CapitalSage Holdings

Application Security Engineer

CapitalSage Holdings Lagos, Lagos State, Nigeria

Investment Management · 201-500 employees

Yesterday
security Senior (5-10 yrs) Full-time Nigeria
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves protecting applications by identifying and reducing security risks throughout the software development lifecycle. Responsibilities include performing security assessments, code reviews, threat modelling, and enforcing secure coding practices across digital channels.

What they look for

Application Security Code Review Security Testing Checkmarx Threat Modelling Security Architecture OWASP Vulnerability Management API Security Secure Coding Risk Reporting Stakeholder Management Cybersecurity Information Technology

Requirements

Candidates must hold a relevant degree in Cybersecurity, Computer Science, or a related field and possess demonstrable practical experience. Professional certifications such as OSCP, eWPT, or CSSLP are considered a significant advantage.

Benefits

Industry Standard

Full description

Role Purpose: Protect the Group's applications by identifying, assessing and reducing application security risks throughout the software lifecycle.

Key Responsibilities:

  • Perform application security assessments, code reviews and security testing.
  • Manage and optimize application security tools and processes, including Checkmarx.
  • Conduct threat modelling and security architecture reviews for applications.
  • Support remediation of OWASP and application-specific vulnerabilities.
  • Assess APIs, web applications, mobile applications and other digital channels.
  • Work with development teams to establish and enforce secure coding practices.
  • Support security testing before production release.
  • Maintain application security standards, metrics and risk reports.

Requirements

  • Relevant degree or equivalent professional qualification in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline.
  • Relevant professional certifications will be an advantage and should align with the specific role.
  • Demonstrable practical experience relevant to the position.
  • Strong communication, analytical, documentation and stakeholder-management skills.
  • Ability to operate in a regulated, technology-driven and multi-business environment.

Preferred / Added Advantage Certifications

  • OSCP – Offensive Security Certified Professional
  • eWPT or equivalent web application security certification
  • CSSLP – Certified Secure Software Lifecycle Professional
  • Checkmarx certification/training (advantage)

Benefits

Industry Standard

Similar roles