Moniepoint is a financial technology company digitising Africa’s real economy by building a financial ecosystem for businesses, providing them with all the payment, banking, credit and business management tools they need to succeed.
Read more about this company
We are seeking a passionate Application Security Engineer to drive security across our services and development pipelines.
In this role, you’ll champion security best practices, embed application security into the product lifecycles, and empower engineering teams to build and release safe products.
Key Responsibilities
Act as a Security Champion across product teams, influencing design and engineering decisions to prioritize security from the outset.
Design solutions that are Secure by Design, integrating threat modeling and security requirements into feature architecture and design reviews.
Promote and enforce Secure Coding standards through CI/CD automation, peer reviews, and development training to reduce vulnerabilities at the source.
Lead Vulnerability Management & Remediation, overseeing identification, risk-based triage, and tracking of remediation efforts for security issues.
Develop and maintain standard security packages (e.g., secure configuration baselines, code templates, CI/CD security integrations) for consistent use across engineering teams.
Conduct and support Penetration Testing, both hands-on and automated to uncover vulnerabilities throughout environments, platforms, and release cycles.
Enable continuous improvement through Collaboration & Enablement, delivering security knowledge transfer, best practices, and feedback loops across teams.
Requirements
5+ years of hands-on experience in application security (AppSec), DevSecOps, or similar roles.
Software engineer with a keen interest in Security.
At least 2 years of experience working in an engineering team a plus
Deep understanding of secure software development lifecycle (SDLC) and first-principles of secure-by-design engineering.
Skilled in security scanning tools (e.g., SAST, DAST, SCA), incident and remediation workflows, and security automation.
Proficiency in reading and writing code for Java/Python/JavaScript and cloud platforms (AWS/Azure/GCP)
Proven experience with pentesting or red-team engagements, identifying and exploiting application-level vulnerabilities.
Excellent communication skills, you're able to translate technical risks into actionable steps and help engineers incorporate security improvements.
Comfortable building trust as a security mentor and champion, raising security maturity across teams with patience and influence.
Contributions to security tooling/open-source projects.
OSCP, OSCE, GXPN, or similar offensive security certifications a plus
Staff Turnover and How to Calculate ItIn this article, we'll explain what staff turnover means, how to calculate it, why it matters, and what businesses can do to reduce it.
MyJobMag Career Kickstart Scholarship 2026: Training Report & HighlightsFollowing the resounding success of the pilot programme, the MyJobMag Career Kickstart Scholarship 2025, the second edition was launched in 2026 to expand impact and deepen outcomes. Here's everything you need to know about how the training went.
AI's Impact on Jobs and Organisations (Nigeria report)This report examines the extent to which AI is affecting jobs and organisations in Nigeria. It brings together perspectives from HR professionals and managers across different industries.
30 Contract Staffing Risks That Could Get Your Company SuedThis piece outlines 30 contract staffing risks that have real legal consequences under Nigerian law. If you are a business owner, HR professional, or staffing agency operator, you will find this highly valuable.