Job Overview
SwipBox is seeking a qualified, proactive, and dynamic professional for the position of Senior Application Security Engineer.
Job Reference: JJ-00725
Job Details
Role and Responsibilities
- Perform penetration testing and vulnerability assessments across web, mobile, API, network, embedded software, firmware, and cloud environments.
- Conduct security testing of AWS infrastructure, including IAM, EC2, S3, Lambda, API Gateway, VPC, CloudFront, Cognito, and related services.
- Strong hands-on experience with web, API, mobile, cloud, network, and application security testing.
- Perform threat modeling, attack-surface analysis, and security architecture reviews to identify security risks and design-level weaknesses.
- Perform ethical hacking and red-team activities to simulate real-world attacks and assess security posture.
- Identify vulnerabilities, security misconfigurations, authentication and authorization weaknesses, business-logic vulnerabilities, abuse cases, and potential attack paths.
- Conduct API security testing, including REST APIs and authentication mechanisms.
- Review application source code to identify security vulnerabilities and insecure coding practices.
- Perform business-logic testing to identify vulnerabilities that may not be detected through automated security tools.
- Conduct firmware and embedded security testing, including reverse engineering, firmware extraction, static and dynamic analysis, and tampering analysis.
- Perform BLE security and protocol testing and identify vulnerabilities in embedded communication protocols.
- Work closely with developers and DevOps teams to understand and remediate security findings.
- Integrate security testing and controls into CI/CD pipelines, including SAST, DAST, SCA, IaC, and container security scanning.
- Apply secure software development and DevSecOps practices throughout the Software Development Lifecycle (SDLC).
- Validate security fixes through retesting and provide clear technical recommendations.
- Prepare detailed penetration testing reports covering vulnerabilities, risk ratings, evidence, impact, and remediation recommendations.
- Support security assessments during the design and development lifecycle.
- Stay current with emerging vulnerabilities, attack techniques, OWASP standards, and cloud security best practices.
- Independently plan, execute, document, and present penetration testing activities and security findings.
- Lead penetration-testing engagements and provide technical guidance to junior team members.
- Mentor junior team members and review security findings and penetration testing reports.
- Present security risks, findings, and recommendations to technical and management stakeholders.
- Collaborate with development and engineering teams to identify, communicate, and remediate security vulnerabilities.
Qualifications and Education Requirements
- Master’s or Bachelor’s degree in Software Engineering, Computer Engineering, Telecommunication Engineering, or Computer Science.
- 7+ years of professional experience.
- CEH, eCPPT, CRTP, OSCP, or any recognized security vendor certification would be preferred.
Preferred Skills
- Real-time traffic analysis, network IDS, and packet dissection.
- Strong understanding of information security and applied cryptographic protocols.
- Good knowledge of security technologies for secure software development, including cryptography, authentication techniques, and protocols.
- Good understanding of tools and technologies used for penetration testing.
- Experience with advanced vulnerability research and exploit development.
- Experience developing scripts or custom tools to support penetration testing and security assessments.
Key Responsibilities
Perform comprehensive penetration testing and vulnerability assessments across web, mobile, cloud, and embedded environments. Collaborate with development and DevOps teams to integrate security controls into CI/CD pipelines and remediate identified vulnerabilities.
Requirements and Skills
Requires a Bachelor's or Master's degree in a relevant engineering or computer science field with at least 7 years of professional experience. Candidates should possess strong technical skills in security testing and hold relevant industry certifications such as OSCP or CEH.
Key Competencies: Penetration testing, Vulnerability assessment, AWS security, Threat modeling, Ethical hacking, API security, Source code review, Firmware security, Reverse engineering, DevSecOps, CI/CD integration, SAST, DAST, SCA, Cryptography, Network security, AWS, IAM, Red Teaming, CI/CD