Bunna Bank

Senior Application Security Specialist

Full-Time·6-8 years·Addis Ababa, Ethiopia
Posted today

Job Description

Company Description Bunna Bank S.C. is a privately owned commercial bank established to meet the growing demand for financial services in Ethiopia’s expanding economy. Licensed by the National Bank of Ethiopia in June 2009, the bank operates under the Licensing & Supervision of Banking Business Proclamation No. 592/2008 and the Commercial Code of Ethiopia. Bunna Bank officially began operations in October 2009 with substantial subscribed and paid-up capital, reflecting a strong financial foundation. The bank continues to grow its presence and services, offering career opportunities for professionals who want to contribute to the development of Ethiopia’s banking sector. Role Description The Senior Application Security Specialist is a full-time, on-site role based in Addis Ababa, Ethiopia. This role is responsible for designing, implementing, and maintaining security controls for banking applications, ensuring that systems, APIs, and integrations are protected against emerging threats. Day-to-day tasks include performing secure code reviews, conducting application penetration tests, overseeing vulnerability assessments, and working closely with development and infrastructure teams to remediate identified risks. The specialist will define secure development practices, contribute to security architecture and design, and help build security awareness among technical teams through guidance, documentation, and training. The role also involves monitoring application security posture, preparing risk and compliance reports, and supporting audits and regulatory requirements relevant to the Ethiopian banking sector. Qualifications Strong background in application security, including secure software development lifecycle (SSDLC), threat modeling, and secure architecture design. Hands-on experience with vulnerability assessment and penetration testing tools and techniques for web, mobile, and API-based applications. Proficiency in secure coding practices in common programming languages and familiarity with code review tools. Knowledge of relevant security standards and frameworks such as OWASP, ISO 27001, PCI DSS, and regulatory requirements for financial institutions. Experience collaborating with software development, DevOps, and IT operations teams to implement and enforce security controls. Ability to analyze complex technical issues, prioritize risks, and communicate clear, practical recommendations to both technical and non-technical stakeholders. Bachelor’s degree in Computer Science or a related field; advanced certifications such as CISSP, CISM, CEH, or CSSLP are an advantage. Demonstrated ability to work on-site in a collaborative environment and mentor junior security and development team members.

Similar jobs