Application Security Engineer

Sterling Wells Nepal — Nepal · Posted ~4 hours ago

Mid Full-time Onsite

Skills

Application Security Azure Java Spring Boot Node.js TypeScript React APIs Web Security Mobile Security SaaS Security Microsoft Azure

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A hands-on Application Security Engineer is needed to protect live, multi-tenant SaaS platforms and assess whether applications and systems withstand real-world attacks. The role spans cloud-hosted web and mobile applications, APIs, backend services, databases, event-driven systems, integrations, and automated engineering workflows.

Highlights

A hands-on security role with broad exposure to web and mobile applications, APIs, cloud infrastructure, backend services, and modern SaaS architecture.

Description

Sterling Wells Nepal is the operational hub of a UK-based group of chartered certified accountancy firms and fintech companies, including UK Property Accountants, Sterling & Wells, Crane & Partners, FigsFlow, RentalBux, Taxule, and PropertySPV. We support thousands of clients across 50+ countries and oversee accounting for $8B+ in assets. We are looking for an Application Security Engineer to strengthen the security of our live, multi-tenant SaaS platforms from our Kathmandu office. This is a full-time, hands-on role in Engineering, focused on one question: does the code we write and the systems we build hold up when someone tries to break them? You will work across a customer-facing platform hosted in Microsoft Azure, covering web and mobile applications, APIs, and backend services built mainly in Java and Spring Boot alongside Node.js and TypeScript with React front ends, supported by relational and document databases, event-driven services, third-party integrations, and automated build and deployment pipelines. What you’ll own Threat modelling with delivery squads, helping teams identify trust boundaries, attack paths, and high-risk design decisions before implementation.Security design reviews of new features, integrations, and higher-risk changes, with practical recommendations and challenge where required.Code reviews on security-sensitive surfaces, including authentication, authorisation, tenant boundaries, identity services, external integrations, and OAuth, OpenID Connect, and API permission scopes.Tenant isolation assurance, proving through targeted testing and automation that access-control boundaries, customer data segregation, and authorisation controls continue to hold.Hands-on testing of web applications, APIs, mobile applications, and third-party integrations, including how customer data moves across integration boundaries, rather than relying on automated tooling alone.The security testing toolchain, embedded proportionately within the software development lifecycle so that findings remain meaningful, prioritised, and actionable.Triage of findings from code analysis, security testing, penetration tests, and vulnerability assessments, working with developers to drive remediation.External penetration tests, from scoping through to evidenced closure of every finding.Investigation of application-level security incidents, identifying the control improvements that prevent recurrence.Reporting on application security posture, remediation progress, testing coverage, and key risks, supported by clear technical and remediation documentation.This is a hands-on engineering role, suited to someone who reads code properly, tests systems directly, and helps developers fix issues at the source. What we need 4+ years of experience in software engineering, application security, product security, or a related field, with hands-on responsibility for securing software applications.Strong coding ability in Java and Spring Boot, or TypeScript and Node.js, and comfort reviewing code across both stacks.End-to-end ownership of at least one of the following: a vulnerability management programme, a penetration test engagement from scope to closure, or a threat modelling practice adopted by engineering teams; this is essential.Multi-tenant SaaS experience, including tenant isolation testing, access-control validation, and customer data segregation.A track record of building automated security checks that run continuously within the development lifecycle, not just point-in-time manual reviews.Strong practical knowledge of web and API security, authentication, authorisation, OAuth, OpenID Connect, access-control failures, injection risks, and the OWASP Top Ten.Hands-on experience with SAST, dependency scanning, and application testing tools such as Burp Suite or OWASP ZAP.Comfort working in modern cloud-hosted environments, with experience of CI/CD pipelines, source control, and modern engineering practices.Clear written and spoken communication in English, with the confidence to explain risk to developers and product leads. Nice to have Identity and authorisation design for multi-tenant applications.Mobile application security for iOS and Android.Experience with event-driven and message-based architectures.Security testing of AI and LLM-enabled features.Experience working in regulated or compliance-sensitive environments. Who you are Curious about how systems break, and disciplined about proving they don’t.Ready to challenge a design or a release when the risk is not acceptable.Practical and collaborative; you help developers fix issues, not just report them.Willing to take full ownership of your work. What makes this role different This is not a scan-and-report role; you will review code, test directly, and prove that controls work.You will work across the wider platform estate rather than a single product.You will work closely with delivery squads, Product Leads, IT, Security, Cloud, and DevOps teams within a UK-based international group.You will have the scope to shape how security is built into the development lifecycle, not just follow existing processes. What we offer Competitive salary package based on experience and qualification.Access to Sterling Wells Academy, LinkedIn Learning, and structured development programmes.At least one month of total working time dedicated to training and development annually.Five-day working week, with Saturday and Sunday off.Daily office lunch, paid annual leave, and sick leave.Accident and medical insurance coverage.Regular team-building activities and cultural events. If you are an engineer who would rather prove a control works than assume it does, this is your role. Apply with your CV and a brief note on a vulnerability management programme, penetration test, or threat modelling practice you have owned end to end. #Hiring #ApplicationSecurity #AppSec #ProductSecurity #CyberSecurity #SaaS #KathmanduJobs #NepalHiring #SterlingWellsNepal