Senior Application Security Engineer

5 days ago


Pretoria, South Africa Digicert Full time

Who we are We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to the little things like surgically embedded pacemakers. We help companies put trust - an abstract idea - to work. That's digital trust for the real world. Job summary As a Senior Application Security Engineer specializing in application security and DevSecOps within our cybersecurity team, you will play a crucial role in safeguarding our company's web applications by integrating security practices into the Software Development Life Cycle (SDLC). You will be responsible for the proactive identification, assessment, and mitigation of security vulnerabilities, developing and driving the adoption of DevSecOps practices, and ensuring that security is embedded in all phases of software development. This is a remote position. What you will do Lead the integration of security measures into the SDLC, ensuring that all aspects of web application development are secure by design. Conduct thorough security assessments and penetration testing for web applications to identify vulnerabilities and security gaps. Play an advisory role with software engineering teams in the architectural design of new applications, emphasizing secure architectural patterns and best practices. Perform and coordinate manual and automated code reviews. Lead threat modeling exercises across engineering teams. Collaborate with software development teams to implement DevSecOps practices, providing guidance on secure coding, automated security testing, and continuous monitoring. Contribute to internal security tooling development or integration. Develop and maintain a secure framework for code deployment, automating security processes where possible to streamline the development workflow. Work cross-functionally with various teams, including IT, engineering, operations, and business units, to communicate security policies and procedures effectively. Establish and maintain strong relationships with stakeholders, presenting complex security concepts in an accessible manner. Stay abreast of the latest security threats, trends, and technologies in web application security and incorporate this knowledge into company practices. Assist in the development and enforcement of security policies and procedures, ensuring compliance with industry standards and regulations. Assist with managing bug bounty program. Develop program documentation to promote operational stability and scalability. Support Leadership in defining and executing the roadmap for DevSecOps maturity and secure SDLC initiatives. Support governance and compliance teams on secure engineering practices for aligning security policies related to SDLC Drive and support security identified remediation efforts. Foster and promote a security-forward culture. Mentor junior team members. Other duties and responsibilities, as assigned. What you will have Bachelor’s or master’s degree in computer science, cybersecurity, or a related field. Professional security certifications such as CISSP, OSCP, CEH, or equivalent are highly desirable. 5+ years of experience in cybersecurity, with a focus on web application security and secure SDLC. Experience with red team implementation and methodologies. Proven track record of working with DevSecOps tools (such as SAST/DAST/SCA) and methodologies. Strong understanding of security protocols, cryptography, authentication, authorization, and security vulnerabilities. Proficiency with programming/scripting languages such as JavaScript, Python, Java, Bash, PowerShell Excellent communication skills with the ability to engage technical and non-technical stakeholders. Strong analytical and problem-solving abilities, with a meticulous attention to detail. Advanced level of knowledge of Information Security design concepts and principles Nice to have Master's degree in a technical discipline Experience working in highly regulated environments. Advanced level of knowledge of IT frameworks and standards (NIST, OWASP Top Ten, COBIT, ITIL, ISO, PCI-PIN, GDPR, WebTrust, FedRAMP) Certified Information Systems Auditor (CISA) AWS Solutions Architect Benefits Provident Fund Medical Aid + Gap Cover Employee Assistance Program Gym Reimbursement Life Insurance Disability Insurance Sabbatical #LI-GA1 __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT __PRESENT #J-18808-Ljbffr


  • Security Engineer

    3 weeks ago


    Pretoria, South Africa Air Chefs Full time

    Security Engineer Air Chefs We're looking for an experienced Security Engineer to support our cybersecurity and compliance efforts across product, operations, and infrastructure. Key Responsibilities Cybersecurity Management (40%) Develop and maintain security standards and processes to support compliance requirements. Oversee cybersecurity operations and...

  • Security Engineer

    5 days ago


    Pretoria, South Africa wePlace Full time

    Job Purpose:Responsible for company-wide cybersecurity and related documents, process and record management to ensure that systems and products are safe and effective. Ensures data integrity, and that information is kept accurate and consistent unless authorized changes are made (and documented), and that confidentiality is upheld by protecting information...

  • Lead Applications

    2 weeks ago


    Pretoria, South Africa IT Ridge Technologies Full time

    The main purpose of this position is to provide technical leadership and guidance in the application and integration security function, in support of secure business applications development, implementation and maintenance. Detailed description Contribute to the compilation of divisional operational plans and take responsibility for the implementation as...

  • Structural Engineer

    3 weeks ago


    Pretoria, South Africa Gig Engineer Full time

    Structural Engineer (Resident Engineer) Location: Sedibeng District Municipality, Vereeniging Area – Gauteng, South Africa An exciting opportunity exists to join a major greenfields industrial development project in the Sedibeng region. Role Overview We are seeking a Structural Resident Engineer (RE) on behalf of our client. The successful candidate will...

  • Security Engineer

    3 weeks ago


    Pretoria, South Africa Hearx Full time

    Role DescriptionResponsible for company-wide cybersecurity and related documents, process and record management to ensure that systems and products are safe and effective. Ensures data integrity, and that information is kept accurate and consistent unless authorized changes are made (and documented), and that confidentiality is upheld by protecting...

  • Security Engineer

    3 weeks ago


    Pretoria, South Africa findojobs-za Full time

    Job Purpose Responsible for company-wide cybersecurity and related documents, process and record management to ensure that systems and products are safe and effective. Ensures data integrity, and that information is kept accurate and consistent unless authorized changes are made (and documented), and that confidentiality is upheld by protecting information...

  • Security Engineer

    5 days ago


    Pretoria, South Africa wePlace Full time

    Job Purpose: Responsible for company-wide cybersecurity and related documents, process and record management to ensure that systems and products are safe and effective. Ensures data integrity, and that information is kept accurate and consistent unless authorized changes are made (and documented), and that confidentiality is upheld by protecting information...

  • Security Engineer

    5 days ago


    Pretoria, South Africa The Hiring House Full time

    Key Performance Areas - Cybersecurity Management- Infrastructure Management- Risk Management and Compliance- QMS and Documentation Minimum education (essential):- Engineering degree (Computer, Software, Mechanical or Electronic)Minimum education (desirable):- OSCP (Offensive Security Certified Professional)- PNPT (Practical Network Penetration Tester)- CISSP...

  • Security Engineer

    3 days ago


    Pretoria, Gauteng, South Africa Weplace Full time R120 000 - R180 000 per year

    Our client, an award-winning MedTech is looking for a Security Engineer to join their team.  Job Purpose: Responsible for company-wide cybersecurity and related documents, process and record management to ensure that systems and products are safe and effective. Ensures data integrity, and that information is kept accurate and consistent unless authorized...

  • Security Supervisor

    1 week ago


    Pretoria, South Africa PABC Security Solutions Full time

    Job Advertisement: Security Operations Supervisor Location: 323 North Village Lane, Lynwood, Pretoria Company: PABC Security Solutions Job Overview: Key Responsibilities: Develop and implement strategies to enhance operational efficiency Conduct regular risk assessments and enforce appropriate mitigation measures Manage site personnel, including...