Senior Application Security Engineer

SwipBox

Islamabad

On-site

PKR 400,000 - 700,000

Full time

44 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SwipBox in Islamabad seeks an experienced Senior Security Tester to perform penetration testing across web, mobile, API, cloud, and embedded environments, and to assess security controls in AWS. You will conduct threat modeling, review architectures, lead red-team activities, and mentor junior staff while integrating security into CI/CD pipelines.

Responsibilities include reporting, coordination with DevOps, and staying current with OWASP and cloud security best practices.

Qualifications

  • Master’s or Bachelor’s degree in Software Engineering, Computer Science or related field.
  • 7+ years of professional security experience.
  • CEH, eCPPT, CRTP, OSCP certifications preferred.

Responsibilities

  • Perform penetration testing across web, mobile, API, network, embedded software, firmware, and cloud environments.
  • Conduct threat modeling, attack-surface analysis, and security architecture reviews to identify risks.
  • Lead red-team activities to simulate real-world attacks and assess security posture.
  • Review application source code to identify vulnerabilities and insecure coding practices.
  • Integrate security testing and controls into CI/CD pipelines (SAST, DAST, SCA, IaC, container security).
  • Prepare detailed penetration testing reports with vulnerabilities, risk ratings and remediation recommendations.

Skills

Penetration testing
Vulnerability assessments
Cloud security
Threat modeling
Red-team
CI/CD security
Code review security
Scripting
Team mentoring
Communication

Education

Master’s or Bachelor’s degree in Software Engineering / CS
7+ years professional security experience
CEH, eCPPT, CRTP, OSCP certifications preferred

Tools

CEH
eCPPT
CRTP
OSCP

Job description


  • Perform penetration testing and vulnerability assessments across web, mobile, API, network, embedded software, firmware, and cloud environments.

  • Conduct security testing of AWS infrastructure, including IAM, EC2, S3, Lambda, API Gateway, VPC, CloudFront, Cognito, and related services.

  • Strong hands-on experience with web, API, mobile, cloud, network, and application security testing.

  • Perform threat modeling, attack-surface analysis, and security architecture reviews to identify security risks and design-level weaknesses.

  • Perform ethical hacking and red-team activities to simulate real-world attacks and assess security posture.

  • Identify vulnerabilities, security misconfigurations, authentication and authorization weaknesses, business-logic vulnerabilities, abuse cases, and potential attack paths.

  • Conduct API security testing, including REST APIs and authentication mechanisms.

  • Review application source code to identify security vulnerabilities and insecure coding practices.

  • Perform business-logic testing to identify vulnerabilities that may not be detected through automated security tools.

  • Conduct firmware and embedded security testing, including reverse engineering, firmware extraction, static and dynamic analysis, and tampering analysis.

  • Perform BLE security and protocol testing and identify vulnerabilities in embedded communication protocols.

  • Work closely with developers and DevOps teams to understand and remediate security findings.

  • Integrate security testing and controls into CI/CD pipelines, including SAST, DAST, SCA, IaC, and container security scanning.

  • Apply secure software development and DevSecOps practices throughout the Software Development Lifecycle (SDLC).

  • Validate security fixes through retesting and provide clear technical recommendations.

  • Prepare detailed penetration testing reports covering vulnerabilities, risk ratings, evidence, impact, and remediation recommendations.

  • Support security assessments during the design and development lifecycle.

  • Stay current with emerging vulnerabilities, attack techniques, OWASP standards, and cloud security best practices.

  • Independently plan, execute, document, and present penetration testing activities and security findings.

  • Lead penetration-testing engagements and provide technical guidance to junior team members.

  • Mentor junior team members and review security findings and penetration testing reports.

  • Present security risks, findings, and recommendations to technical and management stakeholders.

  • Collaborate with development and engineering teams to identify, communicate, and remediate security vulnerabilities.


Qualifications and Education Requirements


  • Master’s or Bachelor’s degree in Software Engineering, Computer Engineering, Telecommunication Engineering, or Computer Science.

  • 7+ years of professional experience.

  • CEH, eCPPT, CRTP, OSCP, or any recognized security vendor certification would be preferred.


Preferred Skills


  • Real-time traffic analysis, network IDS, and packet dissection.

  • Strong understanding of information security and applied cryptographic protocols.

  • Good knowledge of security technologies for secure software development, including cryptography, authentication techniques, and protocols.

  • Good understanding of tools and technologies used for penetration testing.

  • Experience with advanced vulnerability research and exploit development.

  • Experience developing scripts or custom tools to support penetration testing and security assessments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior VAPT Engineer
Senior VAPT Engineer

Arwentech • Islamabad

On-site
PKR 1,800,000 - 3,200,000
Excellent Salary
Fuel Allowance
Internet Allowance
+5
Assistant Manager (Penetration Testing)
Assistant Manager (Penetration Testing)

Risk Associates Pvt. Ltd. • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
Cyber Security Consultant
Cyber Security Consultant

Catalyic Security • Lahore

On-site
Software Engineer - Security Testing
Software Engineer - Security Testing

i2c Inc • Lahore

On-site
PKR 5,575,000 - 11,152,000
Penetration Testing Senior Associate
Penetration Testing Senior Associate

PwC South Africa • Karachi Division

On-site
Confidential
Junior Cybersecurity Engineer
Junior Cybersecurity Engineer

Octdaily • Karachi Division

On-site
PKR 600,000 - 900,000
Senior Software Security Engineer - Afternoon Shift
Senior Software Security Engineer - Afternoon Shift

10Pearls, LLC • Lahore, Karachi Division, Islamabad

On-site
PKR 1,800,000 - 2,400,000
Senior Software Security Engineer - Afternoon Shift
Senior Software Security Engineer - Afternoon Shift

10Pearls • Islamabad

On-site
PKR 1,800,000 - 2,400,000
Security Engineer
Security Engineer

7vals • Lahore

On-site
PKR 1,200,000 - 2,000,000
Penetration Testing Senior Associate
Penetration Testing Senior Associate

A. F. Ferguson & Co. (a member firm of the PwC network) • Karachi Division

On-site
PKR 1,200,000 - 1,800,000