IT Application Security Specialist

Employment

Doha

On-site

QAR 320,000 - 520,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Employment seeks an IT Application Security Specialist to design, implement and govern application security across enterprise systems. You will drive Dev Sec Ops, integrate security into SDLC, and establish secure architecture standards across cloud, on-premises and hybrid environments.

Key activities include threat modeling, secure design pattern enforcement, CI/CD security tooling, and collaboration with SOC for threat detection and incident response.

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, or related field.
  • 8–12 years in cybersecurity with focus on application security and DevSecOps.

Responsibilities

  • Develop and govern enterprise Application Security program and secure-by-design principles.
  • Design and review secure architectures for applications, APIs, and microservices.
  • Lead threat modeling activities and enforce secure design patterns (authn, encryption).
  • Integrate security controls into CI/CD pipelines and manage SAST/DAST/SCA tools.
  • Design secure cloud architectures (AWS/Azure) with IAM and Zero Trust principles.
  • Coordinate vulnerability assessments, remediation, and security testing.
  • Collaborate with SOC, support SIEM use case development and monitoring.
  • Ensure compliance with PCI DSS, ISO 27001 and other standards; audits support.

Skills

OWASP Top 10
Threat Modeling
DevSecOps
Secure SDLC
Cloud Security
Kubernetes/OpenShift
SIEM
Vulnerability Management
Security Architecture
Secure Coding Practices

Education

Bachelor's degree in Computer Science/Cybersecurity/Software Engineering

Tools

SAST
DAST
SCA
Kubernetes/OpenShift
AWS
Azure
CI/CD Security Tools
Threat Modeling Tools

Job description

Position Title:IT Application Security Specialist Department:Information Security / Cybersecurity

Job Purpose: The Application Security Architect is responsible for designing, implementing, and governing application security across enterprise systems, ensuring that all applications are secure by design and compliant with organizational and regulatory requirements.

The role focuses on integrating security into the Software Development Lifecycle (SDLC), driving Dev Sec Ops practices, and establishing secure architecture standards across cloud, on-premises, and hybrid environments.

Key Responsibilities
  • Application Security Strategy Develop and maintain the enterprise Application Security program Define and implement secure-by-design principles across all applications Establish and monitor key security metrics (e.g., vulnerability reduction, remediation timelines) Continuously improve application security maturity
  • Security Architecture & Design Design and review secure architectures for applications, APIs, and microservices Lead threat modeling activities (e.g., STRIDE methodology) Define and enforce security design patterns, including authentication, encryption, and data protection Participate in architecture governance and review forums
  • Dev Sec Ops & Secure SDLC Integrate security controls into CI/CD pipelines Implement and manage application security testing tools (SAST, DAST, SCA) Establish secure coding standards aligned with OWASP Top 10 Automate security validation and enforcement across development pipelines
  • Cloud Security Design and implement secure cloud architectures across AWS and/or Azure environments Enforce Identity and Access Management (IAM) and Zero Trust principles Secure containerized environments (Kubernetes / Open Shift) Ensure effective monitoring, logging, and threat detection in cloud platforms
  • Security Testing & Assurance Coordinate vulnerability assessments, penetration testing, and application security reviews Ensure timely remediation and closure of identified vulnerabilities Validate security controls through regular testing and simulation exercises
  • Security Operations Integration Collaborate with SOC teams to enhance monitoring and incident response capabilities Support SIEM use case development and optimization Analyze security trends and proactively identify emerging risks
  • Governance, Risk & Compliance Ensure adherence to security standards and regulatory requirements, including:PCI DSSSWIFT CSPISO 27001 Support internal and external audits and regulatory assessments Develop and maintain security policies, standards, and procedures
  • Stakeholder Engagement & Awareness Provide security guidance to development, Dev Ops, and architecture teams Conduct training and awareness sessions on secure coding practices Act as a trusted advisor on application security matters
Qualifications & Experience

Bachelor’s degree in computer science, Cybersecurity, Software Engineering, or a related field Minimum 8-12 years of experience in cybersecurity, with strong focus on: Application Security Dev Sec Ops Cloud Security Experience in the banking or financial services sector preferred

Required Skills & Competencies
  • Technical Skills: Strong knowledge of: OWASP Top 10 and secure coding practices Secure SDLC and threat modeling techniques API and web application security Experience with application security tools: SAST, DAST, and SCA platforms Proficiency in cloud security (AWS / Azure) Knowledge of container security (Kubernetes / Open Shift) Familiarity with SIEM, vulnerability management, and security monitoring
  • Behavioral Competencies: Strong analytical and problem-solving skills Effective communication and stakeholder management Ability to influence cross-functional teams Strong attention to detail and risk awareness
  • Professional Certifications: Required (Minimum 2): CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) CISM or CRISC Preferred: CEH (Certified Ethical Hacker) Microsoft Azure Security Engineer (AZ-500) or AWS Security Specialty OSCP (Offensive Security Certified Professional)
Additional Information

This role requires close collaboration with development, infrastructure, and security teams The position involves both strategic planning and hands-on technical contributions Experience in regulated environments is highly desirable

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security
Application Security

Employment • Doha

On-site
QAR 180,000 - 300,000
Application Security Specialist
Application Security Specialist

Employment • Doha

On-site
QAR 240,000 - 360,000
None
Senior Application Security Architect (DevSecOps)
Senior Application Security Architect (DevSecOps)

Employment • Doha

On-site
QAR 320,000 - 520,000
Security Analyst - IT Ops
Security Analyst - IT Ops

Mekdam Technical Services • Doha

On-site
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Employment • Doha

On-site
QAR 360,000 - 600,000
Application Security Engineer: Pen Testing & DevSecOps
Application Security Engineer: Pen Testing & DevSecOps

Employment • Doha

On-site
QAR 240,000 - 360,000
None
Principal Information Security Assurance Engineer/Specialist
Principal Information Security Assurance Engineer/Specialist

beIN MEDIA GROUP • Doha

On-site
QAR 180,000 - 240,000
Technical Project Manager (Cybersecruity)
Technical Project Manager (Cybersecruity)

BAE Systems • Doha

On-site
QAR 250,000 - 550,000
Cloud Security Specialist
Cloud Security Specialist

TAQAT • Doha

On-site
QAR 180,000 - 300,000
IT Security Specialist
IT Security Specialist

Employment • Doha

On-site
QAR 180,000 - 300,000