Application Security Engineer
Apply on
Availability Status
This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.
We are seeking an experienced Application Security Engineer/Analyst to join our team. In this role, you will work closely with our Application Security team to secure our clients' applications. Your responsibilities will include conducting security scans, performing penetration tests, and assessing vulnerabilities across various types of applications, including web-based, mobile, APIs, and thick clients. You will collaborate with development and QA teams to embed security best practices throughout the software development lifecycle, ensuring that applications are designed and implemented with robust security controls.
Key Responsibilities:
- Penetration Testing: Conduct penetration tests on web applications, mobile applications, APIs, and thick client applications. Prepare detailed reports with actionable recommendations for remediation.
- Security Scanning: Implement and manage automated security scanning tools (SAST, DAST, SCA) to continuously monitor and identify vulnerabilities in code, configurations, and dependencies across all application types.
- Threat Modelling: Perform threat modelling to identify potential security risks associated with various types of applications. Provide guidance on mitigating these risks.
- Code Review: Review application code for security vulnerabilities across multiple platforms and offer practical recommendations for remediation.
- Training & Awareness: Develop and deliver training sessions and workshops to raise awareness about application security among development teams and other stakeholders, tailored to different application types.
- Tool Evaluation: Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms.
- Documentation: Create and maintain comprehensive documentation related to security assessments, vulnerability management, and security policies for diverse application types.
Qualifications:
- Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.
- Experience: At least 2 years of experience in application security, software development, or a related field.
- Certifications: Relevant certifications (e.g., BCSP, OSWA, OSWE, eWPT, eWPTX, SEC542) are highly desirable.
- Technical Skills: Proficiency with security testing tools such as Burp Suite (required), Fortify, SonarQube, and Postman (preferred). Strong understanding of secure coding practices and experience with at least one programming language.
- Knowledge: In-depth knowledge of application security principles and practices, familiar with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Familiarity with DevSecOps practices and CI/CD pipelines is a plus.
- Position to be based in DOHA.
Job Type: Full-time
Pay: RM14,000.00 - RM20,000.00 per month
Benefits:
- Health insurance
Schedule:
- Monday to Friday
Supplemental Pay:
- Performance bonus
Experience:
- Linux: 1 year (Preferred)
- Cybersecurity: 1 year (Preferred)
- Information security: 1 year (Preferred)
Ability to Commute:
- Henderson, NV 89015 (Required)
Ability to Relocate:
- Henderson, NV 89015: Relocate before starting work (Required)