Application Security Engineer
CapitalSage Holdings Lagos, Lagos State, Nigeria
Investment Management · 201-500 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The role involves protecting applications by identifying and reducing security risks throughout the software development lifecycle. Responsibilities include performing security assessments, code reviews, threat modelling, and enforcing secure coding practices across digital channels.
What they look for
Requirements
Candidates must hold a relevant degree in Cybersecurity, Computer Science, or a related field and possess demonstrable practical experience. Professional certifications such as OSCP, eWPT, or CSSLP are considered a significant advantage.
Benefits
Full description
Role Purpose: Protect the Group's applications by identifying, assessing and reducing application security risks throughout the software lifecycle.
Key Responsibilities:
- Perform application security assessments, code reviews and security testing.
- Manage and optimize application security tools and processes, including Checkmarx.
- Conduct threat modelling and security architecture reviews for applications.
- Support remediation of OWASP and application-specific vulnerabilities.
- Assess APIs, web applications, mobile applications and other digital channels.
- Work with development teams to establish and enforce secure coding practices.
- Support security testing before production release.
- Maintain application security standards, metrics and risk reports.
Requirements
- Relevant degree or equivalent professional qualification in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline.
- Relevant professional certifications will be an advantage and should align with the specific role.
- Demonstrable practical experience relevant to the position.
- Strong communication, analytical, documentation and stakeholder-management skills.
- Ability to operate in a regulated, technology-driven and multi-business environment.
Preferred / Added Advantage Certifications
- OSCP – Offensive Security Certified Professional
- eWPT or equivalent web application security certification
- CSSLP – Certified Secure Software Lifecycle Professional
- Checkmarx certification/training (advantage)
Benefits
Industry Standard
Similar roles
-
IT & Cybersecurity Internal Auditor (2-month Project)
Naseej Cairo, Cairo, Egypt
-
Google SecOps Security Engineer Associate Manager (Saudi Nationals Only)
Accenture Riyadh, Riyadh Region, Saudi Arabia
-
2027 Internship - Cybersecurity Engineer - Critical Infrastructure Protection
Johns Hopkins Applied Physics Laboratory Laurel, Maryland, United States
-
Technical Product Manager - Cybersecurity
X-PHY Singapore, Singapore
-
Analyst - Cybersecurity Business Partner
Qiddiya Investment Company Riyadh, Riyadh Region, Saudi Arabia
-
Cybersecurity and IT Governance Lead (TS/SCI, Contingent)
Zaden Tech Maryland, United States · $135K–$157K/yr