Skip to main content
Back to jobs

Application Security Engineer (IGT1)

External
Ifs1 logoIfs1 · Colombo, Western Province, Lk
Full-timeOn-site1d ago
Application SecurityOWASPPenetration TestingSIEMSparkSQL
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


Benefits

Remote work options

Additional Information

Web Application Firewall (WAF) Monitoring & Management Monitor and analyze WAF logs, alerts, and security events to identify malicious activity and potential attacks. Investigate application-layer threats including SQL injection, cross-site scripting (XSS), remote code execution (RCE), credential stuffing, bot activity, API abuse, and other web-based attacks. Fine-tune WAF rules, signatures, and policies to improve threat detection while minimizing false positives. Review and optimize WAF configurations to align with business and security requirements. Collaborate with SOC teams to triage and escalate security incidents involving web applications. Application Security Testing Conduct web application and API penetration testing using manual and automated techniques. Perform vulnerability assessments and security reviews throughout the software development lifecycle. Validate reported vulnerabilities and assess their potential impact and exploitability. Provide detailed findings, risk assessments, and remediation recommendations to development teams. Conduct retesting activities to verify successful remediation of identified vulnerabilities. Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related technical field (or equivalent experience). 3+ years of experience in Application Security, Penetration Testing, Security Operations, or a related cybersecurity role. Hands-on experience managing and monitoring Web Application Firewalls (WAFs). Strong understanding of the OWASP Top 10 and common web application attack vectors. Experience conducting web application and API penetration testing. Proficiency with security testing tools such as Burp Suite, OWASP ZAP, Nmap, Nikto, SQLMap, and similar technologies. Experience analyzing security logs and alerts from SIEM and monitoring platforms. We champion flexibility and hybrid work options to support varying lifestyles and personal needs. At the same time, we value the power of in-person collaboration to build community, spark innovation, and strengthen connections. Our approach ensures you can work in ways that suit you best while still engaging with colleagues to share ideas and grow together. #LI-Hybrid #LI-DNP


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at Ifs1? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect