Quick Overview
- CategoryInformation Technology
- LocationKathmandu
- Job TypeContract
- Experience5+ years
- EducationSLC / SEE
- SalaryNegotiable
- Deadline2026-08-11
Required Skills
Job Description
We are seeking a skilled Application Security Engineer with 3-5 years of relevant experience for a three-month contract. The candidate will assess and improve the security of our web portal, codebase, APIs, third-party integrations, infrastructure, and related systems while supporting better code quality and secure development practices.
Key Responsibilities
Security Assessment: Review the web portal, APIs, codebase, configurations, and peripheral systems for security risks.
Secure Code Review
Identify vulnerabilities, insecure coding practices, and code-quality issues.
Vulnerability Testing
Conduct authorized vulnerability assessments and penetration testing.
Remediation Support: Recommend practical fixes, collaborate with developers, and retest resolved issues.
Dependency Review: Assess third-party libraries, plugins, packages, and integrations for vulnerabilities.
Reporting: Prepare clear reports with risk levels, supporting evidence, and remediation recommendations.
Required Skills & Qualifications
Experience: 3–5 years of experience in application security, cybersecurity, penetration testing, or secure software development.
Web Security: Strong understanding of the OWASP Top 10, authentication, authorization, session security, and data protection.
Code Security: Experience reviewing application code for security, reliability, and maintainability.
API Security
Good knowledge of REST APIs, HTTP, access controls, and common API vulnerabilities.
Security Tools
Experience with SAST, DAST, dependency scanning, and penetration-testing tools.
Technical Knowledge: Familiarity with cloud environments, databases, Linux, Docker, CI/CD, logging, and secrets management.
Communication: Ability to clearly explain security risks and remediation steps to technical and non-technical stakeholders.