Application Security Engineer (VA/PT & DevSecOps)
Karachi, Karachi City, Sindh, Pakistan
Job Title: Application Security Engineer (VA/PT & DevSecOps)
Location and timings: Karachi DHA Phase 6, onsite, 11 am to 8 pm monday to Friday
Experience: 3–5 Years
Department: Information Security
Role Overview
We are seeking a skilled Application Security Engineer / Penetration Tester to take full ownership of our organization's VA/PT program and embed security across the software development lifecycle. The ideal candidate will independently conduct vulnerability assessments and penetration tests, integrate security tooling into CI/CD pipelines, and proactively identify and remediate threats across applications and infrastructure.
Key Responsibilities
Vulnerability Assessment & Penetration Testing — Conduct end-to-end VA/PT across web applications, APIs, mobile apps, and supporting infrastructure; validate findings and eliminate false positives.
DevSecOps / CI/CD Security — Embed security into CI/CD pipelines; integrate and manage tools such as SonarQube (SAST), DAST scanners, SCA, and secret-scanning solutions.
Full Program Ownership — Own the VA/PT lifecycle independently — scoping, execution, reporting, remediation tracking, and revalidation — with minimal supervision.
Threat Identification & Analysis — Proactively identify application and infrastructure threats; assess exploitability, business impact, and prioritize remediation.
Secure SDLC — Work with development teams to enforce secure coding practices, review architecture, and support threat modeling.
Remediation Support — Partner with engineering teams to guide fixes, verify closure, and reduce recurring vulnerability patterns.
Reporting — Produce clear, risk-based VA/PT reports and executive summaries for technical and management audiences.
Required Skills & Experience
3–5 years of hands-on VA/PT and application security experience.
Strong command of web, API, and mobile application penetration testing (OWASP Top 10, OWASP ASVS, OWASP MASVS).
Hands-on experience integrating security into CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, etc.).
Practical experience with SonarQube and other SAST/DAST/SCA tooling.
Proficiency with industry tools (Burp Suite, Nmap, Metasploit, OWASP ZAP, Nessus/Qualys).
Solid understanding of common vulnerability classes, exploitation techniques, and secure coding principles.
Ability to work with full ownership and drive the security program independently.
Preferred / Nice to Have:
- Bachelor's/Master's in Computer Science/Cybersecurity.
- Certifications such as OSCP, OSWE, CEH, GWAPT, or eWPTX.
- Scripting/automation skills (Python, Bash, PowerShell).
- Experience with SBOM, SLSA, and supply-chain security.
- Exposure to compliance frameworks (PCI DSS, ISO 27001, NESA/DESC).
Apply: careers@kamelpay.com and (cc: faizan.ali@kamelpay.com)