Senior Software Security Consultant- Afternoon - Contractual
Lahore, Karachi, Islamabad, Pakistan
Contracted
Experienced
Company Overview
10Pearls is an award-winning end-to-end digital innovation company that helps businesses imagine and build the future. We are proud to announce that 10Pearls was named as winner of the Best Tech Work Culture Timmy Award in Washington DC by Tech in Motion, recognized on the Inc. 5000 Fastest-Growing Companies List, and was ranked the #1 Most Diverse Midsize Company in Greater Washington. We partner with businesses to help them transform, scale, and accelerate by adopting digital and exponential technologies. Our work has ranged from creating highly usable, secure digital experiences, mobile and software products, to helping businesses modernize through cloud adoption and development and the digitalization of their business processes. Our clientele is highly diverse, including Global 1000 enterprises, mid-market businesses, and high-growth start-ups. But those are just the facts. What makes us unique is that we have true heart and soul. We have a strong focus on a double bottom line and actively support and engage with the communities where we live and work to make the world a better place. In a nutshell, we believe in doing well, while doing good, and know how to balance the two.
Role Overview
We are hiring for Senior Software Security Engineer at 10Pearls, the person will bring a strong background in software development, security and operations. This role supports the Digital Product Management team in embedding security requirements and best practices into new Digital Products and Services under the guidance of the Lead Software Security Engineer. They will work closely with Digital Product Management and IT Security to ensure the right security controls across the product lifecycle, using the established tooling and process to manage these controls.
Responsibilities
- Collaborate with software development teams to integrate security into the SDLC, ensuring products are built securely.
- Champion a DevSecOps mindset across squads assign to work closely with the various roles within these squads to ensure a security-first approach is taken while minimising impact to the end users experience.
- Implement and manage security controls, tools and processes to secure applications and infrastructure.
- Monitor and respond to security incidents and threats in a timely manner.
- Work with the Lead Security Engineer to continually automate and shit left security testing and deployment processes to enable rapid, secure software delivery.
- Update and maintain concise security documentation and training materials for engineering teams.
- Work with the lead Security Engineer to ensure the selected application security tools are in grated within existing development processes and CI/CD pipelines.
- Assist with the planning and execution of application penetration tests; track and support remediation.
- Act as a subject‑matter expert to squads on application security patterns and reviews.
- Define pragmatic security non‑functional requirements (NFRs) with product teams and verify they’re met.
- Contribute to reporting on compliance with security standards and control effectiveness.
- CI/CD and monitoring requirements as described in the Digital Product Management Target Operating Model.
Requirements
- Strong 5+ years of experience in software development and application security, including secure design review and code‑level mitigation.
- Proficiency in scripting and configuration languages such as PowerShell, YAML and JSON.
- Hands‑on experience with vulnerability management and remediation, including responses to pen test findings and security assessments.
- Experience conducting risk assessments and threat modelling for software systems; ability to advise engineering teams.
- Solid understanding of Agile and DevSecOps practices.
- Knowledge of security standards and secure development principles (e.g., NCSC Secure Development & Deployment Guidance, OWASP, NIST SSDF 800‑218, Microsoft Azure secure development best practices, ISO 27001).
- Experience with Azure cloud infrastructure, particularly Azure PaaS services; familiarity with Azure DevOps for CI/CD and backlog management.
- Strong analytical and problem‑solving skills, with excellent communication and interpersonal abilities.
Experience working with Security Operations Center (SOC) tools, including SIEM, Splunk, Wazuh, and Wiz. - Hands-on experience with SAST, DAST, and SCA tools.
- Strong understanding of and experience identifying vulnerabilities related to the OWASP Top 10 and CWE Top 25.
- Experience performing API security testing, including REST and SOAP APIs.
- Familiarity with penetration testing tools such as Burp Suite, Qualys, Metasploit, Nmap, Maltego, Sonarqube, wireshark, invicti etc.
Apply for this position
Required*