Specialist Application Security
2026-01-30T07:45:00+00:00
CRDB
https://cdn.greattanzaniajobs.com/jsjobsdata/data/employer/comp_2278/logo/CRDB%20Bank%20Plc.jpg
https://www.crdbbank.co.tz/
FULL_TIME
Tanzania Head Office
Dar es Salaam
00000
Tanzania
Finance
Computer & IT, Science & Engineering
2026-02-10T17:00:00+00:00
8
The Applications Security specialist is a key member of the Security Architecture team, reporting to the Enterprise Security Architect. This role is responsible for integrating security into Agile squads and the Software Development Lifecycle (SDLC), Designing Cyber security controls in CRDB Products and services and systems.
It is also responsible with providing assurance towards delivery of such controls by conducting security assessments and threat modelling and ensuring secure coding practices across all software development initiatives.
Furthermore, the specialist embeds secure SDLC practices inside product squads, own secure coding guidelines, orchestrate CI/CD security with SAST, DAST, SCA and act as the primary security SME supporting developers to deliver secure features at speed.
Responsibilities or duties
- Work closely with Agile development squads to embed security into all stages of the Software Development Lifecycle (SDLC) and support secure-by-design principles in systems and applications.
- Participate in application security testing, including threat modeling, vulnerability assessments, and penetration testing of web and mobile applications.
- Contribute to the adoption of secure coding practices and security best practices across the development teams.
- Conduct risk assessments and recommend security controls to mitigate identified risks.
- Participate in Development and maintenance of security standards, guidelines, and tools to support secure Agile development.
- Review source code for security vulnerabilities and offer actionable recommendations to improve application security.
- Work with Security Champions within squads to strengthen the security posture and promote a culture of security-first development.
- Assist in the development of secure DevOps pipelines and the implementation of security in CI/CD pipelines.
- Collaborate with Security Champions and Software Developers to conduct automated static (SAST) and dynamic (DAST) security testing across development and production environments in the CI/CD pipeline.
- Enforce security policies throughout the development process and deployment stages in the CI/CD pipeline.
- Participate in providing training and mentorship on secure development practices to developers and DevOps teams.
- Contribute to incident response and investigations involving application security issues.
- Assist in evaluating third-party applications and integrations for security risks.
Qualifications or requirements (e.g., education, skills)
- Bachelor’s degree in computer science, Cyber Security, Software engineering or related academic field.
- Industry certifications such as CISSP, CEH, OSCP, or CSSLP are a plus.
- Strong foundation of the required skills and knowledge through projects, programs and related experience.
- Solid understanding of cybersecurity principles, application security, and secure coding standards (e.g., OWASP Top 10).
- Familiarity with security frameworks and standards (e.g., NIST, ISO 27001).
- Basic knowledge of DevSecOps, CI/CD pipeline security, and cloud platforms.
- Understanding of ICT infrastructure, networks, and application development.
- Analytical and problem-solving skills, especially in identifying and mitigating security risks.
- Basic project management and documentation skills.
Experience needed
Minimum of 2 years of experience in Cyber Security and Software Development industry.
- Work closely with Agile development squads to embed security into all stages of the Software Development Lifecycle (SDLC) and support secure-by-design principles in systems and applications.
- Participate in application security testing, including threat modeling, vulnerability assessments, and penetration testing of web and mobile applications.
- Contribute to the adoption of secure coding practices and security best practices across the development teams.
- Conduct risk assessments and recommend security controls to mitigate identified risks.
- Participate in Development and maintenance of security standards, guidelines, and tools to support secure Agile development.
- Review source code for security vulnerabilities and offer actionable recommendations to improve application security.
- Work with Security Champions within squads to strengthen the security posture and promote a culture of security-first development.
- Assist in the development of secure DevOps pipelines and the implementation of security in CI/CD pipelines.
- Collaborate with Security Champions and Software Developers to conduct automated static (SAST) and dynamic (DAST) security testing across development and production environments in the CI/CD pipeline.
- Enforce security policies throughout the development process and deployment stages in the CI/CD pipeline.
- Participate in providing training and mentorship on secure development practices to developers and DevOps teams.
- Contribute to incident response and investigations involving application security issues.
- Assist in evaluating third-party applications and integrations for security risks.
- Strong foundation of the required skills and knowledge through projects, programs and related experience.
- Solid understanding of cybersecurity principles, application security, and secure coding standards (e.g., OWASP Top 10).
- Familiarity with security frameworks and standards (e.g., NIST, ISO 27001).
- Basic knowledge of DevSecOps, CI/CD pipeline security, and cloud platforms.
- Understanding of ICT infrastructure, networks, and application development.
- Analytical and problem-solving skills, especially in identifying and mitigating security risks.
- Basic project management and documentation skills.
- Bachelor’s degree in computer science, Cyber Security, Software engineering or related academic field.
- Industry certifications such as CISSP, CEH, OSCP, or CSSLP are a plus.
JOB-697c617c727f7
Vacancy title:
Specialist Application Security
[Type: FULL_TIME, Industry: Finance, Category: Computer & IT, Science & Engineering]
Jobs at:
CRDB
Deadline of this Job:
Tuesday, February 10 2026
Duty Station:
Tanzania Head Office | Dar es Salaam
Summary
Date Posted: Friday, January 30 2026, Base Salary: Not Disclosed
Similar Jobs in Tanzania
Learn more about CRDB
CRDB jobs in Tanzania
JOB DETAILS:
The Applications Security specialist is a key member of the Security Architecture team, reporting to the Enterprise Security Architect. This role is responsible for integrating security into Agile squads and the Software Development Lifecycle (SDLC), Designing Cyber security controls in CRDB Products and services and systems.
It is also responsible with providing assurance towards delivery of such controls by conducting security assessments and threat modelling and ensuring secure coding practices across all software development initiatives.
Furthermore, the specialist embeds secure SDLC practices inside product squads, own secure coding guidelines, orchestrate CI/CD security with SAST, DAST, SCA and act as the primary security SME supporting developers to deliver secure features at speed.
Responsibilities or duties
- Work closely with Agile development squads to embed security into all stages of the Software Development Lifecycle (SDLC) and support secure-by-design principles in systems and applications.
- Participate in application security testing, including threat modeling, vulnerability assessments, and penetration testing of web and mobile applications.
- Contribute to the adoption of secure coding practices and security best practices across the development teams.
- Conduct risk assessments and recommend security controls to mitigate identified risks.
- Participate in Development and maintenance of security standards, guidelines, and tools to support secure Agile development.
- Review source code for security vulnerabilities and offer actionable recommendations to improve application security.
- Work with Security Champions within squads to strengthen the security posture and promote a culture of security-first development.
- Assist in the development of secure DevOps pipelines and the implementation of security in CI/CD pipelines.
- Collaborate with Security Champions and Software Developers to conduct automated static (SAST) and dynamic (DAST) security testing across development and production environments in the CI/CD pipeline.
- Enforce security policies throughout the development process and deployment stages in the CI/CD pipeline.
- Participate in providing training and mentorship on secure development practices to developers and DevOps teams.
- Contribute to incident response and investigations involving application security issues.
- Assist in evaluating third-party applications and integrations for security risks.
Qualifications or requirements (e.g., education, skills)
- Bachelor’s degree in computer science, Cyber Security, Software engineering or related academic field.
- Industry certifications such as CISSP, CEH, OSCP, or CSSLP are a plus.
- Strong foundation of the required skills and knowledge through projects, programs and related experience.
- Solid understanding of cybersecurity principles, application security, and secure coding standards (e.g., OWASP Top 10).
- Familiarity with security frameworks and standards (e.g., NIST, ISO 27001).
- Basic knowledge of DevSecOps, CI/CD pipeline security, and cloud platforms.
- Understanding of ICT infrastructure, networks, and application development.
- Analytical and problem-solving skills, especially in identifying and mitigating security risks.
- Basic project management and documentation skills.
Experience needed
Minimum of 2 years of experience in Cyber Security and Software Development industry.
Work Hours: 8
Experience in Months: 24
Level of Education: bachelor degree
Job application procedure
Application Link: Click Here to Apply Now
All Jobs | QUICK ALERT SUBSCRIPTION