Application Security Engineering Service at VaporVM

VaporVM

Dubai

On-site

AED 180,000 - 320,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

VaporVM is seeking an on-site Application Security Engineer to safeguard enterprise applications throughout their lifecycle. You will conduct assessments, manage security tools, identify vulnerabilities, and guide remediation while aligning security with development and IT operations.

You will lead secure coding practices, collaborate with DevOps and cloud teams, and drive SSDLC compliance across internal and third-party apps.

Qualifications

  • Bachelor’s degree in cybersecurity or related field.
  • Certifications: CSSLP, GWAPT, CASE, CEH, OSWE, OSCP, CISSP.

Responsibilities

  • Application Security Operations: administer, configure and optimise SAST/DAST/IAST and SCA tools.
  • Monitor controls and ensure ongoing effectiveness of security measures.
  • Support deployment and management of security solutions in dev/prod.
  • Troubleshoot issues in application security tooling.

Skills

Application Security
SAST/DAST/IAST/SCA
Vulnerability Management
SSDLC/Secure coding
Cloud-native apps
CI/CD & DevSecOps
OWASP Top 10/ASVS

Education

Bachelor’s Degree in Cybersecurity or related field

Tools

Veracode
Fortify
Checkmarx
SonarQube
Burp Suite
OWASP ZAP
Nessus
Qualys
Rapid7
GitHub Advanced Security

Job description

Job Summary

The Application Security On‑Site Engineer is responsible for ensuring the security of enterprise applications throughout their lifecycle by performing security assessments, managing application security tools, identifying vulnerabilities, and supporting remediation efforts. The role serves as a key liaison between security, development, and IT operations teams to enhance the organization’s security posture and ensure compliance with security standards and regulatory requirements. The successful candidate will possess strong technical expertise in application security, vulnerability management, secure software development practices, and security testing methodologies, and will provide hands‑on operational support and active collaboration with stakeholders to drive security improvements across both internally developed and third‑party applications.

Key Responsibilities
  • Application Security Operations – Administer, configure, maintain, and optimise application security tools and platforms, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and vulnerability management solutions.
  • Monitor application security controls and ensure continuous operational effectiveness.
  • Support the deployment, integration, and ongoing management of security solutions within development and production environments.
  • Troubleshoot and resolve technical issues related to application security tools and services.
Security Assessments and Testing
  • Conduct comprehensive application security assessments for internally developed, commercial off‑the‑shelf (COTS), cloud‑based, and third‑party applications.
  • Perform vulnerability assessments, secure code reviews, configuration reviews, and security testing activities.
  • Identify security weaknesses, vulnerabilities, and misconfigurations within applications and supporting infrastructure.
  • Validate security findings and eliminate false positives through detailed analysis.
Vulnerability Management
  • Analyse, classify, and prioritise vulnerabilities based on risk, exploitability, business impact, and compliance requirements.
  • Maintain vulnerability tracking processes and ensure accurate documentation of findings.
  • Monitor remediation progress and verify the effectiveness of corrective actions.
  • Support risk management activities by providing recommendations for mitigation strategies.
Secure Development Support
  • Partner with software development teams to promote Secure Software Development Lifecycle (SSDLC) practices.
  • Provide secure coding guidance and application security best‑practice recommendations.
  • Review application architecture and design to identify potential security risks.
  • Assist developers in understanding and addressing security vulnerabilities during development and testing phases.
Collaboration and Incident Support
  • Work closely with development, infrastructure, DevOps, cloud, and IT operations teams to resolve security issues.
  • Participate in security investigations involving application‑related vulnerabilities and incidents.
  • Support root‑cause analysis and implementation of preventive security controls.
  • Serve as the on‑site technical focal point for application security‑related activities.
Documentation and Reporting
  • Prepare detailed security assessment reports, risk reports, vulnerability summaries, and remediation recommendations.
  • Develop and maintain security procedures, standards, and operational documentation.
  • Produce metrics and dashboards related to application security posture and vulnerability trends.
  • Ensure documentation aligns with organisational policies, regulatory requirements, and industry standards.
Compliance and Governance
  • Support compliance initiatives related to ISO 27001, NIST, PCI DSS, OWASP, CIS Controls and other applicable security frameworks.
  • Participate in security audits and compliance reviews.
  • Assist in developing and enforcing application security policies and procedures.
  • Ensure application security activities meet internal governance requirements and industry best practices.
Required Qualifications
  • Education: Bachelor’s Degree in Cybersecurity, Information Security, Computer Science, Software Engineering, Information Technology, or a related field.
  • Certifications (Preferred):
    • Certified Secure Software Lifecycle Professional (CSSLP)
    • GIAC Web Application Penetration Tester (GWAPT)
    • Certified Application Security Engineer (CASE)
    • Certified Ethical Hacker (CEH)
    • Offensive Security Web Expert (OSWE)
    • Offensive Security Certified Professional (OSCP)
    • Certified Information Systems Security Professional (CISSP)
Experience
  • Minimum of three (3) years of hands‑on experience in application security operations.
  • Experience with application security testing and vulnerability management processes.
  • Experience supporting secure software development initiatives.
  • Experience working with developers, DevOps, and infrastructure teams in enterprise environments.
Required Technical Skills
  • Application Security, Application Security Testing (SAST, DAST, IAST, SCA), Secure Code Review, Vulnerability Assessment and Management, Threat Modelling, Web Application Security, API Security, Security Frameworks & Standards.
  • OWASP Top 10, OWASP ASVS, NIST Cybersecurity Framework, NIST Secure Software Development Framework (SSDF), PCI DSS, ISO 27001.
  • Development & Technologies: Knowledge of programming languages such as Java, .NET, Python, JavaScript, PHP, or Node.js.
  • Understanding of web technologies, REST APIs, microservices, and cloud‑native applications.
  • Familiarity with CI/CD pipelines and DevSecOps practices.
  • Security Tools (Examples): Veracode, Fortify, Checkmarx, SonarQube, Burp Suite, OWASP ZAP, Nessus, Qualys, Rapid7, GitHub Advanced Security.
Soft Skills
  • Strong analytical and problem‑solving capabilities.
  • Excellent communication and stakeholder management skills.
  • Ability to explain technical security risks to both technical and non‑technical audiences.
  • Strong report writing and documentation skills.
  • Ability to work independently while effectively collaborating with cross‑functional teams.
  • Strong attention to detail and commitment to continuous improvement.
Key Deliverables
  • Regular application security assessment reports.
  • Vulnerability management dashboards and remediation tracking reports.
  • Secure coding guidance documentation.
  • Compliance‑aligned security evidence and audit support documentation.
  • Security metrics and risk analysis reports.
  • Continuous improvement recommendations for application security maturity.
Working Environment

Primarily an on‑site customer‑facing role with close interaction with development, IT operations, infrastructure, cloud, and cybersecurity teams. Participation in security reviews, audits, remediation workshops, and technical support activities.

Experience Level

Mid‑Level (3‑5 Years)

Employment Type

Full‑Time

Department

Cybersecurity / Application Security

Reporting To

Application Security Lead / Cybersecurity Manager

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hands-On Application Security Engineer
Hands-On Application Security Engineer

VaporVM • Dubai

On-site
AED 180,000 - 320,000
Senior Web App Security Engineer (m/f/d)
Senior Web App Security Engineer (m/f/d)

Halian • Abu Dhabi

On-site
AED 350,000 - 520,000
Application Security Engineer/Penetration Tester
Application Security Engineer/Penetration Tester

Remotedxb • Dubai

On-site
AED 180,000 - 240,000
Security Consultant
Security Consultant

Epergne Solutions • Dubai

On-site
Security Consultant
Security Consultant

Epergne Solutions • Abu Dhabi

On-site
Senior Web App Security Engineer (m/f/d)
Senior Web App Security Engineer (m/f/d)

Halian | Managed Services, Recruitment Agency & Contract Staffing • Abu Dhabi Emirate

On-site
AED 279,000 - 469,000
Cyber Security Lead
Cyber Security Lead

Good co India • United Arab Emirates

On-site
AED 420,000 - 840,000
Senior Security Engineer
Senior Security Engineer

SDD • Sharjah

On-site
AED 180,000 - 280,000
Application Security Engineer
Application Security Engineer

Remotedxb • Dubai

On-site
AED 180,000 - 280,000
Global Medical Coverage
Health & Wellness Focus
Gym, dental, psychological services
Cloud Security Engineer - Hybrid Platforms
Cloud Security Engineer - Hybrid Platforms

AlFuttaim • Dubai

Hybrid