Application Security Engineer

CapitalSage Holdings

Remote
Role Purpose: Protect the Group's applications by identifying, assessing and reducing application security risks throughout the software lifecycle.

Key Responsibilities:
  • Perform application security assessments, code reviews and security testing.
  • Manage and optimize application security tools and processes, including Checkmarx.
  • Conduct threat modelling and security architecture reviews for applications.
  • Support remediation of OWASP and application-specific vulnerabilities.
  • Assess APIs, web applications, mobile applications and other digital channels.
  • Work with development teams to establish and enforce secure coding practices.
  • Support security testing before production release.
  • Maintain application security standards, metrics and risk reports.


Requirements

  • Relevant degree or equivalent professional qualification in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline.
  • Relevant professional certifications will be an advantage and should align with the specific role.
  • Demonstrable practical experience relevant to the position.
  • Strong communication, analytical, documentation and stakeholder-management skills.
  • Ability to operate in a regulated, technology-driven and multi-business environment.

Preferred / Added Advantage Certifications
  • OSCP – Offensive Security Certified Professional
  • eWPT or equivalent web application security certification
  • CSSLP – Certified Secure Software Lifecycle Professional
  • Checkmarx certification/training (advantage)



Benefits

Industry Standard


How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.