- Location
- Cairo
- Workplace
- Remote, Hybrid, Onsite
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 5+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- CareersPage
Description
We are seeking an experienced Senior Application Security Engineer to ensure application security across Platforms and Agile Release Trains (ARTs).
The role combines hands-on application security, secure software development, cloud security, and technical leadership. You will work closely with Cybersecurity, Product, Platform, Infrastructure, and Engineering teams to embed secure-by-design practices throughout the SDLC.
Budget & Benefits
Compensation:
- Annual gross salary: 1,370,000 EGP
- Annual bonus: 15%
- 13th and 14th salary: included
- Transportation allowance: 120,000 EGP gross/year, paid monthly
Benefits:
- Family medical insurance
- Life insurance
Location & Working Model:
- Location: Cairo, Egypt
- Candidates must be Cairo-based
- Hybrid: 4 days onsite + 1 day remote per week
Key Responsibilities
- Drive and support the application security strategy across multiple teams and platforms.
- Lead security initiatives throughout the Software Development Lifecycle (SDLC).
- Conduct security requirements analysis and threat modeling during early design phases.
- Lead security architecture, design, and code reviews.
- Perform hands-on application security testing, identify vulnerabilities, assess their risk, and drive remediation.
- Integrate and improve automated security controls within CI/CD pipelines.
- Drive software supply chain security to protect code, builds, dependencies, and artifacts from tampering.
- Partner with Product Management, Platform Engineering, Development, Infrastructure, and Cyber Defense teams.
- Provide pragmatic, risk-based security recommendations that balance security and business needs.
- Turn lessons learned into reusable security standards, practices, and organizational assets.
- Mentor engineers and promote secure-by-default development practices.
- Coordinate cross-functional security initiatives and drive measurable improvements.
Key Requirements
Experience & Education
- 5+ years of experience in Information/Cyber Security.
- 2+ years of software development experience.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
- Strong experience working in enterprise application security environments.
Application Security
- Strong knowledge of application security and secure software development practices.
-
Proven experience conducting:
- Security architecture and design reviews
- Secure code reviews
- Threat modeling
- Application security testing
- Vulnerability assessment and remediation
-
Strong knowledge of:
- OWASP Top 10
- OWASP SAMM / DSOMM
- OWASP ASVS / MASVS
- Hands-on experience with Burp Suite, OWASP ZAP, or similar application security testing tools.
- Ability to identify, validate, prioritize, and communicate exploitable security risks.
DevSecOps / CI/CD
Hands-on experience integrating security tooling into CI/CD pipelines, including:
- SAST
- DAST
- SCA
- Secrets Scanning
- Container Image Scanning
Strong understanding of software supply chain security, including protection against code, build, dependency, and artifact tampering.
Development Skills
- 2+ years of hands-on software development experience.
- Ability to understand and review application code.
-
Experience with multiple programming languages, preferably:
- .NET / C#
- JavaScript
- Python
Cloud & Infrastructure Security
- Deep understanding of enterprise, cloud, and cloud-native architectures.
-
Hands-on experience with:
- Microsoft Azure
- Kubernetes
- Containers
- Cloud identity and access management
- Secure cloud configuration
- Understanding of secure architecture principles and cloud security controls.
Network & Web Security
Strong knowledge of:
- TCP/IP
- TLS / HTTPS
- OAuth 2.0
- OpenID Connect
- Web application architecture
- Common web and network attack vectors
Certifications
At least one Cybersecurity certification, for example:
- ISC2 CISSP
- EC-Council CEH
- ISACA CSX
- Microsoft Azure Security certification
- AWS Certified Security – Specialty
Application Security certification is also expected/preferred, for example:
- EC-Council CASE
- ISC2 CSSLP
- OffSec OWSA
- GIAC CWAD
Leadership & Soft Skills
- Strong technical leadership and ability to act as an Application Security SME.
- Ability to influence architecture, design, and engineering decisions.
- Strong project management and prioritization skills.
- Excellent stakeholder management and communication skills.
- Ability to collaborate across Product, Engineering, Infrastructure, and Cybersecurity teams.
- Proactive approach and ability to independently identify and lead security initiatives.
- Strong problem-solving and risk-based decision-making skills.
- Ability to mentor engineers and promote security ownership across development teams.
- Strong written and spoken English.
Ideal Candidate Profile
The strongest candidate is not purely a Cybersecurity/Infrastructure Security specialist. We are looking for someone with a strong Application Security + Software Development + DevSecOps combination.
They should be able to work directly with developers, understand and review code, conduct threat modeling and hands-on application testing, and integrate security tooling into CI/CD pipelines. Experience with Azure, Kubernetes, containers, OWASP practices, Burp Suite/ZAP, and SAST/DAST/SCA is particularly important.
About Coca-Cola HBC
Coca-Cola Hellenic is a growth-focused consumer goods business and strategic bottling partner of The Coca-Cola Company, operating across 29 markets in Europe, Africa, and Eurasia.
The organization brings together more than 30,000 people from over 70 nationalities and promotes an inclusive working environment with equal opportunities and a strong focus on employee development, collaboration, and diversity.