Application Security Engineer (IGT1)

IFS1· Engineering
Apply Now ↗

About this role

Company Description

About IGT1:

IGT1 is a rapidly growing offshore technology and talent solutions company based in Port City Colombo. We are a fully owned subsidiary of IGT I Holdings Sweden AB, funded by the three of world’s leading private equity firms; EQT Group, Hg, and TA Associates and also a sister company of IFS.

At IGT1, we partner with global businesses to provide them with an operation that maximizes efficiency, spurs growth, allows them to develop and deliver world-class products and services, and creates long-term value. Our people-first culture champions diversity, teamwork, and continuous learning, creating an environment where talent thrives. 

With a team of over 500 professionals and counting, we are always looking for passionate, skilled individuals who want to make a global impact while being part of something extraordinary. 

Through our offshore collaboration model, you'll be embedded within the team of one of our esteemed international clients, contributing directly to high-impact, enterprise-level initiatives. 

About the Client: Kyriba

Kyriba is the global leader in cloud-based finance solutions, empowering CFOs and their teams to transform how they activate liquidity as a dynamic, real-time vehicle for growth and value creation. Our award-winning SaaS platform delivers comprehensive treasury, risk management, payments, and supply chain finance capabilities that enable companies to optimize their working capital and enhance financial performance.

The Role:
We are seeking an Application Security Engineer with a strong focus on Web Application Firewall (WAF) monitoring and web application penetration testing. This role is responsible for detecting, analyzing, and responding to application-layer threats by reviewing WAF logs, security alerts, and performing penetration testing. The engineer will work closely with SOC analysts, DevSecOps, and application teams to strengthen application-layer defenses, investigate suspicious activity, and continuously improve web security controls

Job Description

Web Application Firewall (WAF) Monitoring & Management

  • Monitor and analyze WAF logs, alerts, and security events to identify malicious activity and potential attacks.
  • Investigate application-layer threats including SQL injection, cross-site scripting (XSS), remote code execution (RCE), credential stuffing, bot activity, API abuse, and other web-based attacks.
  • Fine-tune WAF rules, signatures, and policies to improve threat detection while minimizing false positives.
  • Review and optimize WAF configurations to align with business and security requirements.
  • Collaborate with SOC teams to triage and escalate security incidents involving web applications.


Application Security Testing

  • Conduct web application and API penetration testing using manual and automated techniques.
  • Perform vulnerability assessments and security reviews throughout the software development lifecycle.
  • Validate reported vulnerabilities and assess their potential impact and exploitability.
  • Provide detailed findings, risk assessments, and remediation recommendations to development teams.
  • Conduct retesting activities to verify successful remediation of identified vulnerabilities.

Qualifications

  •  Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related technical field (or equivalent experience).
  • 3+ years of experience in Application Security, Penetration Testing, Security Operations, or a related cybersecurity role.
  • Hands-on experience managing and monitoring Web Application Firewalls (WAFs).
  • Strong understanding of the OWASP Top 10 and common web application attack vectors.
  • Experience conducting web application and API penetration testing.
  • Proficiency with security testing tools such as Burp Suite, OWASP ZAP, Nmap, Nikto, SQLMap, and similar technologies.
  • Experience analyzing security logs and alerts from SIEM and monitoring platforms.

Additional Information

We champion flexibility and hybrid work options to support varying lifestyles and personal needs. At the same time, we value the power of in-person collaboration to build community, spark innovation, and strengthen connections. Our approach ensures you can work in ways that suit you best while still engaging with colleagues to share ideas and grow together. #LI-Hybrid #LI-DNP 

    Frequently Asked Questions

    Is the salary disclosed for the Application Security Engineer (IGT1) position at IFS1?
    The salary for this Application Security Engineer (IGT1) role at IFS1 is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
    Where is the Application Security Engineer (IGT1) position at IFS1 located?
    This Application Security Engineer (IGT1) role at IFS1 is based in Colombo, Colombo, Western Province, Sri Lanka, Western Province, lk. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
    Is the Application Security Engineer (IGT1) role at IFS1 full-time or part-time?
    This is listed as a Full time position. It is posted as a Application Security Engineer (IGT1) role in the Engineering department at IFS1.
    Which team or department does the Application Security Engineer (IGT1) at IFS1 belong to?
    This Application Security Engineer (IGT1) position is part of the Engineering department at IFS1. See the full job description for more information about the team structure and responsibilities.
    How do I apply for the Application Security Engineer (IGT1) position at IFS1?
    Click the "Apply Now" button on this page. You will be redirected to IFS1's official application portal hosted on smartrecruiters where you can submit your application directly.
    When was the Application Security Engineer (IGT1) job at IFS1 posted?
    This Application Security Engineer (IGT1) position at IFS1 was posted on Jun 22, 2026. Apply as soon as possible — early applications are often reviewed first.
    Application Security Engineer (IGT1)
    IFS1
    Apply for this role ↗

    You'll be redirected to IFS1's official application page on SmartRecruiters.