This page was automatically translated and may contain errors. View in English.
malomatia

Application Security Specialist

malomatia

Doha, Doha Municipality, Qatar ・ フルタイム

最初に応募しよう

経験
3+ yrs
給料
求人情報
1
投稿済み
6時間前
Work mode
在任中
教育
Bachelor’s degree in Computer Science, Information Security, or related field
Resume
Required to apply

Where you'll work

仕事内容

Role Overview

We are looking for an Application Security Specialist who can help protect applications throughout the entire development and release cycle. In this role, you will partner with development, DevOps, and QA teams to build security into web, mobile, API, and thick-client applications from the start.

The position centers on finding security weaknesses, running testing activities, promoting secure development habits, and embedding security checks into CI/CD workflows through a DevSecOps mindset.

Key Responsibilities

  • Test web, mobile, API, and thick-client applications for security issues using penetration testing methods.
  • Use automated tools and techniques such as SAST, DAST, and SCA to uncover flaws in code, configurations, and third-party dependencies.
  • Conduct threat modeling during the design stage to spot potential risks and define practical mitigation steps.
  • Review source code from a security perspective and give developers clear, actionable remediation advice.
  • Build security controls into CI/CD pipelines to support DevSecOps delivery.
  • Create and run secure coding training sessions and awareness programs for development teams.
  • Assess application security products and recommend suitable tools and technologies.
  • Document assessment results, vulnerabilities, and application security standards in a clear and maintainable way.

Requirements

  • At least 3 years of experience in application security, secure software development, or penetration testing.
  • Practical, hands-on experience testing web, mobile, API, and other application types.
  • Strong working knowledge of Burp Suite, which is required, plus familiarity with tools such as Snyk, HCL AppScan, Fortify, and Postman.
  • Solid understanding of secure coding principles and proficiency in at least one programming language.
  • Experience working with DevSecOps processes and integrating security into CI/CD pipelines.
  • Good knowledge of OWASP Top 10, ASVS, MASVS, WSTG, and MSTG.
  • Understanding of common vulnerability categories, exploitation approaches, and remediation methods.
  • Strong analytical ability along with reporting and communication skills.
  • Bachelor’s degree in Computer Science, Information Security, or a closely related discipline.

Preferred Certifications

  • OffSec certifications such as OSWA or OSWE.
  • eLearnSecurity certifications such as eWPT or eWPTX.
  • GIAC / SANS certifications such as SEC542 or GWAPT.
  • Other recognized application security certifications.

Additional Advantage

Knowledge of the Qatar National Information Assurance (NIA) framework will be considered a plus.

返信をご希望の場合は、そのまま残してください。それ以外の目的には一切使用いたしません。

クリックして閲覧ドラッグ&ドロップ、または ペースト スクリーンショット

PNG、JPG、GIF、MP4、WebM、MOV形式 · 各ファイル最大20MB · 最大5ファイルまで