Application Security Engineer/Penetration Tester
Job Description
As part of the Security team, you will work closely with product and engineering teams to ensure the security of web and desktop applications.You will take ownership of security assessments, contribute to secure development practices, and help drive security maturity across the organization.
Role and ResponsibilitiesPerform penetration testing and security assessments of:Web applications and APIsDesktop (thick client) applicationsIdentify vulnerabilities and clearly communicate risks and impact.Produce high-quality security reports with:clear reproduction stepsrealistic impact assessmentpractical remediation guidanceWork closely with developers and product teams to:explain vulnerabilitiessupport remediationvalidate fixesImprove internal security processes, tools, and methodologies.Participate in secure coding trainings and knowledge sharing.
Required Technical and Professional Expertise3+ years of hands-on experience in application security/penetration testing.Strong practical experience in:Web application security testing (OWASP WSTG, ASWS or equivalent)API security (auth flows, business logic, abuse cases)Understanding of desktop application security basics, including:Local storage / ACLs / secrets handlingReverse engineering basics (static/dynamic analysis)Common issues (hardcoded secrets, insecure IPC, weak crypto usage)Solid understanding of:Common vulnerability classes and their root causesClient-server interaction modelsNetwork communication protocolsModern web technologiesAuthentication mechanismsSecure Software Development LifecycleFoundational Knowledge of AI SecurityUnderstanding of the OWASP Top 10 for LLM Applications (e.g., Prompt Injection, Sensitive Data Disclosure, Insecure Output Handling)Proficiency in using LLMs and AI-powered tools to accelerate vulnerability analysis, deobfuscate code, and automate the creation of custom security tools or exploit scriptsPrompt Engineering: Ability to craft and refine complex prompts for deep-dive code analysis (SAST) and generating context-aware test cases for business logic flawsHands-on experience with tools such as:Burp Suite (advanced usage)Proxies, fuzzers, scannersSAST / DAST toolsSysinternals Suite (ProcMon, SigCheck, etc.)Basic RE tools (Ghidra, jadx, dnSpy — at least on a basic level)AI Productivity Tools: AI-assisted coding environments (e.g., GitHub Copilot, Cursor, or Claude Code) to streamline security auditing and remediation workflowsStrong communication skills:Ability to explain security issues to engineersClear and structured reporting in EnglishAbility to work independently and take ownership.Nice to Have:Experience in bug bounty, public vulnerability disclosures or CTF competitions.Development background (ability to read and understand production code).Experience with Cloud environments, CI/CD and DevSecOps practices.Experience in Threat modeling and Architecture reviewsFamiliarity with privacy and compliance frameworks (GDPR, ISO 27001, SOC2, etc.)Relevant certifications like CEH, BSCP, eWPT, OSCP, etc.
Requirements & Qualifications
Required Technical and Professional Expertise3+ years of hands-on experience in application security/penetration testing.Strong practical experience in:Web application security testing (OWASP WSTG, ASWS or equivalent)API security (auth flows, business logic, abuse cases)Understanding of desktop application security basics, including:Local storage / ACLs / secrets handlingReverse engineering basics (static/dynamic analysis)Common issues (hardcoded secrets, insecure IPC, weak crypto usage)Solid understanding of:Common vulnerability classes and their root causesClient-server interaction modelsNetwork communication protocolsModern web technologiesAuthentication mechanismsSecure Software Development LifecycleFoundational Knowledge of AI SecurityUnderstanding of the OWASP Top 10 for LLM Applications (e.g., Prompt Injection, Sensitive Data Disclosure, Insecure Output Handling)Proficiency in using LLMs and AI-powered tools to accelerate vulnerability analysis, deobfuscate code, and automate the creation of custom security tools or exploit scriptsPrompt Engineering: Ability to craft and refine complex prompts for deep-dive code analysis (SAST) and generating context-aware test cases for business logic flawsHands-on experience with tools such as:Burp Suite (advanced usage)Proxies, fuzzers, scannersSAST / DAST toolsSysinternals Suite (ProcMon, SigCheck, etc.)Basic RE tools (Ghidra, jadx, dnSpy — at least on a basic level)AI Productivity Tools: AI-assisted coding environments (e.g., GitHub Copilot, Cursor, or Claude Code) to streamline security auditing and remediation workflowsStrong communication skills:Ability to explain security issues to engineersClear and structured reporting in EnglishAbility to work independently and take ownership.Nice to Have:Experience in bug bounty, public vulnerability disclosures or CTF competitions.Development background (ability to read and understand production code).Experience with Cloud environments, CI/CD and DevSecOps practices.Experience in Threat modeling and Architecture reviewsFamiliarity with privacy and compliance frameworks (GDPR, ISO 27001, SOC2, etc.)Relevant certifications like CEH, BSCP, eWPT, OSCP, etc.
Quick Role Summary
Opportunity as "Application Security Engineer/Penetration Tester" at Vertex Technologies located in القاهرة on a Full-Time basis, suited for Senior Level candidates, within Technology & IT. Key details from listing: As part of the Security team, you will work closely with product and engineering teams to ensure the security of web and desktop applications.You will take…
The Egyptian Job Bank editorial team prepares curated overviews and actionable application guidance for every listing, preserving official employer details.
Application Tips
- Tailor your CV headline to match "Application Security Engineer/Penetration Tester" and feature measurable achievements in the top third of your resume.
- Customize your cover note for القاهرة: explain why this location and work arrangement suit your availability and how you add value to the team.
- Highlight relevant practical experience, key responsibilities, and specific business impact.
- Demonstrate team leadership, budget stewardship, and tangible business KPIs — concrete numbers carry maximum weight.
- After applying, monitor your status from your dashboard and stay prepared for an interview invitation.
Readiness Checklist
- Updated CV in standard PDF format with a professional filename
- Skills aligned with the stated role requirements
- Availability for work in القاهرة or remote if specified
- Measurable achievement examples prepared for interview talking points
- Egyptian Job Bank candidate profile ready for application tracking