Application Security Engineer

Aifckz — Kazakhstan · Posted ~2 hours ago

Mid Full-time Onsite

Skills

Application security Secure coding Threat modeling Vulnerability assessment Security architecture Secure SDLC

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A financial technology organization is hiring an Application Security Engineer to design secure architectures, assess vulnerabilities, conduct code reviews, and integrate security practices throughout the software lifecycle.

Highlights

Full-time security engineering role focused on protecting applications, improving secure development practices, and collaborating with technical teams.

Description

Role Description The Application Security Engineer role at AIFC is a full-time, on-site position based in Astana, Kazakhstan. The engineer will collaborate with development and IT operations teams to design, implement, and maintain secure application architectures across AIFC’s platforms. Daily responsibilities include performing security assessments and code reviews, identifying and remediating vulnerabilities, and integrating security tools into the software development lifecycle. The role involves developing and enforcing secure coding standards, monitoring applications for security threats, and responding to security incidents. The engineer will also prepare technical documentation, support audits and compliance efforts, and provide guidance and training to colleagues on application security best practices. Qualifications Demonstrated expertise in application security, including secure software design, threat modeling, and vulnerability assessment.Hands-on experience with security testing tools (e.g., SAST, DAST, dependency scanning, penetration testing frameworks).Strong understanding of web and API security principles, common attack vectors (e.g., OWASP Top 10), and mitigation techniques.Proficiency in at least one programming language commonly used for enterprise applications (such as Java, C#, Python, or JavaScript) and secure coding practices.Experience integrating security into CI/CD pipelines and working within DevSecOps environments.Knowledge of relevant security standards and regulations (e.g., ISO/IEC 27001, PCI DSS, GDPR-like data protection requirements).Ability to analyze complex technical issues, communicate risks clearly, and propose practical security improvements.Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field; relevant professional certifications are an advantage.Strong collaboration skills and experience working with cross-functional teams in a financial or regulated environment is highly beneficial.Proficiency in English.