Phase: Registration
Registration Deadline: February 14, 2026
Submission Deadline: February 20, 2026
To register for a quest, you need to create an account on our platform . If you've registered for any quest before, you already have an account. If you face any issues, please contact us on WhatsApp at 01558405326 or join our WhatsApp Community.
Register NowYou get hired with paid contract and the opportunity to work on real-world .
👋 We are Tactful, a scale-up building and operating a cloud-native Customer Engagement Platform that helps businesses manage customer communications across all digital channels.
We enable teams to deliver fast, consistent, and high-quality customer experiences through a unified omnichannel layer and modern tooling. (Tactful AI)
🕓 Start Date: Immediate
📍 Location: Sheraton, Cairo (Hybrid)
💰 Salary: 400 – 650 GBP
📌 Type: Full-time · Individual Contributor
1️⃣ Register for the quest
2️⃣ You’ll receive full challenge instructions by email
3️⃣ Submit your solution before the deadline
4️⃣ Top candidates will be invited to a technical review session
5️⃣ One candidate will be hired — others may be considered for future roles
✔ 3–5 years of experience in Application Security or related software security roles
✔ Strong software development background
✔ Hands-on experience with cloud infrastructure & systems (Kubernetes, Docker, AWS)
✔ Solid experience across backend & frontend stacks (Node.js, Python, React, Vue)
✔ Proven track record in penetration testing, AppSec, or security reviews
✔ Comfortable threat-modeling complex, multi-tenant SaaS systems
✔ Clear communicator who can explain risks, tradeoffs, and mitigations
You will complete an Application Security Validation Challenge focused on a realistic, cloud-native SaaS platform.
Your task is to demonstrate your ability to:
Threat model a multi-tenant SaaS system
Identify and prioritize security risks aligned with OWASP Top 10
Propose shift-left security mitigations
Simulate real application-level exploits
Clearly communicate security reasoning and decisions
📄 All challenge details, scope, and constraints are defined in this document:
Submissions must follow the Deliverables section exactly as defined in the challenge document
Application & Cloud Threat Modeling — 25%
Risk Identification & Prioritization — 25%
Mitigation Quality & Practicality — 20%
Pentest Simulation & Fixes — 20%
Clarity, Structure & Communication — 10%
Top candidates will be invited to a technical review session with the engineering team.
👉 Final hiring decision within 3–5 business days after the review session.