Senior Cyber Security Engineer
Newroz Technologies Limited · Dhaka, Bangladesh
Apply & track with Apply EdgeNewroz Technologies Limited is seeking an experienced, hands-on Senior Cyber Security Engineer to strengthen the security of its applications, APIs, cloud infrastructure, production systems, and fintech/payment platforms.The ideal candidate will have strong expertise in application security, cloud security, vulnerability assessment, penetration testing, incident response, and DevSecOps, with the ability to identify risks and collaborate with engineering teams to implement effective security solutions.Key ResponsibilitiesConduct security assessments of web and mobile applications, APIs, and backend services.Identify and validate vulnerabilities using OWASP Top 10 and OWASP API Security Top 10 standards.Perform Vulnerability Assessment and Penetration Testing (VAPT) and secure code reviews.Assess AWS cloud environments, IAM, network configurations, encryption, and access controls.Implement security hardening across cloud and on-premise infrastructure.Integrate SAST, DAST, SCA, and secret-scanning tools into CI/CD pipelines.Investigate security alerts, respond to incidents, and conduct root-cause analysis.Collaborate with Engineering, DevOps, SRE, QA, and Product teams to resolve security issues.Maintain vulnerability registers and monitor remediation progress.Support security requirements for fintech platforms, digital wallets, payment gateways, and financial APIs.Contribute to PCI DSS, ISO 27001, SOC 2, and other relevant security compliance requirements.Educational & Experience Requirements5–8 years of professional cybersecurity experience.At least 3 years of hands-on experience in Security Engineering or Application Security.Strong knowledge of application security, API security, network security, AWS cloud security, and incident response.Practical experience with authentication, authorization, OAuth2, JWT, MFA, SSO, and secrets management.Experience with security tools such as Burp Suite, OWASP ZAP, Nmap, Nessus/OpenVAS, and SAST/DAST/SCA solutions.Working knowledge of Linux, Windows security, SIEM platforms, and scripting with Python, Bash, or PowerShell.Understanding of DevSecOps, Secure SDLC, threat modelling, and security architecture reviews.Strong written and verbal English communication skills.Preferred QualificationsExperience in one or more of the following areas will be an advantage:Fintech, banking, payment gateways, or digital wallets.Financial APIs and merchant/payment systems.PCI DSS and AWS production environments.Production incident response and cloud security operations.Preferred Certifications: CISSP, CISM, OSCP, CEH, Security+, CySA+, PenTest+, eJPT, eWPT, AWS Certified Security – Specialty, ISO 27001, or GIAC certifications.What We ExpectThe successful candidate should be able to independently assess security risks, prioritize vulnerabilities, investigate complex incidents, recommend practical remediation, and work with engineering teams to ensure security issues are resolved effectively.