Senior Application Security Engineer

SwipBox A/S

Islamabad

On-site

PKR 2,790,000 - 5,022,000

Full time

32 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SwipBox A/S is seeking an experienced security tester to perform penetration testing across web, mobile, API, network, embedded software, firmware, and cloud environments.

You will conduct threat modeling, attack-surface analysis, security architecture reviews, red-team activities, API security testing, and review of code and firmware with remediation guidance.

Applicants typically hold CEH/OSCP or similar certifications and have 7+ years of professional security testing experience.

Qualifications

  • Master’s or Bachelor's degree in Software/Computer Engineering or CS.
  • 7+ years of professional security testing experience.
  • CEH, eCPPT, CRTP, OSCP or equivalent certifications preferred.

Responsibilities

  • Perform penetration testing across web, mobile, API, network, embedded software, firmware, and cloud environments.
  • Conduct threat modeling, attack-surface analysis, and security architecture reviews.
  • Lead red-team activities to simulate real-world attacks and assess security posture.
  • Identify vulnerabilities, misconfigurations, and weaknesses; provide remediation guidance.
  • Perform API security testing, including REST APIs and authentication mechanisms.
  • Review source code and firmware for insecure practices; perform secure DevSecOps integration.
  • Prepare detailed penetration testing reports with evidence, risk ratings, and remediation recommendations.
  • Mentor junior team members and present findings to stakeholders.

Skills

Penetration testing
Vulnerability assessments
Threat modeling
Red-team activities
Security architecture reviews
CI/CD security
Web security testing
API security testing
Mobile security testing
Cloud security testing
Firmware security testing

Education

Master’s/ Bachelor’s in CS/Engineering

Tools

CEH
eCPPT
CRTP
OSCP

Job description

  • Perform penetration testing and vulnerability assessments across web, mobile, API, network, embedded software, firmware, and cloud environments.
  • Conduct security testing of AWS infrastructure, including IAM, EC2, S3, Lambda, API Gateway, VPC, CloudFront, Cognito, and related services.
  • Strong hands-on experience with web, API, mobile, cloud, network, and application security testing.
  • Perform threat modeling, attack-surface analysis, and security architecture reviews to identify security risks and design-level weaknesses.
  • Perform ethical hacking and red-team activities to simulate real-world attacks and assess security posture.
  • Identify vulnerabilities, security misconfigurations, authentication and authorization weaknesses, business-logic vulnerabilities, abuse cases, and potential attack paths.
  • Conduct API security testing, including REST APIs and authentication mechanisms.
  • Review application source code to identify security vulnerabilities and insecure coding practices.
  • Perform business-logic testing to identify vulnerabilities that may not be detected through automated security tools.
  • Conduct firmware and embedded security testing, including reverse engineering, firmware extraction, static and dynamic analysis, and tampering analysis.
  • Perform BLE security and protocol testing and identify vulnerabilities in embedded communication protocols.
  • Work closely with developers and DevOps teams to understand and remediate security findings.
  • Integrate security testing and controls into CI/CD pipelines, including SAST, DAST, SCA, IaC, and container security scanning.
  • Apply secure software development and DevSecOps practices throughout the Software Development Lifecycle (SDLC).
  • Validate security fixes through retesting and provide clear technical recommendations.
  • Prepare detailed penetration testing reports covering vulnerabilities, risk ratings, evidence, impact, and remediation recommendations.
  • Support security assessments during the design and development lifecycle.
  • Stay current with emerging vulnerabilities, attack techniques, OWASP standards, and cloud security best practices.
  • Independently plan, execute, document, and present penetration testing activities and security findings.
  • Lead penetration-testing engagements and provide technical guidance to junior team members.
  • Mentor junior team members and review security findings and penetration testing reports.
  • Present security risks, findings, and recommendations to technical and management stakeholders.
  • Collaborate with development and engineering teams to identify, communicate, and remediate security vulnerabilities.
Qualifications and Education Requirements
  • Master’s or Bachelor’s degree in Software Engineering, Computer Engineering, Telecommunication Engineering, or Computer Science.
  • 7+ years of professional experience.
  • CEH, eCPPT, CRTP, OSCP, or any recognized security vendor certification would be preferred.
Preferred Skills
  • Real-time traffic analysis, network IDS, and packet dissection.
  • Strong understanding of information security and applied cryptographic protocols.
  • Good knowledge of security technologies for secure software development, including cryptography, authentication techniques, and protocols.
  • Good understanding of tools and technologies used for penetration testing.
  • Experience with advanced vulnerability research and exploit development.
  • Experience developing scripts or custom tools to support penetration testing and security assessments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Engineer - Security Testing
Software Engineer - Security Testing

i2c Inc • Lahore

On-site
PKR 5,575,690 - 11,151,380
Assistant Manager (Penetration Testing)
Assistant Manager (Penetration Testing)

Risk Associates Pvt. Ltd. • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
Cyber Security Consultant
Cyber Security Consultant

Catalyic Security • Lahore

On-site
PKR 1,674,000 - 2,232,000
Penetration Testing Senior Associate
Penetration Testing Senior Associate

PwC South Africa • Karachi Division

On-site
Confidential
Lead App Security Engineer - PenTesting & DevSecOps
Lead App Security Engineer - PenTesting & DevSecOps

SwipBox A/S • Islamabad

On-site
PKR 2,790,000 - 5,022,000
Penetration Tester
Penetration Tester

Pluto IT Solutions INC • Lahore

On-site
PKR 2,400,000 - 4,200,000
Security Engineer
Security Engineer

7vals • Lahore

On-site
PKR 1,200,000 - 2,000,000
Infrastructure & DevSecOps Lead Pakistan
Infrastructure & DevSecOps Lead Pakistan

KnowledgeCity • Pakistan

On-site
PKR 3,500,000 - 5,000,000
Infrastructure & DevSecOps Lead
Infrastructure & DevSecOps Lead

KnowledgeCity • Pakistan

On-site
PKR 1,800,000 - 3,200,000
VAPT Engineer – Enterprise & Scalable Platforms (Onsite, Karachi, PKR Salary)
VAPT Engineer – Enterprise & Scalable Platforms (Onsite, Karachi, PKR Salary)

hr-pod-hiring-talent-globally • Karachi Division

On-site
PKR 1,800,000 - 2,400,000