Application Security Analyst | Hydrogen | Unspecified

Hydrogen

Gajar

On-site

PKR 16,644,000 - 24,965,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Hydrogen is seeking an experienced Application Security Analyst to protect critical payment platforms, including card management and switch architectures. You will lead SAST, DAST, SCA, and manual reviews, embed security gates in CI/CD, and drive PCI-DSS compliance across high-velocity engineering teams.

The role requires 3–5 years in application security, strong penetration testing skills, and a solid PCI-DSS background to translate risk into actionable business context.

Qualifications

  • Bachelor's degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related technical discipline.
  • Between 3 to 5 years of relevant professional experience in application security, penetration testing, or software security engineering.
  • Prior hands-on exposure to fintech, digital banking, payment card processing, or financial payment switch environments.
  • CompTIA Security+ certification (required or actively in progress).
  • Solid technical proficiency in executing SAST, DAST, and SCA tooling within automated CI/CD software delivery pipelines.
  • Demonstrated expertise in web, API, and mobile application penetration testing methodologies and secure code review practices.
  • Comprehensive working knowledge of the PCI-DSS compliance framework, control requirements, and formal audit evidence validation.
  • Strong analytical, cross-functional collaboration, and communication skills, with a proven ability to translate technical security risk into business context.

Responsibilities

  • Conduct comprehensive SAST, DAST, SCA, and manual secure source code reviews across card management, payment switch, and POS/ATM integration systems.
  • Perform vulnerability assessments and hands-on penetration testing across enterprise web applications, mobile apps, and payment API endpoints.
  • Design, configure, and embed automated security gates and policy checkpoints throughout the software development lifecycle (SDLC) and CI/CD pipelines.
  • Support continuous PCI-DSS compliance operations through control validation, audit evidence collection, and structured remediation tracking.
  • Evaluate third-party partner and vendor integrations for cybersecurity risk, focusing specifically on ISO 8583 messaging interfaces and payment networks.
  • Monitor application-layer security telemetry and partner with SOC analysts to investigate anomalous transaction flows and potential fraudulent activities.
  • Participate actively in incident response operations and technical containment procedures for application-level security incidents.
  • Draft comprehensive risk assessment reports, document security vulnerabilities, and partner directly with engineering squads to verify permanent defect closure.

Skills

SAST tooling
DAST tooling
SCA tooling
PCI-DSS knowledge
Penetration testing
Secure code reviews
CI/CD security gates
Vulnerability assessments

Education

Bachelor's degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related technical discipline

Tools

CI/CD tooling
ISO 8583 knowledge

Job description

Position Summary

Hydrogen is seeking an experienced, proactive Application Security Analyst to protect and fortify the mission-critical applications and digital payment infrastructure powering modern financial transactions. In this vital cybersecurity role, you will take ownership of safeguarding high-throughput card issuance, card management, and switch/transaction processing platforms from evolving cyber threats. Leveraging 3 to 5 years of dedicated application security and penetration testing experience, you will embed robust security checkpoints across the software development lifecycle, drive vulnerability remediation, and uphold stringent PCI-DSS compliance standards. This position offers an outstanding platform for an ambitious security analyst to protect premier payment switch technologies and ensure flawless transactional security for millions of users.

Detailed Job Description

As an Application Security Analyst at Hydrogen, you will hold direct technical accountability for embedding enterprise-grade application security across high-velocity engineering workflows and core payment switch architectures. Collaborating closely with software developers, DevOps teams, the Security Operations Center (SOC), and infrastructure engineers, you will champion a proactive shift-left security culture that integrates automated testing and security gates directly into modern CI/CD deployment pipelines.

Your comprehensive scope of responsibility spans conducting Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), manual secure code reviews, and deep-dive penetration testing across web, mobile, and API interfaces. You will evaluate risk and validate security controls across POS/ATM integrations, card management platforms, third-party vendor connections, and ISO 8583 financial messaging interfaces. Additionally, you will support PCI-DSS compliance evidence collection, monitor application-layer security telemetry in tandem with SOC teams to triage anomalous transaction flows, and lead technical remediation tracking to full closure. This high-impact role demands exceptional analytical rigor, deep knowledge of payment security standards, and the ability to articulate technical risk clearly to cross-functional stakeholders.

Key Responsibilities
  • Conduct comprehensive SAST, DAST, SCA, and manual secure source code reviews across card management, payment switch, and POS/ATM integration systems.
  • Perform vulnerability assessments and hands-on penetration testing across enterprise web applications, mobile apps, and payment API endpoints.
  • Design, configure, and embed automated security gates and policy checkpoints throughout the software development lifecycle (SDLC) and CI/CD pipelines.
  • Support continuous PCI-DSS compliance operations through control validation, audit evidence collection, and structured remediation tracking.
  • Evaluate third-party partner and vendor integrations for cybersecurity risk, focusing specifically on ISO 8583 messaging interfaces and payment networks.
  • Monitor application-layer security telemetry and partner with SOC analysts to investigate anomalous transaction flows and potential fraudulent activities.
  • Participate actively in incident response operations and technical containment procedures for application-level security incidents.
  • Draft comprehensive risk assessment reports, document security vulnerabilities, and partner directly with engineering squads to verify permanent defect closure.
Required Qualifications & Skills
  • Bachelor's degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related technical discipline.
  • Between 3 to 5 years of relevant professional experience in application security, penetration testing, or software security engineering.
  • Prior hands-on exposure to fintech, digital banking, payment card processing, or financial payment switch environments.
  • CompTIA Security+ certification (required or actively in progress).
  • Solid technical proficiency in executing SAST, DAST, and SCA tooling within automated CI/CD software delivery pipelines.
  • Demonstrated expertise in web, API, and mobile application penetration testing methodologies and secure code review practices.
  • Comprehensive working knowledge of the PCI-DSS compliance framework, control requirements, and formal audit evidence validation.
  • Strong analytical, cross-functional collaboration, and communication skills, with a proven ability to translate technical security risk into business context.
Nice-to-Have Skills
  • Recognized professional cybersecurity certifications such as CEH (Certified Ethical Hacker), OSCP (Offensive Security Certified Professional), or CSSLP.
  • Specialized cloud security certifications such as AWS Certified Security - Specialty or Microsoft Certified: Azure Security Engineer Associate (AZ-500).
  • Active progress toward obtaining the Certified Information Systems Security Professional (CISSP) credential.
  • In-depth technical knowledge of ISO 8583 financial transaction messaging formats, HSM (Hardware Security Module) workflows, or tokenization standards.
  • Experience delivering interactive secure coding training and security awareness workshops for software engineering teams.
Application Information
  • Employer: Hydrogen (Hydrogen Payments)
  • Website: hydrogenpay.com
  • Position: Application Security Analyst
  • Experience Required: 3-5 Years of relevant experience
  • Work Location: Unspecified
  • Employment Type: Full Time
  • Application Email: careers@hydrogenpay.com
  • Shortlisting Notice: Only qualified candidates will be contacted.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Analyst: FinTech & PCI-DSS
Application Security Analyst: FinTech & PCI-DSS

Hydrogen • Gajar

On-site
PKR 16,644,000 - 24,965,000
Senior Application Security Engineer
Senior Application Security Engineer

SwipBox A/S • Islamabad

On-site
PKR 2,790,000 - 5,022,000
SECURITY SPECIALIST
SECURITY SPECIALIST

Abacus Global • Lahore

On-site
PKR 1,200,000 - 1,800,000
Assistant Manager (Penetration Testing)
Assistant Manager (Penetration Testing)

Risk Associates Pvt. Ltd. • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
System Engineer – Implementation & Payments Domain
System Engineer – Implementation & Payments Domain

Urban Ridge Supplies • Karachi Division

On-site
PKR 800,000 - 1,200,000
Security Engineer
Security Engineer

7vals • Lahore

On-site
PKR 1,200,000 - 2,000,000
Senior Platform Consultant - (Security/Policy Engineer)
Senior Platform Consultant - (Security/Policy Engineer)

10Pearls • Lahore

On-site
PKR 1,116,000 - 1,674,000
Software Engineer - Security Testing
Software Engineer - Security Testing

i2c Inc • Lahore

On-site
PKR 5,575,690 - 11,151,380
SecOps Security Engineer (L3) – Check Point, Palo Alto & Fortinet firewalls
SecOps Security Engineer (L3) – Check Point, Palo Alto & Fortinet firewalls

NorthBay Solutions LLC • Karachi Division

On-site
PKR 1,200,000 - 1,800,000
Infrastructure & DevSecOps Lead
Infrastructure & DevSecOps Lead

KnowledgeCity • Pakistan

On-site
PKR 1,800,000 - 3,200,000