// job listing

Application Security Engineer

Talent Safari
Nairobi
Full-time
Posted: 2026-09-02

About Talent Safari

We connect innovative companies and rising professionals through our trusted, quality-first hiring.

Description

We are looking for an highly skilled and qualified Application Security Engineer to join Talent Safari in Nairobi.

Qualifications

Job Responsibilities

As an Application Security Engineer/Analyst, you will be a key contributor to our security posture, working closely with engineering and product teams.

Your responsibilities will include:

Application Security Testing: Conduct web and mobile application security assessments and API security testing. Perform threat modelling, secure code reviews, and attack surface analysis. Support SAST and DAST initiatives.

Vulnerability Management: Assist in managing the vulnerability lifecycle. Coordinate internal and external security assessments, ensuring proper scoping and timely delivery. Track and report on remediation progress.

Secure Development Lifecycle (SDLC) Integration: Ensure secure coding practices are followed. Collaborate with developers, testers, and business analysts to provide proactive security guidance during development sprints. Contribute to security frameworks, checklists, and guidelines (aligned with OWASP, NIST, MITRE). Work on DevSecOps testing and protective controls.

Incident Response Support: Assist in the investigation and resolution of application security incidents. Contribute to post-incident analysis and implement preventative measures.

Continuous Improvement & Innovation: Stay informed about cybersecurity trends, emerging threats, and attack vectors. Research and contribute to the implementation of innovative security solutions. Identify process improvements to enhance the efficiency and effectiveness of security assessments.

Who You Are

A few things we expect you should have to be able to meet the demands of the role include:

Minimum 3 years in application security, IT security, or software development with a security focus

Hands-on experience with penetration testing, vulnerability assessments, and secure code reviews

Proven experience with SAST, DAST, and threat modelling frameworks

Practical knowledge of secure software development practices (OWASP Top 10, CWE)

Hands-on development experience or scripting ability (Python, JavaScript, Bash)

Strong understanding of web application security, API security, and cloud security concepts (AWS, Azure, or GCP)

Understanding of DevSecOps principles and CI/CD security integration

Excellent communication skills with the ability to explain complex security concepts to technical and non-technical audiences

Collaborative mindset with the ability to work cross-functionally

Benefits

Competitive compensation package and benefits

Stripe Equity compensation

Full medical coverage

Wellbeing stipend

Generous leave and sabbatical policies

Hybrid working environment

Smart, kind colleagues who’re invested in your growth.

Rate Talent Safari

Click a star to rate this company

0.0 (0 ratings)

Job Stats

20 Views