Enable job alerts via email!

Senior Application Security Engineer-Johannesburg

DigiCert, Inc.

Johannesburg

Remote

ZAR 600,000 - 800,000

Full time

13 days ago

Job summary

A leading cybersecurity firm is seeking a Senior Application Security Engineer to enhance the security of web applications. The role involves integrating security practices into the development lifecycle, conducting assessments, and mentoring team members. Candidates should have over 5 years of experience in web application security, relevant degrees, and desirable certifications. This position is remote and offers exposure to cutting-edge security technologies.

Qualifications

  • 5+ years of experience in cybersecurity with a focus on web application security.
  • Professional security certifications such as CISSP, OSCP, CEH are desirable.
  • Strong understanding of security protocols and vulnerabilities.

Responsibilities

  • Lead the integration of security measures into the SDLC.
  • Conduct security assessments and penetration testing on web applications.
  • Advise on secure architectural patterns for applications.

Skills

Web application security
DevSecOps practices
Security assessments
Penetration testing
Secure coding
Programming languages (JavaScript, Python, Java)

Education

Bachelor’s or master’s degree in computer science or cybersecurity

Tools

DevSecOps tools (SAST / DAST / SCA)

Job description

Job title : Senior Application Security Engineer - Johannesburg

Job Location : Gauteng, Johannesburg

Deadline : August 29, 2025

Quick Recommended Links

  • Jobs by Location
  • Jobs by Industry
Job summary

As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development.

This is a remote position.

What you will do
  • Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design.
  • Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps.
  • Advise software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices.
  • Perform and coordinate manual and automated code reviews.
  • Lead threat modeling exercises across engineering teams.
  • Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring.
  • Contribute to internal security tooling development or integration.
  • Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow.
  • Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively.
  • Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner.
  • Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices.
  • Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations.
  • Assist with managing bug bounty programs.
  • Develop program documentation to promote operational stability and scalability.
  • Support leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives.
  • Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC.
  • Drive and support security remediation efforts.
  • Foster and promote a security-forward culture.
  • Mentor junior team members.
  • Other duties and responsibilities, as assigned.
What you will have
  • Bachelor’s or master’s degree in computer science, cybersecurity, or a related field.
  • Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable.
  • 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC.
  • Experience with red team implementation and methodologies.
  • Proven track record of working with DevSecOps tools (such as SAST / DAST / SCA) and methodologies.
  • Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities.
  • Proficiency with programming / scripting languages such as JavaScript, Python, Java, Bash, PowerShell.
  • Excellent communication skills with the ability to engage technical and non-technical stakeholders.
  • Strong analytical and problem-solving abilities, with a meticulous attention to detail.
  • Advanced knowledge of Information Security design concepts and principles.
Nice to have
  • Master's degree in a technical discipline.
  • Experience working in highly regulated environments.
  • Advanced knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP).
  • Certified Information Systems Auditor (CISA).
  • AWS Solutions Architect.
  • ICT jobs.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.