We are looking for an experienced Application Security Engineer to lead a critical security initiative focused on closing application-level security gaps identified during Amazon’s security review. The goal is to ensure our platform meets compliance requirements and gains approval for integration with Amazon. This role is highly hands-on and application-centric, with no responsibilities related to cloud infrastructure or Azure administration, as those are managed by dedicated specialists. The successful candidate will translate Amazon’s security and compliance mandates into effective application-level solutions and implement them swiftly across both web and mobile platforms.

Key Responsibilities

- Identify and remediate application-level security vulnerabilities that hinder compliance with Amazon’s security standards and broader industry best practices.
- Implement encryption protocols for sensitive data and personally identifiable information (PII) throughout the application.
- Design and integrate secure key management and secrets management systems.
- Develop fine-grained role-based access control (RBAC) and permission frameworks for all user types and system functions.
- Design and deploy Multi-Factor Authentication (MFA) and other enhanced authentication mechanisms for web and mobile applications.
- Review and improve how sensitive information is stored, transmitted, accessed, and displayed across the platform.
- Strengthen authentication, authorization, session management, and account security controls.
- Implement audit logging and monitoring for sensitive data access and security-related activities.
- Integrate automated vulnerability scanning and code security tools (SAST/DAST) into the release pipeline to enforce secure development practices.
- Collaborate closely with cloud and security teams to ensure application changes support infrastructure-level security controls.
- Ensure ongoing alignment of the platform with Amazon’s compliance expectations and contemporary security best practices.

Required Qualifications

- Minimum of 5 years’ experience in application security and/or secure software development.
- Strong hands-on expertise in data encryption, key management, and secrets management.
- Proven experience implementing RBAC, MFA, and secure authentication/session management in production environments.
- Deep understanding of OWASP Top 10 vulnerabilities, secure coding standards, and vulnerability remediation techniques.
- Experience integrating security tools such as SAST and DAST into CI/CD pipelines.
- Demonstrated ability to secure both web and mobile applications effectively.
- Experience working toward third-party or enterprise compliance requirements, including Amazon, PCI DSS, or SOC 2, is highly desirable.
- Excellent communication and collaboration skills to work effectively with cross-functional teams.

Job Details

- Working hours: 9:00 AM to 6:00 PM (PKT)
- Workdays: Monday to Friday (onsite)
- Required experience: 5+ years

This role offers the opportunity to play a pivotal part in securing a platform critical for integration with a major enterprise partner. The position demands a proactive, detail-oriented professional who thrives in a fast-paced environment and is passionate about application security and compliance.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Career Level:
Mid-Level
Experience:
3 Years - 5 Years
Apply Before:
Oct 02, 2026
Posting Date:
Sep 26, 2026

Avaib

· 11-50 employees - Karachi

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium
I found a job on Rozee!