Treehouse Jobs
Mid-levelOn-site

APPLICATION SECURITY

TATUM BANK

Posted 9 days ago

Type
Mid-level · On-site
Location
Lagos
Posted
14 September 2026
Deadline
No fixed deadline

About the role

The Application Security Officer will be responsible for identifying, assessing, and mitigating security vulnerabilities across the bank's applications, APIs, and digital platforms. The role will collaborate with Development, Technology, and Information Security teams to embed security throughout the software development lifecycle.

KEY RESPONSIBILITIES

• Conduct VAPT, SAST, and DAST on web, mobile, and API applications

• Perform manual and automated application security testing and validate identified vulnerabilities

• Conduct secure code reviews and provide practical remediation guidance to developers.

• Identify, assess, document, and track application vulnerabilities through to remediation.

• Perform API security testing, including authentication, authorization, and access-control assessments.

• Support the integration of security controls into the SDLC, CI/CD, and DevSecOps processes.

• Participate in application architecture and security reviews for new applications and major changes.

• Support cybersecurity audits, regulatory assessments, and application security compliance requirements.

Requirements

  • Required Skills & Experience
  • • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or a related discipline.
  • • 3-5 years of relevant experience in application security, Penetration Testing, Vulnerability Management or Cybersecurity.
  • • Strong hands-on experience with VAPT, SAST, DAST and secure code review.
  • • Good knowledge of OWASP Top 10 and
  • OWASP API Security Top 10.
  • • Experience testing web applications, mobile applications and APls.
  • • Knowledge of common application vulnerabilities, including SQL Injection, XSS, SSRF, CSRF and
  • authentication/ authorization flaws.
  • • Experience with tools such as Burp Suite, OWASP ZAP, SonarQube, Checkmarx, Fortify, Nessus/Qualys or equivalent.
  • • Good understanding of Secure SDLC and DevSecOps principles.
  • Preferred Certifications
  • • Certified Ethical Hacker (CEH)
  • • Offensive Security Certified Professional (OSCP)
  • • Burp Suite Certified Practitioner (BSCP)
  • • Certified Application Security Engineer
  • (CASE)
  • • GIAC Web Application Penetration Tester (GWAPT)
  • • Other relevant application security or penetration testing certifications.

How to apply

Do not skip this: Click on the link above to review the qualification requirements and submit your application.

Applications go directly to TATUM BANK. Treehouse Job does not collect your details and never charges for a listing.

Other jobs you should see

Apply now