LOLC Microfinance Bank is seeking a dedicated Application Security Analyst with at least three years of experience to safeguard our digital assets from security threats and vulnerabilities. The successful candidate will lead a small team of two security specialists and coordinate efforts to identify, assess, and mitigate risks related to application security within our organization. This role involves hands-on application security testing, vulnerability assessments, and managing security incidents, ensuring adherence to industry standards and regulatory compliance requirements. The position requires someone who can effectively communicate complex security concepts to diverse audiences and collaborate with technical teams to enhance our security posture. The Application Security Analyst will play a pivotal role in maintaining the banks security infrastructure by continuously monitoring security events, performing risk analysis, and leading incident response activities. A thorough understanding of web application vulnerabilities, especially OWASP Top 10, and cloud security best practices is essential. The role demands strong project management skills and in-depth knowledge of information security frameworks such as ISO 27001, COBIT, NIST, and ETGRMF to ensure all security measures align with regulatory standards relevant to the financial sector. The analyst will also ensure compliance with internal and external requirements while proactively identifying and addressing emerging security threats.
Responsibilities

  • Lead and manage a team of two security analysts to conduct application security assessments and testing.
  • Perform vulnerability assessments on web-based applications, focusing on OWASP Top 10 vulnerabilities and other emerging threats.
  • Develop and implement application security testing strategies to identify security weaknesses and provide remediation recommendations.
  • Coordinate and execute incident response activities, including detection, triage, analysis, remediation, and reporting of security incidents.
  • Manage Security Information and Event Management (SIEM) systems to monitor security events and alerts in real time.
  • Conduct detailed risk analysis to identify potential security threats and recommend mitigation strategies aligned with company risk tolerance.
  • Ensure compliance with relevant regulatory standards and frameworks such as ISO 27001, COBIT, NIST, and ETGRMF within the banks security practices.
  • Collaborate with development, operations, and cloud infrastructure teams to integrate security best practices into the software development lifecycle and cloud environment.
  • Review and update security policies, procedures, and documentation to reflect changes in technology, compliance requirements, and threat landscape.
  • Communicate security findings and complex technical concepts effectively to both technical teams and non-technical stakeholders including executive management.
  • Stay current with emerging application security threats, industry trends, and regulatory changes impacting the financial sector.
  • Lead and participate in security awareness and training sessions to promote a culture of security mindfulness across the organization.
  • Contribute to the development and enhancement of security tools, processes, and technologies to improve overall application security posture.
  • Perform cloud security assessments and ensure controls are in place to protect cloud infrastructure and data in line with industry best practices.
  • Support audit and compliance activities by providing necessary documentation and evidence related to application security controls.

Job Details

Total Positions:
1 Post
Job Type:
Job Location:
Gender:
No Preference
Minimum Experience:
3 Years
Apply Before:
Aug 15, 2026
Posting Date:
Jul 14, 2026

LOLC Microfinance Bank

· 1001-1500 employees - Islamabad

LOLC Microfinance Bank was formerly known as Pak Oman Microfinance Bank Limited (the Bank) that was incorporated on 09 March 2006 as a public limited company under Companies Ordinance, 1984 (Repealed with the enactment of the Companies Act, 2017 on 30 May 2017) and was granted a license by the State Bank of Pakistan (SBP) on 12 April 2006.

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium
I found a job on Rozee!