
Application Security Engineer
5 hours ago
Position Impact
As an Application Security Engineer, you will be at the forefront of securing our applications and infrastructure. You will work with cross-functional teams to embed security into the software development life cycle (SDLC), reduce risk exposure, and ensure compliance with industry standards. Your expertise will directly safeguard sensitive data, protect against emerging threats, and strengthen our overall security posture.
Roles & Responsibilities
· Partner with development teams to embed security principles and practices throughout the SDLC.
· Perform code security assessments to uncover vulnerabilities such as SQL injection, cross-site scripting (XSS), and insecure APIs.
· Lead threat modeling sessions and conduct risk assessments for upcoming features and services.
· Deploy, configure, and maintain tools for both static and dynamic application security testing.
· Assess security risks and propose effective mitigation and remediation strategies.
· Ensure sensitive data (e.g., credentials, tokens, keys) remains protected during builds and deployments.
· Collaborate with teams to remediate or replace insecure third-party libraries and components.
· Support internal and external audits concerning application and infrastructure security practices.
· Strengthen CI/CD pipelines and infrastructure by enforcing secure configurations.
· Monitor and stay informed on the latest exploits, vulnerabilities, and application security trends.
· Deliver training and mentorship to developers on secure coding standards and practices.
· Develop and maintain internal playbooks, documentation, and security guidelines.
· Ensure cloud services (AWS, Azure, GCP) are deployed with secure configurations and controls.
· Review, audit, and optimize access permissions, network policies, and identity management practices.
Requirements & Qualifications
· Bachelor's/Master's in Computer Science, Cybersecurity, or related discipline.
· Minimum 5 years of experience in Application Security, Security Engineering, or DevSecOps.
· Strong knowledge of web application vulnerabilities and remediation (OWASP Top 10, CWE Top 25).
· Experience with security testing tools such as Burp Suite, OWASP ZAP, Checkmarx, Veracode, or Fortify.
· Proficiency in secure coding practices across languages (Java, Python, JavaScript, C#, etc.).
· Hands-on experience with CI/CD and security automation (Jenkins, GitLab CI, GitHub Actions).
· Cloud security expertise in AWS, Azure, or GCP (IAM, secrets management, networking).
· Familiarity with container and microservices security (Docker, Kubernetes).
· Experience with compliance standards (ISO 27001, SOC 2, PCI DSS, GDPR).
Preferred Skills
· Security certifications such as OSWE, OSCP, GWAPT, CEH, or CISSP.
· Knowledge of Infrastructure-as-Code security (Terraform, CloudFormation).
· Experience with API security testing and automation.
- · Strong communication and collaboration skills to bridge technical and non-technical teams.
Microservices Architecture:
- Develop and maintain microservices-based architectures to ensure scalability and fault tolerance.
- Implement service-to-service communication using protocols like gRPC or message brokers (e.g., SQS, RabbitMQ).
- Ensure proper logging, monitoring, and error handling across all services.
- Strong understanding of AWS Lambda and other microservices related products by AWS will be a plus.
Version Control and CI/CD:
- Utilize advanced Git branching strategies (e.g., Git Flow, Trunk-Based Development) to manage codebase changes effectively.
- Participate in code reviews to enforce quality standards and share knowledge within the team.
- Automate deployment pipelines using CI/CD tools to streamline releases to EC2 instances running Nginx .
API Testing and Quality Assurance:
- Use API testing frameworks and tools like Postman, Bruno , or Insomnia to validate API functionality and performance.
- Write automated tests for APIs, including unit tests, integration tests, and end-to-end tests.
- Collaborate with QA engineers to identify and resolve bugs before they reach production.
Production Support and Incident Management:
- Monitor production systems to proactively detect and address issues.
- Troubleshoot and resolve incidents affecting live environments, ensuring minimal downtime.
- Document root cause analyses and implement preventive measures to avoid recurrence.
Mentorship and Knowledge Sharing:
- Mentor junior developers and provide guidance on best practices for backend development.
- Conduct workshops or training sessions to upskill the team on emerging technologies and methodologies.
- Contribute to internal documentation and knowledge repositories.
Required Qualifications
- Bachelor's degree in Computer Science, Software Engineering, or a related field (or equivalent experience).
- 10+ years of professional experience in backend development using and frameworks like NestJS.
- Proven track record of working on large-scale, multi-client production environments.
- Expertise in relational databases, specifically MariaDB, including schema design, query optimization, and indexing.
- Strong understanding of microservices architecture, including inter-service communication, load balancing, and containerization.
- Proficient in Git workflows, including advanced branching strategies and conflict resolution.
- Familiarity with API testing tools like Postman, Bruno, or similar frameworks.
Preferred Skills
- Experience with containerization technologies like Docker and orchestration tools like Kubernetes.
- Knowledge of message brokers such as SQS, RabbitMQ or Redis for asynchronous processing.
- Familiarity with observability tools like Prometheus, Grafana, or ELK Stack for monitoring and logging.
- Demonstrated ability to apply programming principles like SOLID, IoC, and DRY in real-world projects.
-
Application Security Engineer
2 weeks ago
Lahore, Punjab, Pakistan Eonhealth Full timeWork with the industry leaderAt Eon, our mission is to make patients healthier and healthcare affordable. Eon Patient Management ("EPM") identifies patients with disease risk and streamlines clinical decision analysis so clinicians can work at the top of their licenses. With unique solutions across multiple disease states, we drive unprecedented adherence to...
-
Chief Application Security Specialist
2 weeks ago
Lahore, Punjab, Pakistan beBeeSecurity Full time $150,000 - $175,000Job DescriptionWe are seeking a seasoned Application Security Engineer to join our team. In this role, you will be responsible for improving our application security posture and ensuring the platform remains secure throughout the Software Development Life Cycle (SDLC).As an Application Security Engineer, you will analyze, test, and triage application...
-
Application Security Analyst
2 weeks ago
Lahore, Punjab, Pakistan CureMD Corporation Full timeApplication Security Analyst page is loadedApplication Security AnalystApply locations Lahore time type Full time posted on Posted 7 Days Ago job requisition id JR101753Job Overview:The Application Security Analyst at CureMD plays a critical role in safeguarding our applications, data, and systems from potential security threats and vulnerabilities. This...
-
Security Engineer
3 weeks ago
Lahore, Punjab, Pakistan Stewart Information Services Corp. Full timeFull time | Stewart Pakistan Pvt. Ltd. | PakistanPosted On 11/06/2024Job InformationJob Opening ID 115Work Timings 06:00 PM to 03:00 AMIT ServicesLocation Stewart IT Tower, C8X7+JJ4, Civic Center Twp Commercial Area Lahore, PunjabWork Experience 5-8 yearsCity LahoreState/Province Punjab54000About UsStewart Pakistan is a US-based organization with the Head...
-
Security Expert
2 weeks ago
Lahore, Punjab, Pakistan beBeeCybersecurity Full time $80,000 - $120,000Job Title: Cybersecurity ProfessionalThe Cybersecurity Professional plays a critical role in safeguarding applications, data, and systems from potential security threats and vulnerabilities.Key Responsibilities:Conduct comprehensive security assessments and vulnerability testing.Develop and implement effective security controls and...
-
Security Expert
6 days ago
Lahore, Punjab, Pakistan Viral Square Full time 1,200,000 - 3,600,000 per yearJob Description – Security ExpertPosition:Security Expert (Application & Web Security)About the RoleWe are seeking an experienced Security Expert with strong technical skills in application security, TLS/SSL, CDN/WAF configuration, and bot mitigation.The ideal candidate has hands-on experience with Python tooling, Akamai/CDNs, and defending against...
-
IT Security Specialist, IT
4 weeks ago
Lahore, Punjab, Pakistan ibex Full timeJoin to apply for the IT Security Specialist, IT role at ibex.This position is responsible for protecting IBEX infrastructure from emerging threats and assisting the organization in achieving its business objectives. It acts as an IS resource with strong concepts of web application assessments and penetration testing. The role includes coordinating and...
-
Cyber Security Engineer
1 week ago
Lahore, Punjab, Pakistan Arwen Tech Full timePosted on Sep 10, 2025ResponsibilitiesSummary of Job Profile: The Resident Engineer will be responsible for supporting PLRA in the following areas: incident handling and management, patch management (via SCCM), CIS hardening, vulnerability management and penetration testing program, and follow-ups on cybersecurity assessments.Running PLRA's patch management...
-
Dev-Secure-Ops Engineer
2 weeks ago
Lahore, Punjab, Pakistan Gtradecenter Full timeInvoZone is a growing company in Lahore, headquartered in Canada, that offers a combination of consulting, outsourcing, and specialized services to a global clientele across all types of web and mobile app development. The company was launched by experienced and visionary IT professionals with more than 10 years of industry experience in the fraternity of...
-
Associate Information Security Engineer
3 weeks ago
Lahore, Punjab, Pakistan Strategic Systems International Full timePURPOSE:We are seeking a motivated and detail-oriented Associate Information Security Engineer to support our security and compliance initiatives. This entry-level role is ideal for recent graduates or early-career professionals with foundational knowledge of networking, network security, and ISO27001 compliance. The successful candidate will contribute to...