Application Security Lead

Malomatia

Doha

On-site

QAR 180,000 - 280,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Malomatia is seeking an Application Security Engineer to join our Cybersecurity Practice in Doha. You will conduct penetration tests, secure code reviews, and integrate security across the software lifecycle for our clients' web, mobile, and API applications.

You will work with development and DevOps teams to embed security into CI/CD pipelines, perform automated scans (SAST/DAST/SCA), and provide actionable remediation guidance. Strong technical skills and communication are essential.

Qualifications

  • Bachelor’s degree in CS, Info Security, or related field.
  • Minimum 3 years in application security, secure SDLC, or pentesting.
  • Relevant certifications (OffSec OSWE/OSWA, GIAC/SANS, BCSP) desirable.

Responsibilities

  • Penetration Testing: Conduct tests on web, mobile, APIs, and thick-client apps with detailed reports and remediation.
  • Security Scanning: Implement and tune SAST/DAST/SCA to find vulnerabilities in code, configs, and dependencies.
  • Threat Modelling: Identify risks and attack surfaces early in design and advise mitigations.
  • Secure Code Review: Review source code for vulnerabilities and provide remediation guidance.
  • DevSecOps Integration: Integrate security into CI/CD pipelines for automated validation.
  • Training & Awareness: Deliver secure coding training to developers and stakeholders.
  • Tool Evaluation: Assess tools to improve security testing and monitoring.
  • Documentation: Maintain docs on assessments, vulnerability management, and standards.

Skills

Secure coding practices
CI/CD security integration
Threat modelling
Developer enablement
Security testing

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

Burp Suite
Snyk
HCL AppScan
Fortify
Postman

Job description

We are seeking a skilled Application Security Engineer to join our Cybersecurity Practice. In this role, you will work closely with our application security, development, and QA teams to secure our clients’ applications across their entire lifecycle. You will conduct security testing, perform penetration tests, and assess vulnerabilities across web, mobile and API applications.

Your responsibilities will span application penetration testing, automated security scanning (SAST, DAST, SCA), threat modelling, secure code review, and developer enablement. You will embed security best practices throughout the software development lifecycle and ensure that applications are designed and built with robust security controls.

You will collaborate with development and DevOps teams to integrate security into CI/CD pipelines, triage and validate findings, and provide clear, actionable remediation guidance. The role requires hands‑on technical expertise, strong analytical skills, and the ability to translate complex security findings into practical fixes that developers can implement.

Responsibilities
  • Penetration Testing:Conduct penetration tests on web applications, mobile applications, APIs, and thick-client applications. Prepare detailed reports with clear risk ratings and actionable remediation recommendations.
  • Security Scanning:Implement, tune, and manage automated security scanning tools (SAST, DAST, SCA) to continuously identify vulnerabilities in code, configurations, and third‑party dependencies across all application types.
  • Threat Modelling:Perform threat modelling to identify potential security risks and attack surfaces associated with applications early in the design process and provide guidance on mitigating these risks.
  • Secure Code Review:Review application source code for security vulnerabilities across multiple platforms and languages, and offer practical, developer‑friendly recommendations for remediation.
  • DevSecOps Integration:Integrate security testing and controls into CI/CD pipelines, enabling continuous and automated security validation as part of the development workflow.
  • Training & Awareness:Develop and deliver secure coding training sessions and workshops to raise application security awareness among development teams and other stakeholders.
  • Tool Evaluation:Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms.
  • Documentation:Create and maintain comprehensive documentation related to security assessments, vulnerability management, and application security standards and policies.
Qualifications
  • Education:Bachelor’s / college degree in Computer Science, Information Security, or a related field.
  • Experience:At least 3 years of experience in application security, secure software development, penetration testing, or a closely related field.
  • Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
    • OffSec certifications (e.g., OSWA, OSWE)
    • eLearnSecurity (e.g., eWPT, eWPTX)
    • GIAC / SANS (e.g., SEC542, GWAPT)
    • BCSP or other application security certifications.
  • Technical Skills:Proficiency with security testing tools such as Burp Suite (required), and familiarity with Snyk, HCL AppScan, Fority, and Postman (preferred). Strong understanding of secure coding practices and hands‑on experience with at least one programming language. Familiarity with DevSecOps practices and CI/CD pipelines is preferred.
  • Knowledge:In-depth knowledge of application security principles and practices, with strong familiarity with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Understanding of common vulnerability classes, exploitation techniques, and remediation strategies. Knowledge of Qatar National Information Assurance (NIA) is a plus.
About Us

About Malomatia

malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end‑to‑end technology solutions that empower clients to achieve their strategic goals.

Our mission

Empowering Qatar’s businesses and governments to leap into the digital future with agile, knowledge‑driven solutions.

Our vision

To become Qatar’s trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world‑class tech ecosystem.

Driving change that makes a real impact

Since 2008, malomatia has been driving Qatar’s digital transformation through innovative, ISO‑certified IT solutions. With expertise across key public and private sectors, we empower the nation’s vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar’s sustainable future.

About the Team

Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high‑value digital solutions tailored to the unique needs of our clients.

Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation.

Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high‑value digital solutions tailored to the unique needs of our clients.

Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation.

Join us in shaping the future of technology in Qatar

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Consultant - Application Security Doha, Qatar Posted on 08/31/2026 Trending
Consultant - Application Security Doha, Qatar Posted on 08/31/2026 Trending

Malomatia • Doha

On-site
QAR 150,000 - 240,000
Senior Consultant - Cybersecurity
Senior Consultant - Cybersecurity

Employment • Doha

On-site
QAR 180,000 - 240,000
Cloud Security Engineer
Cloud Security Engineer

Malomatia • Doha

On-site
QAR 180,000 - 300,000
Cloud Security Consultant
Cloud Security Consultant

Malomatia • Doha

On-site
QAR 180,000 - 320,000
F5/CloudFlare/LB/GTM- Network_Security_Engineer
F5/CloudFlare/LB/GTM- Network_Security_Engineer

Malomatia • Doha

On-site
QAR 180,000 - 280,000
Senior Network Security Engineer
Senior Network Security Engineer

Malomatia • Doha

On-site
QAR 320,000 - 520,000
Senior Consultant - Infrastructure Architecture Doha, Qatar Posted on 08/31/2026 Trending
Senior Consultant - Infrastructure Architecture Doha, Qatar Posted on 08/31/2026 Trending

Malomatia • Doha

On-site
QAR 300,000 - 600,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Malomatia • Doha

On-site
QAR 180,000 - 300,000
Senior Engineer - Network Security
Senior Engineer - Network Security

malomatia • Doha

On-site
QAR 240,000 - 360,000
Network_Security_Techinical_Lead
Network_Security_Techinical_Lead

Malomatia • Doha

On-site
QAR 150,000 - 190,000
On-call rotation
Travel to datacenter/client sites