Job Summary
We're looking for a hands-on application security engineer who can audit source code across web, mobile, and backend stacks, run the full spectrum of security testing (SAST, DAST, IAST, penetration testing), and produce actionable security certifications and reports.
Core responsibilities
- Conduct thorough code audits across web , mobile (React Native), and backend (Node.js, Python, Java, Go, .NET) codebases to identify security vulnerabilities.
- Design and execute SAST, DAST, IAST, and SCA scans using industry tools; triage findings and drive remediation with engineering teams.
- Perform manual penetration testing on web applications, REST/GraphQL APIs, and mobile apps — covering OWASP Top 10, business logic flaws, and authentication weaknesses.
- Experience with API security testing (GraphQL introspection, gRPC, WebSockets) beyond standard HTTP.
- Produce formal security assessment reports and application security certifications that meet compliance requirements (SOC 2, ISO 27001, PCI-DSS, HIPAA as applicable).
- Define and maintain a secure coding standards library and developer security training programme.
- Perform threat modelling (STRIDE/PASTA) during design reviews for new features and architecture changes.
- Manage and triage external vulnerability disclosures and bug bounty submissions.
Key Responsibilities
Required skills and experience
- 5+ years in application security, with direct experience auditing at least two of: web, mobile, and backend systems.
- Deep familiarity with OWASP Top 10 (Web and Mobile), CWE/SANS Top 25, and secure coding principles across multiple languages.
- Proficient in at least one scripting/programming language (Python, JavaScript, or Bash) to automate security workflows and write custom detection rules.
- Experience producing formal security reports, risk ratings (CVSS), and remediation guidance consumable by both technical and non-technical stakeholders.
- Hands-on experience with cloud-native security posture (AWS, GCP, or Azure) — IAM misconfigurations, S3/storage exposure, secrets management.
- Understanding of authentication and authorisation protocols: OAuth 2.0, OIDC, SAML, JWT, mTLS.
- Experience integrating security into DevSecOps pipelines — shift-left tooling, pre-commit hooks, pipeline gates.
Skill Requirements
We're looking for a hands-on application security engineer who can audit source code across web, mobile, and backend stacks, run the full spectrum of security testing (SAST, DAST, IAST, penetration testing), and produce actionable security certifications and reports.
Core responsibilities
- Conduct thorough code audits across web , mobile (React Native), and backend (Node.js, Python, Java, Go, .NET) codebases to identify security vulnerabilities.
- Design and execute SAST, DAST, IAST, and SCA scans using industry tools; triage findings and drive remediation with engineering teams.
- Perform manual penetration testing on web applications, REST/GraphQL APIs, and mobile apps — covering OWASP Top 10, business logic flaws, and authentication weaknesses.
- Experience with API security testing (GraphQL introspection, gRPC, WebSockets) beyond standard HTTP.
- Produce formal security assessment reports and application security certifications that meet compliance requirements (SOC 2, ISO 27001, PCI-DSS, HIPAA as applicable).
- Define and maintain a secure coding standards library and developer security training programme.
- Perform threat modelling (STRIDE/PASTA) during design reviews for new features and architecture changes.
- Manage and triage external vulnerability disclosures and bug bounty submissions.
Other Requirements
Required skills and experience
- 5+ years in application security, with direct experience auditing at least two of: web, mobile, and backend systems.
- Deep familiarity with OWASP Top 10 (Web and Mobile), CWE/SANS Top 25, and secure coding principles across multiple languages.
- Proficient in at least one scripting/programming language (Python, JavaScript, or Bash) to automate security workflows and write custom detection rules.
- Experience producing formal security reports, risk ratings (CVSS), and remediation guidance consumable by both technical and non-technical stakeholders.
- Hands-on experience with cloud-native security posture (AWS, GCP, or Azure) — IAM misconfigurations, S3/storage exposure, secrets management.
- Understanding of authentication and authorisation protocols: OAuth 2.0, OIDC, SAML, JWT, mTLS.
- Experience integrating security into DevSecOps pipelines — shift-left tooling, pre-commit hooks, pipeline gates.