Talent.com
Web Application Security Engineer

Web Application Security Engineer

CXM Direct LLCPK
4 days ago
Job type
  • Quick Apply
Job description

Position Overview

We are seeking an experienced Web Application Security Engineer to join our team in a unique purple team capacity. This role represents a strategic blend of offensive penetration testing expertise and defensive blue team capabilities, with a specialized focus on securing our web applications and SD-WAN network infrastructure. The successful candidate will be responsible for conducting comprehensive security assessments of our web applications while simultaneously strengthening our defensive posture across our complex proxy and reverse proxy architecture.

This position is ideal for a security professional who thrives at the intersection of offensive and defensive security, possesses deep technical knowledge of web application vulnerabilities, and understands the nuances of securing modern SD-WAN environments. You will work collaboratively with development teams, network engineers, and operations staff to identify vulnerabilities, validate security controls, and drive continuous improvement in our security posture.

Core Responsibilities

Offensive Security (Penetration Testing)

The offensive component of this role involves conducting thorough and methodical penetration tests against our web applications, APIs, and network infrastructure. You will be responsible for identifying security vulnerabilities through manual testing techniques, automated scanning tools, and creative attack scenarios that simulate real-world threat actors. This includes testing authentication mechanisms, authorization controls, input validation, session management, and business logic flaws across our application portfolio.

You will perform security assessments of our SD-WAN infrastructure, with particular emphasis on proxy configurations, reverse proxy implementations, SSL / TLS termination points, and web application firewalls. This requires understanding how traffic flows through our network architecture and identifying potential attack vectors that could compromise confidentiality, integrity, or availability.

Defensive Security (Blue Team Operations)

On the defensive side, you will monitor security events, analyze logs from our WAF and proxy infrastructure, and respond to security incidents affecting our web applications. You will work closely with SOC protocols to investigate suspicious activities, perform root cause analysis of security breaches, and implement corrective measures to prevent recurrence.

You will be responsible for tuning and optimizing our security controls, including WAF rules, proxy access controls, rate limiting configurations, and DDoS mitigation strategies.

Purple Team Collaboration

As a purple team member, you will serve as a bridge between offensive and defensive security functions. You will design and execute purple team exercises that test both our detection capabilities and our defensive controls. After conducting penetration tests, you will work with blue team members to ensure that our monitoring systems can detect similar attacks in the future, creating detection rules and improving our reliability.

You will facilitate knowledge transfer and help defenders understand the techniques used by attackers. This collaborative approach ensures that our security program continuously evolves based on real-world testing and operational feedback.

Security Integration and Automation

You will develop automation scripts and tools to streamline repetitive security tasks, such as vulnerability scanning, configuration auditing, and security report generation. This automation will enhance the efficiency of security operations, allowing for more time to be devoted to complex analysis and strategic security initiatives.

Requirements

Required Qualifications

  • Education Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related technical field; or equivalent practical experience
  • ExperienceMinimum 3-5 years of hands-on experience in web application penetration testing and security assessment
  • Technical Skills Deep understanding of OWASP Top 10 vulnerabilities, common web application attack vectors, and remediation strategies
  • Network Security Practical experience with SD-WAN technologies, forward proxies, reverse proxies (Nginx, HAProxy, Apache), and load balancers
  • Security Tools Proficiency with Burp Suite Professional, OWASP ZAP, Nmap, Metasploit, and vulnerability scanning platforms
  • Programming Strong scripting abilities in Python, Bash, or PowerShell; familiarity with JavaScript, PHP, Java, or .NET for code review
  • Blue Team Skills Experience with SIEM platforms, log analysis, incident response procedures, and threat hunting methodologiesWAF / IPS
  • Hands-on experience configuring and tuning web application firewalls and deep packet inspections

Preferred Qualifications

Experience with cloud security, particularly in AWS, Azure, and alternative cloud environments, is beneficial given the hybrid nature of modern infrastructure. Familiarity with container security (Docker, Kubernetes), API security testing (REST, GraphQL, SOAP), and mobile application security adds significant value to this role.

Previous experience in a purple team capacity, or demonstrated ability to work effectively across offensive and defensive security functions, is strongly preferred. Excellent written and verbal communication skills are essential, as you will be producing detailed security reports, presenting findings to technical and non-technical audiences, and collaborating with diverse stakeholders.

Benefits

Competitive Compensation

Medical

Gym Allowance

Company Events

Personal Growth

Create a job alert for this search

Application Engineer • PK

Related jobs
  • Promoted
Cyber Security Engineer

Cyber Security Engineer

ItcsIslamabad, Islamabad Capital Territory, Pakistan
Microsoft Defender for Endpoint Specialist.The ideal candidate will play a key role in deploying and managing Microsoft Defender for Endpoint solutions to ensure robust endpoint security across the...Show moreLast updated: 30+ days ago
  • Promoted
Cyber Security Expert - Islamabad

Cyber Security Expert - Islamabad

JAZZIslamabad, Islamabad Capital Territory, Pakistan
What is a Cyber Security Expert?.A professional responsible for safeguarding IT systems, applications, and data by implementing advanced security solutions, conducting risk assessments, and ensurin...Show moreLast updated: 5 days ago
  • Promoted
DevSecOps Engineer

DevSecOps Engineer

Datamatics TechnologiesIslamabad, Islamabad Capital Territory, Pakistan
We are seeking a highly experienced DevSecOps engineer.Design and implement Azure Cloud services for applications and projects. Ensure implementation follows architectural and security guidelines an...Show moreLast updated: 5 days ago
  • Promoted
Web Application Developer

Web Application Developer

InoTech Solutions Pvt LtdIslamabad, Pakistan
Bachelor's degree in Computer Science or a related field is required.We are seeking a talented and experienced Web Application Developer to join our team. As a Web Application Developer, you will be...Show moreLast updated: 30+ days ago
  • Promoted
IT / Cyber Security Engineer

IT / Cyber Security Engineer

AI JobsRawalpindi Cantonment, Pakistan
Based in London, United Kingdom.Bachelor\'s degree in Computer Science, Information Technology, or a related field.As a new cyber security company, we are seeking three new employees for our London...Show moreLast updated: 30+ days ago
Web & App Developer

Web & App Developer

Remote VAPK
Quick Apply
RemoteVA PH is seeking a skilled Web & App Developer to join our dynamic team.The ideal candidate will have a strong background in UI / UX design for websites and experience in mobile application...Show moreLast updated: 30+ days ago
  • Promoted
Full Stack Web Developer

Full Stack Web Developer

AppologixRawalpindi Cantonment, Pakistan
Job description We are looking to hire a.NET / Angular Developer to design and develop software and web application in the. Someone who is confident with their ability to write code from scratch and...Show moreLast updated: 30+ days ago
  • Promoted
Web Application Developer

Web Application Developer

Voice Bridge communicationsIslamabad, Pakistan
Bachelor's degree in Computer Science or related field We provide high-quality customer service solutions to businesses in the consumer services industry. We are currently seeking a skilled Web Appl...Show moreLast updated: 30+ days ago
  • Promoted
Software Security Engineer

Software Security Engineer

CodesbyteIslamabad, Pakistan
We are looking for a skilled Security Engineer to analyze software designs and implementations from a security perspective, and identify and resolve security issues. You will include the appropriate...Show moreLast updated: 30+ days ago
  • Promoted
Network Security Engineer

Network Security Engineer

Nova CommunicationsIslamabad, Pakistan
We are hiring Network Security Engineers who can detect, defend, and defeat cyber threats.At NOVA, you’ll work with advanced security tools, protect high-profile networks, and contribute to innovat...Show moreLast updated: 30+ days ago
  • Promoted
Senior Network Security Engineer - REMOTE

Senior Network Security Engineer - REMOTE

Wryneck gbrIslamabad, Pakistan
Senior Network Security Engineer - REMOTE.The ideal candidate will be responsible to support Junior Staff in their Projects Remotely and also do the projects independently.Qualifications : Becholar ...Show moreLast updated: 30+ days ago
  • Promoted
Application Security Engineer

Application Security Engineer

IntercraftsolIslamabad, Pakistan
The ideal candidate will specialize in isolation technologies, threat detection, and policy enforcement, working closely with DevOps and engineering teams to ensure system integrity, compliance, an...Show moreLast updated: 30+ days ago
  • Promoted
Web Specialist

Web Specialist

Data SolutionsIslamabad, Pakistan
Actively participate in complete development life cycle of the product.Manage existing projects and work on new products. Translate requirements into good design and develop prototypes for review by...Show moreLast updated: 30+ days ago
  • Promoted
Software Engineer

Software Engineer

Developer Desks Technology, Islamabad Capital Territory, Pakistan, Islamabad Capital Territory, Pakistan
We are looking for a 'Software Engineer' to join our thriving team at Developers Desk Technology.Must have proven professional industry experience working on web / mobile application development with...Show moreLast updated: 30+ days ago
  • Promoted
Application Developer

Application Developer

IT Beams TechnologyIslamabad, Islamabad Capital Territory, Pakistan
We are seeking an energetic and dedicated developer to join our team.The position allows for remote work.If you are passionate about coding and problem-solving, we would like to hear from you.Devel...Show moreLast updated: 30+ days ago
  • Promoted
Web Developer

Web Developer

Wasko InternationalIslamabad, Pakistan
Job Title : Website Developer (E-commerce) Job Type : Contract Experience Level : Experienced Company Overview : We are looking for a forward-thinking individual in the development of e-commerce websit...Show moreLast updated: 30+ days ago
  • Promoted
Blockchain Developer

Blockchain Developer

Neben SolutionsIslamabad, Pakistan
Get AI-powered advice on this job and more exclusive features.We are looking for a skilled Blockchain / Web 3.Developer to join our dynamic team. The ideal candidate will have hands-on experience in...Show moreLast updated: 27 days ago
Azure DevSecOps Engineer

Azure DevSecOps Engineer

Datamatics TechnologiesIslamabad, Federal Teritory, PK
Quick Apply
Job description We are seeking a highly experienced Azure DevSecOps engineer.Location : Remote Work Timings : UK Time Zone Availiblity : 3o to 60 Days Maximum Experience : 8+ Years i...Show moreLast updated: 1 day ago