Senior Application Security Engineer

SwipBox

Islamabad

On-site

PKR 350,000 - 600,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SwipBox in Islamabad seeks an experienced security testing expert to lead comprehensive penetration testing across web, mobile, API, network, embedded, firmware, and cloud ecosystems. You will perform rigorous assessments of AWS infrastructure and contribute to threat modeling, secure design reviews, and remediation guidance.

The role requires 7+ years of hands-on security testing, with certifications such as CEH, eCPPT, CRTP, or OSCP preferred.

Qualifications

  • Master’s or Bachelor’s degree in software/CS or related engineering field.
  • 7+ years of professional security testing experience.
  • CEH/eCPPT/CRTP/OSCP or equivalent preferred.

Responsibilities

  • Perform penetration testing across web, mobile, API, network, embedded software, firmware, and cloud environments.
  • Conduct security testing of AWS infrastructure, including IAM, EC2, S3, Lambda, API Gateway, VPC, CloudFront, Cognito.
  • Lead penetration-testing engagements and mentor junior team members.
  • Prepare detailed penetration testing reports with vulnerabilities, risk ratings, evidence, and remediation recommendations.
  • Stay updated with OWASP standards and cloud security best practices.
  • Integrate security testing into CI/CD pipelines with SAST, DAST, SCA, IaC, and container security scanning.

Skills

Penetration testing
Security assessments
Threat modeling
CI/CD security
DevSecOps
SAST/DAST/SCA
Embedded security testing

Education

Master's or Bachelor's degree in Software Engineering, Computer Engineering, Telecommunication Engineering, or Computer Science

Tools

CEH
eCPPT
CRTP
OSCP

Job description

Role and Responsibilities
  • Perform penetration testing and vulnerability assessments across web, mobile, API, network, embedded software, firmware, and cloud environments.
  • Conduct security testing of AWS infrastructure, including IAM, EC2, S3, Lambda, API Gateway, VPC, CloudFront, Cognito, and related services.
  • Strong hands-on experience with web, API, mobile, cloud, network, and application security testing.
  • Perform threat modeling, attack-surface analysis, and security architecture reviews to identify security risks and design-level weaknesses.
  • Perform ethical hacking and red-team activities to simulate real-world attacks and assess security posture.
  • Identify vulnerabilities, security misconfigurations, authentication and authorization weaknesses, business-logic vulnerabilities, abuse cases, and potential attack paths.
  • Conduct API security testing, including REST APIs and authentication mechanisms.
  • Review application source code to identify security vulnerabilities and insecure coding practices.
  • Perform business-logic testing to identify vulnerabilities that may not be detected through automated security tools.
  • Conduct firmware and embedded security testing, including reverse engineering, firmware extraction, static and dynamic analysis, and tampering analysis.
  • Perform BLE security and protocol testing and identify vulnerabilities in embedded communication protocols.
  • Work closely with developers and DevOps teams to understand and remediate security findings.
  • Integrate security testing and controls into CI/CD pipelines, including SAST, DAST, SCA, IaC, and container security scanning.
  • Apply secure software development and DevSecOps practices throughout the Software Development Lifecycle (SDLC).
  • Validate security fixes through retesting and provide clear technical recommendations.
  • Prepare detailed penetration testing reports covering vulnerabilities, risk ratings, evidence, impact, and remediation recommendations.
  • Support security assessments during the design and development lifecycle.
  • Stay current with emerging vulnerabilities, attack techniques, OWASP standards, and cloud security best practices.
  • Independently plan, execute, document, and present penetration testing activities and security findings.
  • Lead penetration-testing engagements and provide technical guidance to junior team members.
  • Mentor junior team members and review security findings and penetration testing reports.
  • Present security risks, findings, and recommendations to technical and management stakeholders.
  • Collaborate with development and engineering teams to identify, communicate, and remediate security vulnerabilities.
Qualifications and Education Requirements
  • Master’s or Bachelor’s degree in Software Engineering, Computer Engineering, Telecommunication Engineering, or Computer Science.
  • 7+ years of professional experience.
  • CEH, eCPPT, CRTP, OSCP, or any recognized security vendor certification would be preferred.
Preferred Skills
  • Real-time traffic analysis, network IDS, and packet dissection.
  • Strong understanding of information security and applied cryptographic protocols
  • Good knowledge of security technologies for secure software development, including cryptography, authentication techniques, and protocols.
  • Good understanding of tools and technologies used for penetration testing.
  • Experience with advanced vulnerability research and exploit development.
  • Experience developing scripts or custom tools to support penetration testing and security assessments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer - Security Testing
Software Engineer - Security Testing

i2c Inc • Lahore

On-site
PKR 5,575,000 - 11,152,000
Assistant Manager (Penetration Testing)
Assistant Manager (Penetration Testing)

Risk Associates Pvt. Ltd. • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
Senior Application Security Engineer
Senior Application Security Engineer

Brickstech • Karachi Division

On-site
PKR 2,400,000 - 4,200,000
Security Engineer
Security Engineer

7vals • Lahore

On-site
PKR 1,200,000 - 2,000,000
Senior Security Consultant- Afternoon Shift
Senior Security Consultant- Afternoon Shift

10Pearls • Lahore

On-site
PKR 1,800,000 - 3,200,000
Senior Software Security Engineer - Afternoon Shift
Senior Software Security Engineer - Afternoon Shift

10Pearls • Islamabad

On-site
PKR 1,800,000 - 2,400,000
Senior Software Security Engineer - Afternoon Shift
Senior Software Security Engineer - Afternoon Shift

10Pearls • Lahore

On-site
PKR 1,800,000 - 3,200,000
Cyber Security Consultant
Cyber Security Consultant

Catalyic Security • Lahore

On-site
Penetration Testing Senior Associate
Penetration Testing Senior Associate

PwC South Africa • Karachi Division

On-site
Confidential
Assistant Manager Cyber Security (App Security & Data Protection)
Assistant Manager Cyber Security (App Security & Data Protection)

K-Electric • Karachi Division

On-site
PKR 1,200,000 - 2,400,000