Application Security

malomatia

Doha

On-site

QAR 180,000 - 320,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

malomatia in Doha is seeking an Application Security Specialist to fortify clients' applications across their lifecycle. You will conduct penetration testing, security scanning, threat modelling, and secure code reviews, partnering with development, QA, and DevOps to embed security into CI/CD pipelines.

The role requires hands-on security expertise, strong analytical skills, and the ability to translate findings into practical fixes for developers.

Qualifications

  • Bachelor’s degree in CS, information security, or related field.
  • Minimum 3 years in application security, secure software development, or related roles.
  • Proficiency with Burp Suite and other security testing tools.
  • Experience embedding security in CI/CD pipelines.
  • Knowledge of OWASP Top 10, ASVS, MASVS guidelines.

Responsibilities

  • Penetration testing on web, mobile, APIs, and thick-client apps with detailed reports.
  • Automated security scanning using SAST, DAST, and SCA across code and configurations.
  • Threat modelling and secure code reviews.
  • DevSecOps integration to CI/CD pipelines with remediation guidance.
  • Develop and deliver secure coding training for development teams.
  • Create documentation on assessments, vulnerability management, and standards.

Skills

Penetration testing
Threat modelling
Secure code review
CI/CD / DevSecOps
Training & awareness
Documentation
Secure coding practices
Programming language

Education

Bachelor’s / college degree in Computer Science, Information Security, or a related field
OffSec OSWA / OSWE
eLearnSecurity eWPT / eWPTX
GIAC / SANS SEC542 / GWAPT
BCSP or other application security certifications

Tools

Burp Suite
Snyk
HCL AppScan
Fortify
Postman

Job description

Job Description

We are seeking a skilled Application Security Specialist to join our Cybersecurity Practice. In this role, you will work closely with our application security, development, and QA teams to secure our clients’ applications across their entire lifecycle. You will conduct security testing, perform penetration tests, and assess vulnerabilities across web, mobile, API applications.

Your responsibilities will span application penetration testing, automated security scanning (SAST, DAST, SCA), threat modelling, secure code review, and developer enablement. You will embed security best practices throughout the software development lifecycle and ensure that applications are designed and built with robust security controls.

You will collaborate with development and DevOps teams to integrate security into CI/CD pipelines, triage and validate findings, and provide clear, actionable remediation guidance. The role requires hands‑on technical expertise, strong analytical skills, and the ability to translate complex security findings into practical fixes that developers can implement.

Responsibilities
  • Penetration Testing: Conduct penetration tests on web applications, mobile applications, APIs, and thick-client applications. Prepare detailed reports with clear risk ratings and actionable remediation recommendations.
  • Security Scanning: Implement, tune, and manage automated security scanning tools (SAST, DAST, SCA) to continuously identify vulnerabilities in code, configurations, and third-party dependencies across all application types.
  • Threat Modelling: Perform threat modelling to identify potential security risks and attack surfaces associated with applications early in the design process, and provide guidance on mitigating these risks.
  • Secure Code Review: Review application source code for security vulnerabilities across multiple platforms and languages, and offer practical, developer-friendly recommendations for remediation.
  • DevSecOps Integration: Integrate security testing and controls into CI/CD pipelines, enabling continuous and automated security validation as part of the development workflow.
  • Training & Awareness: Develop and deliver secure coding training sessions and workshops to raise application security awareness among development teams and other stakeholders.
  • Tool Evaluation: Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms.
  • Documentation: Create and maintain comprehensive documentation related to security assessments, vulnerability management, and application security standards and policies.
Qualifications
  • Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.
  • Experience: At least 3 years of experience in application security, secure software development, penetration testing, or a closely related field.
  • Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
    • OffSec certifications (e.g., OSWA, OSWE)
    • eLearnSecurity (e.g., eWPT, eWPTX)
    • GIAC / SANS (e.g., SEC542, GWAPT)
    • BCSP or other application security certifications.
  • Technical Skills: Proficiency with security testing tools such as Burp Suite (required), and familiarity with Snyk, HCL AppScan, Fority, and Postman (preferred). Strong understanding of secure coding practices and hands‑on experience with at least one programming language. Familiarity with DevSecOps practices and CI/CD pipelines is preferred.
  • Knowledge: In-depth knowledge of application security principles and practices, with strong familiarity with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Understanding of common vulnerability classes, exploitation techniques, and remediation strategies. Knowledge of Qatar National Information Assurance (NIA) is a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security
Application Security

Employment • Doha

On-site
QAR 180,000 - 300,000
Application Security Specialist
Application Security Specialist

Employment • Doha

On-site
QAR 240,000 - 360,000
None
IT Application Security Specialist
IT Application Security Specialist

Employment • Doha

On-site
QAR 320,000 - 520,000
Application Security Engineer: Pen Testing & DevSecOps
Application Security Engineer: Pen Testing & DevSecOps

Employment • Doha

On-site
QAR 240,000 - 360,000
None
Application Security Specialist - Pen Testing & Secure SDLC
Application Security Specialist - Pen Testing & Secure SDLC

Employment • Doha

On-site
QAR 180,000 - 300,000
Application Security Specialist: Pen Tests & DevSecOps
Application Security Specialist: Pen Tests & DevSecOps

malomatia • Doha

On-site
QAR 180,000 - 320,000
Security Analyst – VAPT & Penetration Testing
Security Analyst – VAPT & Penetration Testing

BSL • Al Rayyan

On-site
QAR 180,000 - 300,000
Security Analyst – VAPT & Penetration Testing
Security Analyst – VAPT & Penetration Testing

BAE Systems • Doha

On-site
QAR 180,000 - 300,000
Security Analyst – VAPT & Penetration Testing
Security Analyst – VAPT & Penetration Testing

BSL • Qatar

On-site
QAR 291,000 - 437,000
Application Security Consultant: Pen Tests & Secure Coding
Application Security Consultant: Pen Tests & Secure Coding

Malomatia • Doha

On-site
QAR 150,000 - 240,000