20 hours ago
Doha, QatarStaff+
Responsibilities
- Conduct penetration tests on web, mobile, API, and thick-client applications and produce risk-rated reports with remediation recommendations.
- Implement, tune, and manage SAST, DAST, and SCA security scanning tools.
- Perform threat modeling and assess application attack surfaces and security risks.
- Review source code for vulnerabilities and provide developer-friendly remediation guidance.
- Integrate security testing and controls into CI/CD pipelines in collaboration with development and DevOps teams.
- Deliver secure coding training and application security awareness workshops.
- Evaluate and recommend application security testing and monitoring tools.
- Maintain documentation for security assessments, vulnerability management, application security standards, and policies.
Requirements
- Bachelor’s or college degree in Computer Science, Information Security, or a related field.
- At least 3 years of experience in application security, secure software development, penetration testing, or a closely related field.
- Proficiency with Burp Suite is required.
- Hands-on experience with at least one programming language and a strong understanding of secure coding practices.
- Familiarity with Snyk, HCL AppScan, Fortify, Postman, DevSecOps practices, and CI/CD pipelines is preferred.
- In-depth knowledge of application security principles, security frameworks, vulnerability classes, exploitation techniques, and remediation strategies.
- Familiarity with OWASP Top 10, ASVS, MASVS, WSTG, and MSTG.
- Relevant professional certifications such as OSWA, OSWE, eWPT, eWPTX, SEC542, or GWAPT are highly desirable.
- Knowledge of Qatar National Information Assurance is a plus.
Tech Stack
Postman
Categories
About Malomatia
Malomatia is a Doha-based IT services and systems integration firm that delivers consulting, managed services, contact center operations, and enterprise solutions in cybersecurity, cloud, and AI for government and regulated industries in Qatar. The company builds and operates mission-critical platforms, including Oracle and other cloud environments, and provides SLA-driven support. Founded in 2008, it focuses on national digital programs and large public-sector modernization initiatives.
