Application Security Engineer
- CapitalSage Holdings
- Lagos
Role Purpose : Protect the Group's applications by identifying, assessing and reducing application security risks throughout the software lifecycle.
Key Responsibilities:
- Perform application security assessments, code reviews and security testing.
- Manage and optimize application security tools and processes, including Checkmarx.
- Conduct threat modelling and security architecture reviews for applications.
- Support remediation of OWASP and application-specific vulnerabilities.
- Assess APIs, web applications, mobile applications and other digital channels.
- Work with development teams to establish and enforce secure coding practices.
- Support security testing before production release.
- Maintain application security standards, metrics and risk reports.
Requirements
- Relevant degree or equivalent professional qualification in Cybersecurity, Information Technology, Computer Science, Engineering or a related discipline.
- Relevant professional certifications will be an advantage and should align with the specific role.
- Demonstrable practical experience relevant to the position.
- Strong communication, analytical, documentation and stakeholder-management skills.
- Ability to operate in a regulated, technology-driven and multi-business environment.
Preferred / Added Advantage Certifications
- OSCP – Offensive Security Certified Professional
- eWPT or equivalent web application security certification
- CSSLP – Certified Secure Software Lifecycle Professional
- Checkmarx certification/training (advantage)
Benefits
Industry Standard
Skills
- Application Security Assessment
- Secure Code Review
- Threat Modeling
- OWASP
- Checkmarx
- API Security
- Security Architecture Review





