Application Security Analyst will be responsible for performing security assessments and penetration tests on our applications, identifying vulnerabilities, and providing actionable recommendations for mitigation. 

RESPONSIBILITIES

  • Conduct comprehensive security assessments of application software, architectures, and designs to identify vulnerabilities, weaknesses, and security gaps.
  • Utilize methodologies such as threat modeling, risk assessment, and security architecture reviews to evaluate application security.
  • Design and implement security controls, mechanisms, and countermeasures to mitigate identified risks and threats.
  • Ensure robust security practices such as input validation, authentication, authorization, encryption, and logging are integrated into the development lifecycle.
  • Perform code reviews, static and dynamic analysis, and security testing (e.g., penetration testing, fuzz testing) to identify and remediate security vulnerabilities in application code and configurations.
  • Collaborate with development teams to embed security testing.
  • Provide guidance on secure coding practices for technologies such as .NET, Java, and others.
  • Ensure compliance with relevant regulatory requirements, industry standards, and best practices for application security, data privacy, and information security management (e.g., GDPR, PCI DSS, HIPAA).
  • Develop and maintain security standards like (ISO 27001, etc). policies, procedures, and documentation to demonstrate compliance with legal and regulatory mandates.
  • Coordinate and support internal and external audits, assessments, and certifications related to application security and compliance.
  • Prepare for, respond to, and remediate findings from security audits and assessments.
  • Monitor application security events, alerts, and logs for signs of unauthorized access, suspicious activities, or security breaches.
  • Develop and implement incident response plans, and procedures to facilitate timely detection, containment, and resolution of security incidents and breaches. 

Skills

  • Minimum 2-3 years of experience in application security roles, with a focus on designing, implementing, and managing security controls for web applications, mobile apps and cloud-based services.
  • Proficiency in application security assessment tools and techniques, including static and dynamic analysis, vulnerability scanning and penetration testing tools.
  • Strong understanding of secure coding practices, web application frameworks (e.g., Angular, React, Node.js) and programming languages (e.g., Java, .NET, Python, JavaScript).
  • Familiarity with security standards and frameworks as well as relevant regulatory requirements (e.g., GDPR, PCI DSS, HIPAA, ISO/IEC 27001).
  • Excellent analytical and problem-solving skills, with the ability to assess complex application security risks, identify root causes and recommend effective mitigation strategies.
  • Strong communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams, and articulate technical concepts to non- technical stakeholders.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Department:
Deployment & Configuration
Job Location:
Gender:
No Preference
Age:
18 - 50 Years
Minimum Education:
Bachelors
Degree Title:
Bachelor’s (4 Years) or master’s degree in computer science, Information Security, or a related field.
Career Level:
Experienced Professional
Minimum Experience:
2 Years (Minimum 2-3 years of experience in application security roles, with a focus on designing, implementing, and managing security controls for web applications, mobile apps and cloud-based services)
Apply Before:
Jun 26, 2024
Posting Date:
Jun 04, 2024

Pakistan Revenue Automation (Pvt) Ltd

Information Technology · 1001-1500 employees - Islamabad

Pakistan Revenue Automation (Pvt.) Ltd. (acronym – PRAL) has extensive experience of working with federal and provincial tax and revenue agencies to provide wide variety of tax and revenue collection solutions. Since its incorporation in June, 1994, PRAL has been involved in the development of wide array of tax and revenue related solutions pertaining to Income Tax, General Sales Tax, Federal Excise, Customs, Capital Value Tax, Provincial Sales Tax & Services. etc. Over more than two decades of services, PRAL has gained valuable experience of increasing efficiency and efficacy of tax and revenue agencies through use of latest Information and Communication Technologies with Business Process Improvement / Re-engineering. PRAL has also proven its expertise in the areas of software development, project management, technical advisory and consulting services, managing data centers, large databases management, network administration, software implementations, trainings and data entry services. This wide spectrum of services offered by PRAL facilitates our valued customers looking for One-Stop Shop solutions from conceptualization to post-implementation operations. The essence of PRAL’s business strategy is to develop sustainable partnerships with its customers thus acting as a catalyst in transforming and adapting its IT solutions and integrating these to the “New Wave of Technological Innovations” to meet the global requirements of tax and revenue agencies.

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium

Similar Job Titles

Security Operations Analyst

Atheneum, Lahore, Pakistan
Posted Jun 03, 2024

Cyber Security Analyst

Exceinov Private Limited, Lahore, Pakistan
Posted Jun 01, 2024
I found a job on Rozee!