Search by job, company or skills

Senior Security Engineer/ App Sec

Senior Security Engineer/ App Sec

boubyan digital factory
5-10 Years
Not Disclosed
  • Posted 11 days ago
  • Be among the first 10 applicants

Job Description

Role Purpose

The Bank is seeking a senior security engineer specializing in penetration testing, with a primary focus on web applications, APIs, and mobile applications. The role identifies and validates exploitable vulnerabilities, communicates business impact, and works with application owners to verify remediation. Limited support for application security testing tools is a secondary responsibility.

Key Responsibilities

Web API and Mobile Penetration Testing

• Plan and execute penetration tests of web applications, APIs, and Android and iOS mobile applications, covering new releases, major changes, and periodic assessments.

• Perform manual web application testing for authentication, authorization, session management, injection, file handling, and business logic vulnerabilities across user roles.

• Test RESTful, SOAP, and GraphQL APIs for object- and function-level authorization, token handling, input validation, sensitive data exposure, and abuse of business workflows.

• Assess mobile applications through static and dynamic analysis, including local storage, transport security, platform interactions, application binaries, and supporting APIs.

• Validate vulnerabilities with reproducible evidence and controlled proof-of-concept testing; prioritize findings by exploitability and business impact.

• Produce clear findings reports with affected assets, reproduction steps, severity, evidence, and actionable remediation guidance to support CBK CORF and internal assurance requirements.

• Work with developers and application owners to explain findings, recommend practical fixes, and retest remediation before closure.

• Define test scope, prerequisites, and rules of engagement with stakeholders; maintain test coverage and protect sensitive assessment data.

• Coordinate third-party application penetration testing, review deliverables, and track remediation and retesting with relevant stakeholders.

• Maintain repeatable testing methods using relevant OWASP web, API, and mobile testing guidance; mentor colleagues in application penetration testing.

Application Security Tooling Support

• Provide limited support for implementing and tuning static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and mobile application security testing (MAST) tools.

• Help validate tool findings and reduce false positives; coordinate CI/CD integration with DevOps and development teams. This support remains secondary to hands-on penetration testing, with pipeline ownership retained by those teams.

Required Qualifications

• 5–10 years in information security, with substantial hands-on penetration testing experience and demonstrated depth in web application, API, and mobile application testing.

• At least one recognized penetration testing certification, such as OSCP, OSWE, GPEN, or GWAPT.

• Practical proficiency with Burp Suite and mobile testing tools such as Frida, Objection, and MobSF, including manual validation beyond automated scanner results.

• Strong understanding of HTTP, application authentication and authorization, common API architectures, Android and iOS security, and OWASP testing methodologies.

• Ability to script in Python, Bash, or PowerShell to support testing, reproduce findings, and automate repetitive assessment tasks.

Preferred Qualifications

• Familiarity with SAST, DAST, SCA, and MAST tools and their integration with CI/CD platforms such as Jenkins, Azure DevOps, or Tekton.

• Prior experience in financial services or another regulated industry, with familiarity with CBK CORF, PCI DSS, or NIST CSF.

• A demonstrable application vulnerability research or bug bounty track record, or relevant hands-on CTF experience.

• Ability to review source code to support vulnerability investigation and remediation validation.

Soft Skills

• Ability to explain technical vulnerabilities and business impact clearly to developers, application owners, management, and regulatory reviewers.

• Strong reporting discipline, attention to detail, and ability to manage testing priorities and coordinate remediation with stakeholders.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Objection

Dynamic Application Security Testing (DAST)

Tekton

MobSF

CI/CD Integration

OWASP Testing Methodologies

Frida

Static Application Security Testing (SAST)

Mobile Application Security Testing (MAST)

GraphQL APIs

Software Composition Analysis (SCA)