
Application Security Engineer (AppSec Engineer)
HR Insider - Your Career Growth
Visa & sponsorship
- Employers in Qatar sponsor the residence visa by default, and nothing in the posting says otherwise.
Job description
Role:
Application Security Engineer (AppSec Engineer)
Experience:
3-7 years
Location:
Qatar (On Site, 5 Days Working)
Contract Duration: 8 months
Role Description
We are seeking an experienced Application Security professional to assess, identify, and remediate security vulnerabilities across web, mobile, and API applications. The role involves conducting security assessments, penetration testing, secure code reviews, threat modelling, vulnerability management, and integrating security practices within the Software Development Lifecycle (SDLC)
Qualifications
· Conduct Web Application, Mobile Application, and API Security Assessments.
· Perform Black Box, Grey Box, and Source Code Security Reviews.
· Execute Vulnerability Assessment and Penetration Testing (VAPT) activities.
· Identify, analyse, and validate security vulnerabilities in applications.
· Assess application security posture against OWASP Top 10, CWE, and industry security standards.
· Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
· Conduct Threat Modelling and Risk Assessments for new and existing applications.
· Review Authentication, Authorization, Session Management, and Access Control mechanisms.
· Assess API security controls including authentication, authorization, rate limiting, and data exposure risks.
· Collaborate with development teams to remediate vulnerabilities and validate fixes through re-testing.
· Support Secure SDLC initiatives and security requirements during application development.
· Participate in security architecture reviews and provide recommendations for secure design.
· Coordinate with SOC, Infrastructure, Compliance, and WAF teams to ensure secure deployment and operation of applications.
· Review external VAPT reports and ensure appropriate remediation and risk closure.
· Maintain security assessment reports, dashboards, and vulnerability tracking metrics.
Required Skills:
· Application Security (AppSec)
· OWASP Top 10
· VAPT / Penetration Testing
· Secure Code Review
· API Security
· SAST, DAST, SCA
· Threat Modelling
· Secure SDLC / DevSecOps
· Burp Suite, OWASP ZAP, Checkmarx, Fortify, Veracode
Preferred Certifications
: OSCP, CEH, GWAPT, CSSLP, CISSP