JobExpired · Sep 9, 2026Kabul
Cybersecurity Expert
Ibtekarmind • Full Time
- Publisher source
- ACBAR Jobs
- Published
- Not specified
- Last seen
- Aug 30, 2026, 04:54 AM
- Category
- Not specified
- Location
- Kabul
Description
Job Summary Key Responsibilities: · Perform application security assessments, vulnerability testing, and code security reviews. · Identify, analyze, prioritize, and support remediation of security vulnerabilities in web, mobile, API, and backend applications. · Integrate security controls and best practices throughout the Software Development Life Cycle (SDLC). · Review application architecture, APIs, authentication, authorization, session management, and data protection mechanisms. · Work closely with software development, DevOps, QA, infrastructure, and cybersecurity teams to implement secure development practices. · Provide secure coding guidance and support developers in resolving identified security issues. · Monitor emerging application security threats, vulnerabilities, and attack techniques. · Support security testing before application releases and major system changes. · Maintain application security documentation, vulnerability reports, risk assessments, and remediation tracking. · Support incident investigation and root-cause analysis for application-related security events. · Ensure applications follow recognized security standards and best practices, including OWASP guidelines and secure coding principles. Job Requirements Required Qualifications: · Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, or a related field. A Master’s degree is preferred. · Strong understanding of application security principles, secure coding practices, and common software vulnerabilities. · Knowledge of OWASP Top 10, API security, authentication, authorization, session management, and data protection. · Hands-on experience with SAST, DAST, vulnerability scanning, and application security testing tools. · Familiarity with programming or scripting languages such as Python, kotlin, Java, JavaScript, C#, PHP, or similar technologies. · Experience assessing the security of web applications, mobile applications, APIs, and backend services. · Understanding of secure SDLC, threat modeling, code review, and vulnerability management. · Knowledge of networking, operating systems, databases, encryption, and security protocols. · Familiarity with Git, CI/CD pipelines, DevSecOps practices, and containerized environments. · Ability to analyze security findings, determine risk, and provide practical remediation recommendations. · Strong analytical, problem-solving, documentation, and communication skills. · Ability to collaborate effectively with development, DevOps, QA, infrastructure, and cybersecurity teams. Preferred Qualifications: · Hands-on experience in web and API application security testing. · Practical knowledge of OWASP Top 10 and common application vulnerabilities. · Experience with manual penetration testing and vulnerability assessment. · Practical experience with tools such as Burp Suite, OWASP ZAP, Nmap, or similar tools. · Basic experience with secure code review and secure coding practices. · Knowledge of authentication, authorization, session management, input validation, and data protection. · Familiarity with Android and iOS application security is an advantage. · Experience working with developers to identify and remediate application security issues. · Relevant cybersecurity training or certification such as CEH, Security+, eJPT, or equivalent is an advantage. Plus, Points: · Experience with Android and iOS application security testing. · Familiarity with API security testing and common API vulnerabilities. · Basic knowledge of secure code review in languages such as Java, Kotlin, JavaScript, PHP, or Python. · Hands-on experience with Burp Suite and/or OWASP ZAP; familiarity with MobSF or similar mobile application security tools is an advantage. · Familiarity with Git, CI/CD, and DevSecOps practices. · Experience participating in CTFs, bug bounty programs, or practical security labs. · Knowledge of application authentication, authorization, encryption, and secure data storage. · Experience working directly with developers to verify and remediate security findings. · Relevant application-security training or certification is an advantage. Experience Requirement: · 5+ years of relevant experience in application security, penetration testing, or secure software development. · Hands-on experience in web and API security testing. · Practical experience identifying, assessing, and supporting remediation of application vulnerabilities. · Experience using tools such as Burp Suite, OWASP ZAP, or similar application security tools. · Experience with OWASP Top 10, secure coding practices, and vulnerability assessment. · Experience working with developers to verify, prioritize, and remediate security findings. · Experience with mobile application security testing for Android or iOS is an advantage. · Familiarity with secure SDLC, code review, and application security testing before release is preferred. What We Offer: · Competitive salary based on qualifications and experience. · Hands-on work with real-world application security projects. · Opportunities to strengthen skills in web, API, and mobile application security. · Access to practical security testing tools and secure development environments. · Collaboration with software development, DevOps, QA, and cybersecurity teams. · Opportunities for technical training, professional development, and career growth. · Opportunity to contribute to secure, locally developed, and self-hosted applications.
Additional details
- Procurement method
- Not specified
- Contract type
- Not specified
- Job type
- Not specified
- Salary or budget
- Not specified
- Experience level
- Not specified
- Language
- en