Application Security Expert

Starlink Qatar

Doha

On-site

QAR 300,000 - 420,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Starlink Qatar seeks an experienced Application Security Expert to assess and strengthen the security of Telco products, applications and platforms, with a focus on threat modelling, penetration testing, DAST/SAST, secure code review and DevSecOps across enterprise and customer-facing systems.

You will lead hands-on testing across web, mobile and APIs, review third-party components, guide developers through secure SDLC, and integrate security gates into CI/CD pipelines using GitLab and Jenkins

Qualifications

  • 10+ years in Application Security or Cybersecurity.
  • Hands-on experience with DAST, SAST, and security testing.
  • Strong telecom/Telco security background.
  • Familiarity with OWASP Top 10, API Security and secure SDLC.

Responsibilities

  • Conduct web, mobile and API security testing and validation.
  • Perform threat modelling and security risk assessments.
  • Review code and secure software development lifecycle.
  • Integrate security controls into CI/CD pipelines (GitLab/Jenkins).
  • Secure cloud environments and containerized architectures.

Skills

Application Security
Threat Modelling
Penetration Testing
DAST
SAST
Secure Code Review
DevSecOps
GitLab
Jenkins
Kubernetes
Terraform
Cloud Platforms
CVE Mgmt

Tools

Burp Suite
Metasploit
Kali Linux
SonarQube
Checkmarx
Fortify

Job description

We are seeking an experienced Application Security Expert to assess and strengthen the security of Telco products, applications and platforms. The role will focus on threat modelling, penetration testing, DAST/SAST, secure code review, vulnerability assessment and DevSecOps across enterprise, telecom and customer-facing applications.

Key Responsibilities
  • Conduct web, mobile and API penetration testing, vulnerability assessments and security validation using both automated and manual techniques.
  • Perform SAST, DAST, SCA and secure code reviews, including false-positive/false-negative analysis and remediation validation.
  • Conduct threat modelling and application security risk assessments using methodologies such as STRIDE and DREAD.
  • Secure telecom applications including BSS/OSS, CRM, Billing, Charging, Provisioning, Order Management, Subscriber Management, Self-Care, Mobile Applications and APIs.
  • Assess security across 4G/5G, EPC/5GC, IMS, API Gateways, microservices and network-facing applications.
  • Integrate application security controls and security gates into CI/CD pipelines using GitLab and Jenkins.
  • Secure modern architectures involving cloud, containers, Kubernetes and Infrastructure-as-Code.
  • Support investigation of application security incidents, identify root causes and recommend remediation.
  • Assess security risks associated with AI/ML-enabled applications, APIs and data flows.
  • Work closely with developers, architects, DevOps, cloud and cybersecurity teams to embed security throughout the SDLC.
Required Skills & Experience
  • 10+ years of Application Security / Cybersecurity experience, with strong hands-on AppSec expertise.
  • Proven experience in DAST, SAST, penetration testing and secure code review.
  • Strong telecom/Telco application security experience.
  • Strong knowledge of OWASP Top 10, API Security, NIST, PCI DSS and NIA.
  • Hands-on experience with Burp Suite, Metasploit, Kali Linux, SonarQube, Checkmarx or Fortify.
  • Experience with Tenable, Qualys or Rapid7.
  • Strong DevSecOps experience with GitLab, Jenkins, Docker, Kubernetes and Terraform.
  • Experience securing AWS, Azure or GCP environments.
  • Strong knowledge of SCA, CVE management and third-party/open-source dependency security.
Preferred Certifications

CISSP | OSCP | CEH | CCSP or equivalent security certifications.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security
Application Security

malomatia • Doha

On-site
QAR 180,000 - 320,000
Application Security Specialist
Application Security Specialist

Employment • Doha

On-site
QAR 240,000 - 360,000
None
Application Security
Application Security

Employment • Doha

On-site
QAR 180,000 - 300,000
IT Application Security Specialist
IT Application Security Specialist

Employment • Doha

On-site
QAR 320,000 - 520,000
Application Security Engineer: Pen Testing & DevSecOps
Application Security Engineer: Pen Testing & DevSecOps

Employment • Doha

On-site
QAR 240,000 - 360,000
None
Senior Application Security Engineer - DevSecOps & Cloud
Senior Application Security Engineer - DevSecOps & Cloud

Starlink Qatar • Doha

On-site
QAR 300,000 - 420,000
Cyber Security Engineer
Cyber Security Engineer

Vistas Global • Doha

On-site
QAR 240,000 - 360,000
Technical Project Manager (Cybersecruity)
Technical Project Manager (Cybersecruity)

BSL • Doha

On-site
QAR 450,000 - 700,000
Security Analyst - IT Ops
Security Analyst - IT Ops

Mekdam Technical Services • Doha

On-site
QAR 334,800 - 502,200
Security Engineer (Tenable | Qualys | SIEM )
Security Engineer (Tenable | Qualys | SIEM )

Talent Leaders Inc. • Doha

On-site
QAR 223,200 - 334,800