Security Engineer

Rihal

Muscat

On-site

OMR 12,000 - 18,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Rihal is seeking a Security Engineer to implement and maintain security measures that protect the organization’s digital assets. The role requires foundational cybersecurity knowledge and a willingness to learn under the guidance of senior engineers.

You will act as the single point of contact for product security, perform security code reviews, and contribute to secure architecture and threat modeling. You’ll work with engineering teams to embed security into the SDLC and track remediation

Qualifications

  • Proven experience in security code review and identifying vulnerabilities beyond automated scanners.
  • Solid understanding of threat modeling, secure design patterns and zero trust concepts.
  • Familiarity with OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes.
  • Working knowledge of SAST/DAST/SCA tools and CI/CD security integration.
  • Ability to communicate findings clearly to technical and non-technical stakeholders.

Responsibilities

  • Act as the single point of contact between security and product/engineering for security matters.
  • Perform security code reviews across codebases to identify vulnerabilities before release.
  • Review and contribute to security architecture, threat modeling, and secure design patterns.
  • Embed security requirements into design, development, and deployment stages (Secure SDLC).
  • Triage, validate, and help remediate vulnerabilities from code review, SAST/DAST, and tests.
  • Define and maintain secure coding standards, guidelines, and checklists.
  • Support integration of security tooling into CI/CD pipelines (SAST, SCA, secrets, container scanning).
  • Provide security guidance on API design, authentication/authorization, and data protection.
  • Track and report product security posture and remediation timelines to management.
  • Stay current on emerging threats and industry best practices (OWASP, CWE/SANS Top 25).

Skills

Security code review
Security architecture
OWASP Top 10
CWE/SANS Top 25
SAST/DAST/SCA tools
DevSecOps
Threat modeling
Cloud platforms
Kubernetes security
Communication with stakeholders
Software development experience
CI/CD security gates

Tools

Semgrep
SonarQube
Checkmarx
Snyk

Job description

Job Purpose

The Security Engineer assists in implementing and maintaining security measures to protect the organization’s digital assets. This role requires foundational knowledge of cybersecurity principles and the ability to learn and grow under the guidance of senior engineers.

Key Responsibilities
  • Act as the single point of contact between the security team and product/engineering teams for all product security matters.
  • Perform security code reviews (manual and tool-assisted) across codebases to identify vulnerabilities, insecure patterns, and logic flaws before release.
  • Review and contribute to security architecture for new and existing products, including threat modeling, secure design patterns, and risk assessments.
  • Partner with engineering teams early in the SDLC to embed security requirements into design, development, and deployment stages (Secure SDLC / DevSecOps practices).
  • Triage, validate, and help remediate vulnerabilities identified through code review, SAST/DAST tools, penetration tests, and bug bounty reports.
  • Define and maintain secure coding standards, guidelines, and checklists tailored to the technology stacks in use.
  • Support integration of security tooling into CI/CD pipelines (SAST, dependency/SCA scanning, secrets detection, container scanning).
  • Provide security guidance on API design, authentication/authorization models, data protection, and third-party integrations.
  • Track and report on product security posture, open findings, and remediation timelines to management.
  • Stay current on emerging threats, vulnerability classes, and industry best practices (OWASP, CWE/SANS Top 25, etc.) relevant to the product portfolio.
Required Qualifications
  • Proven experience in security code review — able to read and analyze code (not just run automated scanners) to identify vulnerabilities such as injection flaws, broken authentication/authorization, insecure deserialization, business logic issues, etc.
  • Solid understanding of security architecture principles — threat modeling, secure design patterns, defense-in-depth, zero trust concepts, and secure API/data flow design.
  • Familiarity with the OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes across web, API, mobile, and cloud-native applications.
  • Working knowledge of SAST/DAST/SCA tools (e.g., Semgrep, SonarQube, Checkmarx, Snyk, or similar) and how to integrate them into CI/CD pipelines.
  • Ability to communicate security findings clearly to both technical and non-technical stakeholders, and to build collaborative relationships with development teams.
Preferred Qualifications
  • Prior software development experience (e.g., as a developer or in a hybrid dev/security role) — hands-on experience writing production code in one or more languages (e.g., JavaScript/TypeScript, Python, Java, Go, .NET) is a strong plus.
  • Experience with cloud platforms (AWS, Azure, or GCP) and container/orchestration security (Docker, Kubernetes) and on prem deployments also
  • Familiarity with DevSecOps practices and pipeline security (CI/CD security gates, IaC scanning).
  • Relevant certifications such as OSWE or similar are a plus but not mandatory.
  • Experience conducting or coordinating penetration tests and working with external security assessors.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Security Architecture & Engineering
Head of Security Architecture & Engineering

The IN Group • Muscat

On-site
OMR 30,000 - 60,000
Security Engineer: Code Review & Secure SDLC Champion
Security Engineer: Code Review & Secure SDLC Champion

Rihal • Muscat

On-site
OMR 12,000 - 18,000
Information Security Specialist
Information Security Specialist

tamimi commercial • As Sudiyah

On-site
OMR 15,000 - 25,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Kreate Energy • Oman

On-site
OMR 12,000 - 24,000
Pre Sales Architect
Pre Sales Architect

Salt Digital Recruitment • As Sudiyah

On-site
OMR 30,000 - 47,000
Cyber Security Specialist
Cyber Security Specialist

Oman Investment Authority • Oman

On-site
OMR 30,000 - 50,000
Cyber Security Specialist
Cyber Security Specialist

Gender • Oman

On-site
OMR 12,000 - 18,000
Security Architecture & DevSecOps Leader
Security Architecture & DevSecOps Leader

The IN Group • Muscat

On-site
OMR 30,000 - 60,000
IT Security Manager
IT Security Manager

bTranz Solutions • As Sudiyah

On-site
OMR 26,000 - 35,000
Expert SAP Technical Security
Expert SAP Technical Security

Experience • Muscat

On-site
OMR 22,000 - 45,000