This job is no longer available
This job expired on 19/07/2026. It no longer accepts applications.
Application Security Engineer (Web & Mobile)
Avaib · Karachi
Job description
About the role
We are looking for an experienced Application Security Engineer to lead a high‑priority initiative aimed at closing application‑level security gaps identified during Amazon’s security review. The role focuses exclusively on web and mobile applications, translating Amazon’s compliance requirements into robust, production‑ready solutions.
Key responsibilities
- Identify and remediate application‑level security gaps to meet Amazon’s security requirements and industry standards.
- Implement encryption of sensitive data and personally identifiable information (PII) throughout the application stack.
- Design and integrate secure key‑management and secrets‑management solutions.
- Build fine‑grained role‑based access control (RBAC) and permission structures for all user types.
- Design and deploy multi‑factor authentication (MFA) and other authentication enhancements for web and mobile platforms.
- Review and remediate storage, transmission, access, and display of sensitive information.
- Strengthen authentication, authorization, session management, and account security controls.
- Implement audit logging and tracking of sensitive data access and security‑related activities.
- Integrate automated vulnerability scanning, SAST/DAST, and secure development practices into the CI/CD pipeline.
- Collaborate with cloud and security teams to ensure application changes support infrastructure‑level controls and compliance expectations.
Required profile
- 5+ years of experience in application security or secure software development.
- Proven track record delivering encryption, key‑management, RBAC, MFA, and secure authentication in production.
- Deep understanding of OWASP Top 10, secure coding practices, and vulnerability remediation.
- Experience integrating security tooling (SAST/DAST) into CI/CD pipelines.
- Familiarity with third‑party compliance frameworks such as Amazon, PCI DSS, or SOC 2 is a strong plus.
- Strong communication and collaboration skills for cross‑functional teamwork.
Required skills
- Data encryption
- Key management
- Secrets management
- Role‑based access control (RBAC)
- Multi‑factor authentication (MFA)
- Secure authentication and session management
- OWASP Top 10 knowledge
- Secure coding practices
- Vulnerability remediation
- SAST and DAST integration
- CI/CD pipeline security
- Web and mobile application security
- Compliance frameworks (Amazon, PCI DSS, SOC 2)
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Pakistan.
Salaries by job title
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Avaib
Karachi