×

Security Engineer – Integration (Application, API & Database)

JOB Description

Ensure the security and integrity of the Bank's application, API, and database environments during integration and managing security measures across all stages of SDLC to protect sensitive data and prevent unauthorized access. Close collaboration with development, operations, and compliance teams to deliver secure and efficient solutions aligned with organizational and regulatory standards.

Experience & Skills

  • 2-3 years of hands-on experience in application, API, and database security.
  • Proven track record of conducting security reviews and implementing security measures for API integrations.
  • Experience with securing enterprise-level applications and databases in a banking or financial institution is a strong advantage.

Knowledge and Skills

  • Strong knowledge of API gateways, WAFs, and related security tools.
  • Strong knowledge of application security principles, including secure coding practices, vulnerability management, and application architecture.
  • Experience with API security standards and protocols such as OAuth, OpenID Connect, JWT, and RESTful API security.
  • In-depth understanding of database security concepts, including encryption, access control, and data masking.
  • Familiarity with CI/CD pipelines and integrating security into DevOps practices (DevSecOps).
  • In-depth understanding of OWASP API Security Top 10 and OWASP Top 10 application vulnerabilities.

Responsibilities

  • Design and implement security architectures for applications, APIs, and databases.
  • Conduct comprehensive API security reviews to identify vulnerabilities and provide remediation steps.
  • Perform security assessments and threat modeling of the integration between APIs, applications, and databases to ensure seamless and secure interoperability.
  • Collaborate with development and infrastructure teams to embed secure coding practices across the software development lifecycle (SDLC).
  • Ensure API security controls, including authentication, authorization, and encryption mechanisms.
  • Analyze potential risks associated with data flows between applications and databases.
  • Ensure that application, API, and database security practices comply with relevant regulations, standards, and frameworks (e.g., PCI DSS, ISO 27001, NESA, SWIFT, NIST).
  • Stay updated on the latest security trends, vulnerabilities, and regulatory requirements impacting application, API, and database security. Recommend and implement improvements to existing security processes and tools.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Security (IS), Information Technology (IT), Computer Science, or a related field.
  • Master’s degree in Cybersecurity or a related discipline is preferred.

Certifications

  • Certified Ethical Hacker (CEH)
  • CompTIA Security+
  • Certified API Security professional
  • Certified Secure Software Lifecycle Professional (CSSLP)
  • GIAC Database Security (GDBA)
  • Oracle Certified Professional (OCP): Database Security

Job Location

  • Lahore

Important Note

“Females and Persons with disabilities having required skill set are encouraged to apply . MCB bank Ltd is an equal opportunity employer and is committed to create an inclusive environment for all employees.”

To apply for this position please share your resume at [email protected] Do not forget to mention the title of the position in the subject of your email.

Navigate Seamlessly Using
These Quick Shortcuts

Easily access quick links to important web pages from here.