Engineering

Senior Application Security Engineer At Conclase Consulting

Conclase Consulting·Lagos, nigeria·Full Time·Onsite
EngineeringFull TimeOnsite

Role Description

  • The Senior Application Security Engineer will be responsible for designing, implementing, and maintaining robust application security controls across Conclase's products and client solutions. This full-time, on-site role based in Lagos will work closely with engineering, DevOps, and product teams to embed secure-by-design principles throughout the software development lifecycle (SDLC). Daily responsibilities include performing threat modeling, secure code reviews, security testing
  • and application vulnerability assessments, as well as coordinating remediation efforts with development teams. The person in this role will define and maintain application security standards, guidelines, and best practices, and help automate security testing within CI/CD pipelines. Additional tasks include investigating security incidents, mentoring engineers on secure coding practices, collaborating with stakeholders to meet compliance requirements, and contributing to security architecture decisions for new and existing systems.

Qualifications

  • Strong experience with application security fundamentals, including secure software design, threat modeling, and common vulnerabilities (e.g., OWASP Top 10).
  • Proficiency in secure coding practices in one or more languages used in modern web or mobile applications (such as Java, C#, JavaScript/TypeScript, Python, or similar).
  • Hands-on experience with application security testing tools, such as SAST, DAST, SCA, and interactive application security testing, and the ability to interpret and prioritize their findings.
  • Experience embedding security into CI/CD pipelines and collaborating closely with DevOps and engineering teams on automation and continuous security testing.
  • Knowledge of security testing and code review is a must.
  • Ability to test fixes that have been done on applications and provide status update.
  • Banking or fintech experience is a must.
  • minimum of 5 years experience.
  • Familiarity with cloud security concepts and platforms (such as AWS, Azure, or GCP), including identity and access management, secrets management, and secure configuration.
  • Knowledge of relevant security frameworks and standards (for example, OWASP SAMM, NIST, ISO 27001, or PCI DSS) and how they apply to application security programs.
  • Demonstrated ability to lead security initiatives, influence technical decisions, and mentor other engineers and stakeholders on security best practices.
  • Strong analytical and problem-solving skills, with the ability to communicate complex security topics clearly to both technical and non-technical

Key skills

BA/BSc/HND
Apply Now
Send your CV along with a cover letter to[email protected]

Please use the job title as the subject line of your email.

At a glance

Company

Conclase Consulting

Location

Lagos, nigeria

Employment

Full Time

Work style

Onsite

Experience

Valid until

Not specified

Created

June 24, 2026

More opportunities

Similar roles you might like

Senior Application Security Engineer At Software Business Solutions Consulting

Software Business Solutions Consulting

Lagos, nigeria

full-time

Role Description The Senior Application Security Engineer is a contract, on-site role based in Ikeja, responsible for securing applications and related infrastructure throughout the software development lifecycle. This role involves performing threat modeling, secure design reviews, and code reviews to identify and remediate vulnerabilities in web, mobile, and backend systems. The engineer will collaborate closely with development, DevOps, and product teams to integrate security best practices, define secure coding standards, and support automated security testing in CI/CD pipelines. Daily activities include analyzing security incidents, conducting penetration testing and risk assessments, recommending technical and process improvements, and documenting security requirements and guidelines. The role also includes mentoring team members on security practices, staying current on emerging threats and technologies, and contributing to the overall security posture of client solutions. Qualifications Strong expertise in application security, including threat modeling, secure architecture design, code review, and vulnerability assessment. Experience with common security tools and technologies (e.g., SAST/DAST tools, dependency scanning, penetration testing frameworks, and security monitoring solutions). Solid understanding of secure software development practices, including SDLC integration, CI/CD pipeline security, and DevSecOps principles. Knowledge of industry security standards and frameworks such as OWASP Top 10, NIST, ISO 27001, and relevant compliance requirements. Proficiency in at least one major programming language (such as Java, C#, JavaScript, Python, or similar) and familiarity with modern web and mobile application frameworks. Experience collaborating with cross-functional teams, providing security guidance to developers, and communicating technical risks to non-technical stakeholders. Strong analytical and problem-solving skills, with the ability to prioritize risks and recommend practical mitigation strategies. Bachelor's degree in Computer Science, Information Security, Engineering, or a related field; relevant certifications (e.g., CISSP, CSSLP, OSCP, CEH) are an advantage. Prior experience in a senior or lead application security role, preferably within consulting or multi-industry environments.

5 days ago

Senior Application Security Engineer At Moniepoint Inc.

Moniepoint Inc.

All, nigeria

full-time

About the Role As a Senior Application Security Engineer, you will champion secure innovation by embedding security into the fabric of our software development lifecycle. You'll partner closely with engineering teams to safeguard customer trust while they build cutting-edge services. Your expertise will directly shape secure design through threat modeling and code review, drive efficiency via security automation, and mentor developers to elevate our collective security posture. The ideal candidate is a technical leader who blends deep security expertise with exceptional influence. You possess broad security knowledge anchored by specialization in critical areas, and excel at translating complex risks into actionable insights for both engineers and executives. Your strength lies in harmonizing diverse perspectives, strategically prioritizing risks, and guiding partners to implement resilient, secure solutions that balance speed and safety. Key Responsibilities Security Strategy & Leadership: Define and execute security strategy for product teams, aligning with business objectives. Lead threat modeling, security architecture reviews, and design guidance for diverse software projects. Mentor engineers technically and professionally, fostering a culture of security excellence. Advanced Technical Execution: Conduct adversarial security analysis using automated tools and manual techniques (e.g., custom exploit development). Perform manual/automated secure code reviews across Java, Python, JavaScript, and cloud-native stacks. Develop security automation tools to scale vulnerability detection (SAST/DAST/IAST enhancements). Risk Mitigation & Innovation: Identify complex risks through offensive security research; advocate for cutting-edge mitigation technologies. Solve novel security problems lacking predefined solutions (e.g., zero-day vulnerabilities, emergent attack vectors). Maintain and evolve threat models for critical applications and microservices architectures. Collaboration & Enablement: Partner with the engineering team to embed security controls into CI/CD pipelines and development practices. Design/deliver security training programs tailored to development teams and business stakeholders. Lead incident response for application security events and drive root-cause analysis. Qualifications Required 5+ years in application security, including 2+ years in a senior/lead role. Expertise in threat modeling (e.g., STRIDE, PASTA), penetration testing, and secure SDLC implementation.Proficiency in code review for Java/Python/JavaScript and cloud platforms (AWS/Azure/GCP). Hands-on experience building security tools (e.g., scanners, CI plugins) with Python/Go. Proven track record in security architecture design and risk-based decision-making. Preferred: OSCP, OSCE, GXPN, or similar offensive security certifications. Contributions to security tooling/open-source projects. Experience with container security (Kubernetes, Docker), serverless, or infrastructure-as-code. Skills: Leadership: Ability to define team strategy, mentor engineers, and influence stakeholders. Innovation: Aptitude for researching/implementing novel solutions to ambiguous security challenges. Technical Depth: Mastery of application security frameworks (OWASP, NIST) and exploit techniques. Communication: Translate technical risks to business impact for executives and engineers alike. Execution: Drive implementation of security controls.

2 months ago

Senior Application Security Engineer At Conclase Consulting
Lagos, nigeria
Apply