About the Role:
We are seeking a skilled Application Security Specialist to strengthen the security of applications across their full lifecycle. You will work closely with development, DevOps, and QA teams to ensure secure design, development, and deployment of web, mobile, API, and thick-client applications.
The role focuses on identifying vulnerabilities, performing security testing, enabling secure coding practices, and integrating security into CI/CD pipelines as part of a DevSecOps approach.
Key Responsibilities:
- Conduct penetration testing across web, mobile, API, and thick-client applications.
- Perform automated security scanning (SAST, DAST, SCA) to identify vulnerabilities in code, configurations, and dependencies.
- Carry out threat modelling during the design phase to identify risks and define mitigation strategies.
- Perform secure code reviews and provide developer-friendly remediation guidance.
- Integrate security controls into CI/CD pipelines to enable DevSecOps practices.
- Develop and deliver secure coding training and awareness sessions for development teams.
- Evaluate and recommend application security tools and technologies.
- Prepare and maintain documentation for security assessments, vulnerabilities, and application security standards.
Required Skills & Experience:
- 3+ years of experience in application security, secure software development, or penetration testing.
- Strong hands-on experience with web, mobile, API, and application security testing.
- Proficiency with Burp Suite (required) and familiarity with tools such as Snyk, HCL AppScan, Fortify, and Postman.
- Strong understanding of secure coding practices and at least one programming language.
- Experience with DevSecOps and CI/CD pipeline integration.
- Strong knowledge of OWASP Top 10, ASVS, MASVS, WSTG, and MSTG.
- Understanding of vulnerability classes, exploitation techniques, and remediation approaches.
- Strong analytical, reporting, and communication skills.
Qualifications:
- Bachelor's degree in Computer Science, Information Security, or related field.
Preferred Certifications:
- OffSec (OSWA, OSWE)
- eLearnSecurity (eWPT, eWPTX)
- GIAC / SANS (SEC542, GWAPT)
- Other relevant application security certifications
Additional Advantage:
- Knowledge of Qatar National Information Assurance (NIA) framework.