Application Security Engineer (VA/PT & DevSecOps)

Kamelpay
Kamelpay

Karachi, Karachi City, Sindh, Pakistan

Posted on Jul 22, 2026

Job Title: Application Security Engineer (VA/PT & DevSecOps)

Location and timings: Karachi DHA Phase 6, onsite, 11 am to 8 pm monday to Friday

Experience: 3–5 Years

Department: Information Security

Role Overview

We are seeking a skilled Application Security Engineer / Penetration Tester to take full ownership of our organization's VA/PT program and embed security across the software development lifecycle. The ideal candidate will independently conduct vulnerability assessments and penetration tests, integrate security tooling into CI/CD pipelines, and proactively identify and remediate threats across applications and infrastructure.

Key Responsibilities

Vulnerability Assessment & Penetration Testing — Conduct end-to-end VA/PT across web applications, APIs, mobile apps, and supporting infrastructure; validate findings and eliminate false positives.

DevSecOps / CI/CD Security — Embed security into CI/CD pipelines; integrate and manage tools such as SonarQube (SAST), DAST scanners, SCA, and secret-scanning solutions.

Full Program Ownership — Own the VA/PT lifecycle independently — scoping, execution, reporting, remediation tracking, and revalidation — with minimal supervision.

Threat Identification & Analysis — Proactively identify application and infrastructure threats; assess exploitability, business impact, and prioritize remediation.

Secure SDLC — Work with development teams to enforce secure coding practices, review architecture, and support threat modeling.

Remediation Support — Partner with engineering teams to guide fixes, verify closure, and reduce recurring vulnerability patterns.

Reporting — Produce clear, risk-based VA/PT reports and executive summaries for technical and management audiences.

Required Skills & Experience

3–5 years of hands-on VA/PT and application security experience.

Strong command of web, API, and mobile application penetration testing (OWASP Top 10, OWASP ASVS, OWASP MASVS).

Hands-on experience integrating security into CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, etc.).

Practical experience with SonarQube and other SAST/DAST/SCA tooling.

Proficiency with industry tools (Burp Suite, Nmap, Metasploit, OWASP ZAP, Nessus/Qualys).

Solid understanding of common vulnerability classes, exploitation techniques, and secure coding principles.

Ability to work with full ownership and drive the security program independently.

Preferred / Nice to Have:

  • Bachelor's/Master's in Computer Science/Cybersecurity.
  • Certifications such as OSCP, OSWE, CEH, GWAPT, or eWPTX.
  • Scripting/automation skills (Python, Bash, PowerShell).
  • Experience with SBOM, SLSA, and supply-chain security.
  • Exposure to compliance frameworks (PCI DSS, ISO 27001, NESA/DESC).

Apply: careers@kamelpay.com and (cc: faizan.ali@kamelpay.com)