Powered by Information Department Government of Sindh

About the job

 

Job Description

We are seeking an experienced Cyber Security Engineer, Application Security & Compliance (Web & Mobile) to lead a high-priority security initiative: closing the application-level security gaps identified during Amazon's security review, so that our platform can achieve compliance and gain approval to integrate with Amazon. This is a hands-on, application-focused role - you will not be responsible for cloud infrastructure or Azure administration, as those areas are managed by our existing specialists. Your mission will be to translate Amazon's security and compliance requirements into robust application-level solutions and implement them rapidly across our web and mobile platforms.


 

Key Responsibilities:

  • Identify and remediate application-level security gaps that prevent us from meeting Amazon's security requirements and broader industry security standards
  • Implement encryption of sensitive data and PII throughout the application
  • Design and integrate secure key management and secrets management solutions
  • Build fine-grained role-based access control (RBAC) and permission structures across all user types and system functions
  • Design and implement Multi-Factor Authentication (MFA) and other authentication enhancements for web and mobile applications
  • Review and remediate how sensitive information is stored, transmitted, accessed, and displayed across the platform
  • Strengthen authentication, authorization, session management, and account security controls
  • Implement audit logging and tracking of sensitive data access and security-related activities
  • Integrate automated vulnerability scanning, code security checks (SAST/DAST), and secure development practices into the release process
  • Collaborate with cloud and security teams where application changes support infrastructure-level controls
  • Ensure the platform aligns with Amazon's compliance expectations and modern security best practices


 

Requirements:

  • 5+ years of experience in application security and/or secure software development
  • Strong hands-on experience with data encryption, key management, and secrets management
  • Proven track record implementing RBAC, MFA, and secure authentication/session management in production applications
  • Deep understanding of OWASP Top 10, secure coding practices, and vulnerability remediation
  • Experience integrating security tooling (SAST/DAST) into CI/CD pipelines
  • Experience securing both web and mobile applications
  • Experience working toward third-party / enterprise compliance requirements (e.g., Amazon, PCI DSS, SOC 2) is a strong plus
  • Strong communication and collaboration skills for working with cross-functional teams


 

Job Details:

  • Timings: 9:00 AM – 6:00 PM (PKT)
  • Days: Monday – Friday (5 days) — Onsite
  • Experience: 5+ Years.

Salary

Competitive

Monthly based

Location

Karachi Division,Sindh,Pakistan

Job Overview
Job Posted:
2 weeks ago
Job Expire:
2 weeks from now
Job Type
Pvt Job
Job Role
Cyber Security Engineer
Education
Intermediate
Experience
5+ Years
Total Vacancies
1...
Age requirment
18 Year - 40 Year

Job Tags:

Share This Job:

Location

Karachi Division,Sindh,Pakistan