2 days ago
Doha, QatarMid Level
Responsibilities
- Conduct penetration tests across web, mobile, API, and thick-client applications and produce risk-rated reports with actionable remediation recommendations.
- Implement, tune, and manage SAST, DAST, and SCA security scanning tools across applications, code, configurations, and third-party dependencies.
- Perform threat modeling and provide guidance on mitigating application attack surfaces and security risks.
- Review source code for security vulnerabilities and provide developer-friendly remediation recommendations.
- Integrate security testing and controls into CI/CD pipelines for continuous security validation.
- Deliver secure coding training and application security awareness workshops.
- Evaluate application security testing and monitoring tools and recommend suitable technologies.
- Maintain documentation for security assessments, vulnerability management, application security standards, and policies.
Requirements
- Bachelor’s or college degree in computer science, information security, or a related field.
- At least 3 years of experience in application security, secure software development, penetration testing, or a closely related field.
- Proficiency with Burp Suite is required.
- Strong understanding of secure coding practices and hands-on experience with at least one programming language.
- Relevant professional certifications are highly desirable, including OffSec OSWA or OSWE, eLearnSecurity eWPT or eWPTX, GIAC/SANS SEC542 or GWAPT, BCSP, or other application security certifications.
- Familiarity with Snyk, HCL AppScan, Fortify, Postman, DevSecOps practices, and CI/CD pipelines is preferred.
- Knowledge of application security principles, common vulnerability classes, exploitation techniques, remediation strategies, and frameworks including OWASP Top 10, ASVS, MASVS, WSTG, and MSTG.
- Knowledge of Qatar National Information Assurance is a plus.
Tech Stack
Postman
