We are looking for an experienced Application Security Engineer to lead a critical security initiative focused on addressing application-level security gaps identified during Amazon's security review. The goal is to ensure our platform meets compliance standards and gains approval for integration with Amazon. This role is hands-on and application-centric, specifically excluding responsibilities related to cloud infrastructure or Azure administration, which are managed by dedicated specialists. The successful candidate will translate Amazon’s security and compliance requirements into effective application-level solutions and implement them swiftly across both web and mobile platforms.

Key Responsibilities

- Identify and remediate application-level security vulnerabilities that hinder compliance with Amazon’s security requirements and industry standards.
- Implement encryption protocols for sensitive data and personally identifiable information (PII) throughout the application.
- Design and integrate secure key management and secrets management solutions.
- Develop fine-grained role-based access control (RBAC) and permission frameworks across all user roles and system functions.
- Design and deploy Multi-Factor Authentication (MFA) and other advanced authentication mechanisms for web and mobile applications.
- Review and improve the handling of sensitive information in terms of storage, transmission, access, and display across the platform.
- Enhance authentication, authorization, session management, and account security controls.
- Implement audit logging and tracking for sensitive data access and security-related activities.
- Integrate automated vulnerability scanning and code security checks (SAST/DAST) into the software release process.
- Collaborate with cloud and security teams to ensure application changes support infrastructure-level security controls.
- Ensure the platform consistently aligns with Amazon’s compliance expectations and modern security best practices.

Required Qualifications

- Minimum of 5 years of experience in application security and/or secure software development.
- Strong hands-on expertise in data encryption, key management, and secrets management.
- Proven experience implementing RBAC, MFA, and secure authentication/session management in production environments.
- Deep understanding of OWASP Top 10 vulnerabilities, secure coding standards, and vulnerability remediation techniques.
- Experience integrating security tools such as SAST and DAST into CI/CD pipelines.
- Demonstrated ability to secure both web and mobile applications effectively.
- Experience working toward third-party or enterprise compliance requirements such as Amazon, PCI DSS, or SOC 2 is highly desirable.
- Excellent communication and collaboration skills to work efficiently with cross-functional teams.

Preferred Qualifications and Job Details

While not mandatory, experience with enterprise compliance frameworks and security certifications will be considered an advantage. This position operates onsite, Monday through Friday, from 9:00 AM to 6:00 PM (PKT). Candidates should have at least five years of relevant experience to be considered.

This role offers a unique opportunity to contribute directly to a high-impact security project, ensuring the platform’s readiness for integration with a major industry partner while advancing your expertise in application security.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Career Level:
Mid-Level
Experience:
3 Years - 5 Years
Apply Before:
Oct 03, 2026
Posting Date:
Sep 27, 2026

Avaib

· 11-50 employees - Karachi

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

I found a job on Rozee!