30000-45000
We are seeking a skilled and security-conscious Full Stack PHP Developer to join our engineering team. You will be responsible for designing, developing, and maintaining web applications that process and store critical user data. Security, performance, and reliability are non-negotiable in our stack — you will be expected to treat them as first-class concerns in everything you build.
Security-first Role:This position involves building and maintaining systems that handle highly sensitive user data. Candidates must demonstrate a strong security mindset, adherence to best practices, and experience working in compliance-driven or data-critical environments.
Responsibilities
- Design, develop, and maintain scalable full-stack web applications using PHP and modern frameworks (Laravel, Symfony, or equivalent).
- Implement and enforce robust security measures including input validation, output encoding, authentication, authorisation, and encryption of sensitive data at rest and in transit.
- Perform security-focused code reviews, identify vulnerabilities, and ensure adherence to OWASP Top 10 and relevant compliance standards.
- Design and manage relational databases (MySQL/PostgreSQL) with a focus on data integrity, access controls, and audit logging.
- Build and integrate secure RESTful APIs and third-party services while handling sensitive credentials safely.
- Collaborate with backend and frontend teams to deliver secure, well-tested features across the full stack.
- Monitor applications for anomalies, respond to security incidents, and participate in threat modelling sessions.
- Maintain thorough documentation of systems, data flows, and security decisions.
Required Skills & Qualifications
- Minimum 2 years of hands-on professional experience in full-stack PHP development.
- Proven experience working on software that handles sensitive, personal, or regulated user data.
- Strong command of PHP 8.x and at least one major framework (Laravel preferred).
- Solid understanding of web application security: OWASP, SQL injection prevention, XSS, CSRF, secure session management, and encryption
- Experience with relational databases (MySQL / PostgreSQL) — schema design, query optimisation, role-based access
- Proficiency in frontend technologies: HTML5, CSS3, JavaScript (Vue.js or React is a plus)
- Experience with version control (Git) and CI/CD pipelines.Familiarity with Linux/Unix environments and deployment practices.
Nice to Have
- Experience with data privacy regulations such as GDPR, HIPAA, or similar frameworks
- Knowledge of penetration testing, vulnerability scanning, or security audits
- Exposure to containerisation (Docker, Kubernetes) and cloud platforms (AWS, GCP, or Azure)
- Familiarity with Redis, message queues (RabbitMQ/SQS), or caching strategies
- Security certifications (CEH, OSCP, or equivalent) are a strong advantage.