Application Security Engineer
Job description
About the role
You will own the execution of application security testing across web and mobile platforms for Paystack's fintech products. You will partner with engineering and DevOps teams to embed security into the full software development lifecycle from the earliest design stages. You will drive vulnerability management processes and coordinate assessments with both internal and external stakeholders. You will establish and maintain security standards aligned with industry frameworks like OWASP, NIST, and MITRE. You will act as the technical authority guiding secure implementation across distributed teams. You will investigate security incidents and help implement preventative controls to avoid recurrence. You will continuously innovate by researching new threats and improving security testing methodologies.
Key facts
What you'll do
- Conduct comprehensive application security testing including web and mobile application security assessments and API security testing.
- Perform threat modelling exercises and attack surface analysis to identify potential security risks before production deployment.
- Execute secure code reviews and support SAST and DAST initiatives to detect vulnerabilities early in the development cycle.
- Manage the vulnerability lifecycle by coordinating internal and external security assessments with clear scoping and timely delivery.
- Track remediation progress and report on metrics to ensure timely resolution of security findings.
- Integrate secure development practices into the SDLC by collaborating with developers, testers, and business analysts during development sprints.
- Contribute to the development of security frameworks, checklists, and guidelines that align with industry standards such as OWASP, NIST, and MITRE.
- Support DevSecOps testing and protective controls to ensure security is embedded within CI/CD pipelines.
- Investigate application security incidents and provide technical guidance for resolution and post-incident analysis.
- Identify process improvements and innovate to enhance the efficiency and effectiveness of security assessments and workflows.
- Stay current with cybersecurity trends, emerging threats, and attack vectors to inform proactive security measures.
- Work cross-functionally with leadership teams at all levels to drive security solutions that protect the platform and build customer trust.
Requirements
- Bring a minimum of 3 years of experience in application security, IT security, or software development with a security focus.
- Demonstrate hands-on experience with penetration testing, vulnerability assessments, and secure code reviews across multiple technology stacks.
- Show proven experience working with SAST, DAST, and threat modelling frameworks in real-world environments.
- Provide evidence of practical knowledge of secure software development practices including OWASP Top 10 and CWE.
- Include hands-on development experience or scripting ability using languages such as Python, JavaScript, or Bash.
- Exhibit a strong understanding of web application security, API security, and cloud security concepts across platforms like AWS, Azure, or GCP.
- Display familiarity with DevSecOps principles and CI/CD security integration patterns to bridge security and engineering workflows.
- Communicate complex security concepts clearly to both technical and non-technical audiences through documentation and discussions.
- Collaborate effectively in a cross-functional environment, working closely with engineering, product, and leadership teams.
Nice to have
- Preferred experience within the financial services or payments domain due to regulatory and risk considerations.
- Familiarity with payment processing systems, transaction flows, and PCI DSS considerations.
- Experience with cloud provider security tools and services specific to AWS, Azure, or GCP.
- Knowledge of automated security testing frameworks and security orchestration tools.
- Understanding of secure API design and modern authentication mechanisms such as OAuth and OpenID Connect.
- Exposure to security training and awareness programs as part of organizational security culture.
Practical notes
This role operates full time from our Lagos office. There may be occasional travel required for security assessments, audits, or meetings with stakeholders. No visa sponsorship is available for this position at this time. The role reports to the leadership of the Information Security function and works closely with engineering leadership.