Cyber Security Engineer - Application Security & Compliance (Web & Mobile)
Avaib · Karachi
Job description
About the role
We are looking for an experienced Cyber Security Engineer specialized in application security and compliance to lead a critical initiative aimed at closing security gaps identified during Amazon's security review. This hands‑on role focuses exclusively on web and mobile application protection, translating Amazon’s requirements into robust, production‑ready solutions.
Key responsibilities
- Identify and remediate application‑level security gaps to meet Amazon and industry standards.
- Implement end‑to‑end encryption of sensitive data and personally identifiable information.
- Design and integrate secure key‑management and secrets‑management solutions.
- Build fine‑grained role‑based access control (RBAC) and permission structures.
- Design and deploy Multi‑Factor Authentication (MFA) and other authentication enhancements for web and mobile.
- Review and secure data storage, transmission, access, and display across the platform.
- Strengthen authentication, authorization, session management, and account security controls.
- Implement audit logging and tracking of sensitive data access.
- Integrate automated vulnerability scanning, SAST/DAST, and secure development practices into CI/CD pipelines.
- Collaborate with cloud and security teams to align application changes with infrastructure controls.
Required profile
- 5+ years of experience in application security or secure software development.
- Proven track record delivering encryption, key‑management, RBAC, MFA, and secure authentication in production.
- Deep knowledge of OWASP Top 10, secure coding, and vulnerability remediation.
- Experience integrating security tooling (SAST/DAST) into CI/CD pipelines.
- Hands‑on experience securing both web and mobile applications.
- Familiarity with third‑party compliance frameworks such as Amazon, PCI DSS, SOC 2 is a strong plus.
- Excellent communication and collaboration skills for cross‑functional work.
Required skills
- Data encryption
- Key management
- Secrets management
- Role‑Based Access Control (RBAC)
- Multi‑Factor Authentication (MFA)
- Secure authentication and session management
- OWASP Top 10
- Secure coding practices
- Vulnerability remediation
- SAST and DAST tools
- CI/CD pipeline integration
- Web application security
- Mobile application security
- Compliance frameworks (Amazon, PCI DSS, SOC 2)
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Pakistan.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 2 weeks from now
48 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Avaib
Karachi