Job Overview:
We are seeking a highly skilled and experienced Application Security Specialist to join our client s team in Doha Qatar.
Key Responsibilities:
- Ensure that application security is an embedded and critical part of the software delivery lifecycle (including during the early stages of projects) regardless of delivery methodology and tool sets used (e.g. static code analysis)
- Conduct security assessments including code reviews and vulnerability assessments on applications and APIs.
- Conduct assessments to identify security risks in applications before they are implemented
- Work with development teams to provide appropriate and effective remediation guidance for vulnerabilities discovered during various assessments
- Perform application vulnerability assessments including regular scanning and Coordinate with development team to fix application vulnerabilities
- Track prioritize and manage security vulnerabilities discovered during assessments and thirdparty scans. Coordinate with development teams for timely remediation.
- Develop and maintain threat models for applications and systems to identify potential security risks and recommend mitigation.
- Address Continuously improve the processes and procedures to include report exceptions/risk acceptance for further review
- Contribute to the development of security policies and security standards
- Analyze and specify the security requirements for secure development at all phases of SDLC
- Ensure security and privacy requirements are met before the application development
- Ensure application security guidelines are defined documented and implemented for development testing and deployment
- Implement and manage security tools for static and dynamic application security testing (SAST/DAST) and continuous integration/continuous deployment (CI/CD) pipelines.
- Knowledge of Secure Development of technologies and platform used in the application
- Regular Application Security testing and consistently to make sure that appropriate security measures have been added.
- Provide training and guidance to development teams on secure coding practices threat awareness and emerging security trends.
- Experience with DevSecOps practices and integrating security into DevOps pipelines.
- Familiarity with container security and cloud security best practices.
- Experience in managing and securing APIs and microservices in a distributed environment.
Requirements
- Bachelor s degree in Computer Science or Similar plus substantial continued education and training in the field.
- Experience with web and mobile application security
- Ability to present effectively and communicate security threats and risks to any audience and impress upon them the mitigation techniques and strategies
- Proficiency in security tools like Burp Suite OWASP ZAP Fortify or similar.
- Knowledge of programming languages such as Java Python C# or JavaScript.
- Experience with SAST/DAST tools and CI/CD integration.
- Understanding of web application security vulnerabilities (e.g. OWASP Top 10) and secure coding practices.
- Selfmotivated with the ability to prioritize meet deadlines and manage to change priorities
- Strong understanding of OWASP top 10 and similar application security methodologies
- Strong understanding of cryptography and SSL certificate lifecycle management
- Experience with security tools including vulnerability scanning
- Solid understanding of application security and system design
- Familiarity with common vulnerabilities and attack vectors
Experience with web and mobile application security Ability to present effectively and communicate security threats and risks to any audience and impress upon them the mitigation techniques and strategies Proficiency in security tools like Burp Suite, OWASP ZAP, Fortify, or similar. Knowledge of programming languages such as Java, Python, C#, or JavaScript. Experience with SAST/DAST tools and CI/CD integration. Understanding of web application security vulnerabilities (e.g., OWASP Top 10) and secure coding practices. Self-motivated with the ability to prioritize, meet deadlines, and manage to change priorities Strong understanding of OWASP top 10 and similar application security methodologies Strong understanding of cryptography and SSL certificate lifecycle management Experience with security tools including vulnerability scanning Solid understanding of application security and system design Familiarity with common vulnerabilities and attack vectors
Education
Bachelor s degree in Computer Science or Similar, plus substantial continued education and training in the field.