Responsibilities
- Penetration Testing: Conduct penetration tests on web applications, mobile applications, APIs, and thick client applications. Prepare detailed reports with actionable recommendations for remediation.
- Security Scanning: Implement and manage automated security scanning tools (SAST, DAST, SCA) to continuously monitor and identify vulnerabilities in code, configurations, and dependencies across all application types.
- Threat Modelling: Perform threat modelling to identify potential security risks associated with various types of applications. Provide guidance on mitigating these risks.
- Code Review: Review application code for security vulnerabilities across multiple platforms and offer practical recommendations for remediation.
- Training & Awareness: Develop and deliver training sessions and workshops to raise awareness about application security among development teams and other stakeholders, tailored to different application types.
- Tool Evaluation: Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms.
- Documentation: Create and maintain comprehensive documentation related to security assessments, vulnerability management, and security policies for diverse application types.
Qualifications
- Education: Bachelor's / college degree in Computer Science, Information Security, or a related field.
- Experience: At least 2 years of experience in application security, software development, or a related field.
- Certifications: Relevant certifications (e.g., BCSP, OSWA, OSWE, eWPT, eWPTX, SEC542) are highly desirable.
- Technical Skills: Proficiency with security testing tools such as Burp Suite (required), Fortify, SonarQube, and Postman (preferred). Strong understanding of secure coding practices and experience with at least one programming language.
- Knowledge: In-depth knowledge of application security principles and practices, familiar with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Familiarity with DevSecOps practices and CI/CD pipelines is a plus.
About Malomatia
ABOUT US
malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end-to-end technology solutions that empower clients to achieve their strategic goals.
Our mission
Empowering Qatar's businesses and governments to leap into the digital future with agile, knowledge-driven solutions.
Our vision
To become Qatar's trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world-class tech ecosystem.
Driving change that makes a real impact
Since 2008, malomatia has been driving Qatar's digital transformation through innovative, ISO-certified IT solutions. With expertise across key public and private sectors, we empower the nation's vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar's sustainable future.
About The Team
Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients.
Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation.
Join us in shaping the future of technology in Qatar