+ years of experience to lead the design, automation and security of our hybrid infrastructure. This role requires expertise in managing local data center environments (VMware vCenter/ESXi, firewalls, routers, and switches) as well as AWS production cloud environments. The...


  • Lahore, Punjab, Pakistan Astra Full time $90,000 - $120,000 per year

    About UsAstra is revolutionizing financial compliance through AI and blockchain-powered identityverification and KYC solutions. Our one-click identity platform seamlessly integrates biometricverification, document authentication, and real-time risk assessment to empower financialinstitutions with faster, more secure, and cost-effective compliance...


  • Lahore, Punjab, Pakistan Astra Full time 800,000 - 1,200,000 per year

    Astra is revolutionizing financial compliance through AI and blockchain-powered identity verification and KYC solutions. Our one-click identity platform seamlessly integrates biometric verification, document authentication, and real-time risk assessment to empower financial institutions with faster, more secure, and cost-effective compliance...


  • Lahore, Punjab, Pakistan HR Force International Full time 900,000 - 1,200,000 per year

    Job DescriptionWe are hiring Trainee Information Security Engineers who are passionate about cybersecurity and eager to build their careers in Penetration Testing, Governance-Risk-Compliance (GRC), and Security Operations (SOC). Selected candidates will undergo a 2-month structured training program covering core security concepts, labs, and real-world...


  • Lahore, Punjab, Pakistan Overseas Enterprises Full time 1,200,000 - 3,600,000 per year

    Company DescriptionOverseas Enterprises is a customer-driven, solution-focused company with over 60 years of experience in automation and control. Renowned for its professional staff and management, the company is committed to delivering quality services and adhering to deadlines. Overseas Enterprises offers a wide range of products, systems, solutions, and...


  • Lahore, Punjab, Pakistan M&N Business Full time 900,000 - 1,200,000 per year

    Position: Design & Application EngineerLocation: LahoreQualification: Electrical & Electronics EngineeringRequired Experience: At least 1-4 years of practical experience within the industrial automation industry.Perks & Benefits:Salary: Market Competitive Annual Bonus Vehicle Facility Medical Facility Annual, Casual and Medical Leaves And Many MoreKey...


  • Lahore, Punjab, Pakistan ICE Consulting Full time 1,200,000 - 2,400,000 per year

    Who We Are: We are a privately owned leading Managed IT Services company (Managed Service Provider). Since 1997 we have specialized in providing managed IT services and managed security services for our clients. which are made up of small to medium-sized enterprises. We are looking for highly passionate individuals to join our team to help and drive the...