Senior Security Engineer - Penetration Testing

Selisegroup — Nepal · Posted ~7 hours ago

Senior

Skills

penetration testing threat modeling attack-surface analysis vulnerability assessment security architecture technical security reporting iOS Android REST GraphQL web security mobile security

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a security team responsible for strengthening technology defenses through authorized penetration testing and security architecture. You will test web and mobile applications, APIs, and backend services; perform threat modeling and attack-surface analysis; validate vulnerabilities; and produce actionable reports with remediation guidance.

Highlights

Senior security role with broad responsibility across application, mobile, API, and backend security. The position offers close collaboration with engineering and infrastructure teams, influence over security practices, and opportunities to improve organizational security posture.

Description

Senior Security Engineer – Penetration Testing We are seeking an experienced Senior Security Architect or Senior Security Engineer to strengthen our security posture and help design, implement, and operate secure technology solutions across our organisation. You will partner closely with engineering, infrastructure, product, and business teams to embed security into systems, processes, and delivery practices. What You Will Do Plan and execute authorised penetration tests for web applications, mobile applications (iOS/Android), APIs (REST, GraphQL), and backend services. Perform threat modelling, attack-surface analysis, and risk-based scoping to prioritise testing efforts. Identify, validate, and safely demonstrate vulnerabilities through automated and manual testing techniques. Produce clear technical reports with risk ratings, reproducible steps, proof-of-concept evidence where appropriate, and prioritised remediation recommendations. Collaborate with development, DevOps, and product teams to validate fixes and promote secure design and coding practices. Integrate repeatable security testing into development pipelines, including SAST and DAST where appropriate. Conduct security architecture reviews and assess risks in new and existing systems. Establish and improve security standards, patterns, and technical controls across cloud, applications, infrastructure, identity, and data. Support security reviews, audits, compliance activities, and incident responses as needed. Mentor engineers, share security knowledge and contribute to a collaborative security culture. Who You Are 8+ years of experience in cybersecurity, security engineering, infrastructure engineering, or related fields. Demonstrable experience designing and securing cloud, hybrid, or enterprise environments. Strong knowledge of identity and access management, network security, application security, data protection, incident response, and vulnerability management. Experience with AWS, Microsoft Azure, or Google Cloud Platform. Practical experience with security frameworks such as ISO 27001, NIST CSF, CIS Controls, SOC 2, or similar. Strong understanding of secure coding practices, OWASP Top 10, API security risks, and common exploitation techniques. Experience with penetration-testing tools such as Burp Suite, ZAP, Nmap, Metasploit, sqlmap, and API fuzzers. Scripting and automation skills in Python, Bash, or similar languages. Ability to communicate technical security risks and remediation recommendations clearly to technical and non-technical stakeholders. Strong analytical skills, attention to detail, and the ability to prioritise findings by business impact. Ability to mentor junior team members and collaborate effectively with engineering and SOC teams. Preferred Qualifications Experience with DevSecOps, CI/CD security, infrastructure as code, containers, Kubernetes, or microservices. Experience in regulated environments such as finance, healthcare, insurance, or public sector. Relevant certifications such as CISSP, CISM, CCSP, GIAC, AWS Security Specialty, Azure Security Engineer, or equivalent. Experience leading security projects or influencing architecture decisions across multiple teams. What You Can Expect A competitive salary and growth-oriented career path. A collaborative environment with supportive peers, mentors, and strong engineering culture. Opportunities to participate in innovation initiatives, architecture discussions, and technical leadership. Continuous learning through training, knowledge sharing, and hands-on challenges. Team-building events and recreational activities. Plenty of scope to experiment, innovate, and make a real impact.