📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Application Security Engineer (Web & Mobile)

Avaib · Karachi

Senior 🇬🇧 English
Data encryption Key management Secrets management Role-based access control (RBAC) Multi-factor authentication (MFA) OWASP Top 10 Secure coding practices Vulnerability remediation SAST DAST

Job description

About the role

We are looking for an experienced Application Security Engineer to lead a critical initiative: closing application‑level security gaps identified during Amazon’s security review. This hands‑on role focuses on translating Amazon’s compliance requirements into robust solutions for our web and mobile platforms.

Key responsibilities

  • Identify and remediate application‑level security gaps to meet Amazon and industry standards.
  • Implement encryption for sensitive data and personally identifiable information (PII) across the application.
  • Design and integrate secure key‑management and secrets‑management solutions.
  • Build fine‑grained role‑based access control (RBAC) and permission structures.
  • Design and deploy multi‑factor authentication (MFA) and other authentication enhancements for web and mobile.
  • Review and improve storage, transmission, access, and display of sensitive information.
  • Strengthen authentication, authorization, session management, and account security controls.
  • Implement audit logging and tracking of sensitive data access.
  • Integrate automated vulnerability scanning, SAST/DAST, and secure development practices into CI/CD pipelines.
  • Collaborate with cloud and security teams to align application changes with infrastructure controls.

Required profile

  • 5+ years of experience in application security or secure software development.
  • Proven track record delivering encryption, key‑management, RBAC, MFA, and secure authentication in production.
  • Deep knowledge of OWASP Top 10, secure coding practices, and vulnerability remediation.
  • Experience integrating security tooling (SAST/DAST) into CI/CD pipelines.
  • Experience securing both web and mobile applications.
  • Familiarity with third‑party compliance frameworks such as Amazon, PCI DSS, SOC 2 is a strong plus.
  • Strong communication and collaboration skills for cross‑functional work.

Required skills

  • Data encryption
  • Key management
  • Secrets management
  • Role‑based access control (RBAC)
  • Multi‑factor authentication (MFA)
  • OWASP Top 10
  • Secure coding practices
  • Vulnerability remediation
  • SAST and DAST tools
  • CI/CD pipeline integration
  • Web application security
  • Mobile application security
  • Compliance frameworks (Amazon, PCI DSS, SOC 2)

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Avaib.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 1 day from now

28 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Avaib

Karachi