Application Security Analyst At Hydrogen Payment Services Company Limited
Hydrogen Payment Services Company Limited·Lagos, nigeria·Full Time·Onsite
OperationsFull TimeOnsite
-
We are seeking an Application Security Analyst to protect the applications powering our card issuance, card management, and switch/transaction processing platforms. You will embed security across the SDLC, conduct testing and code reviews, support PCI-DSS compliance, and drive remediation efforts. You'll partner with engineering, SOC, and security teams to secure card and switch infrastructure, including third-party and ISO 8583 integrations
What you will do
Secure Application Testing & Review - Conduct SAST, DAST, SCA, and manual secure code reviews, along with vulnerability assessments and penetration testing (web, API, mobile) across card management, switch, and POS/ATM integration systems.
Secure SDLC & CI/CD Integration - Design and embed security checkpoints throughout the development lifecycle and CI/CD pipelines to ensure security is built into application development from the start.
PCI-DSS Compliance & Risk Management - Support control validation, evidence collection, and remediation tracking for PCI-DSS compliance, while reviewing third-party and vendor integrations (including ISO 8583 messaging and card network interfaces) for security risk
Monitoring & Incident Response - Monitor application-layer security events, collaborate with SOC teams to investigate anomalies in card/switch transaction flows, and participate in incident response for application- level security incidents
Reporting & Security Enablement - Document findings and produce risk assessment reports, partner with engineering teams to track remediation to closure, and contribute to secure coding training and awareness sessions for developers.
Requirements
Bachelor's degree in cyber/information security, computer science, information technology or any related discipline.
3-5 years of relevant experience in application security, penetration testing, or software security engineering, with prior exposure to fintech, banking, card processing, or payment switch environments considered a strong advantage.
Certifications: CompTIA Security+ (required or in progress); CEH, OSCP, CSSLP, PCI-DSS, or cloud security certifications (AWS Security Specialty. AZ-500) preferred; progress toward CISSP a plus.
Strong analytical communication, and cross-functional collaboration skills; able to translate technical risk into business terms and perform under pressure.