Application Security Expert
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We are looking for a seasoned Application Security Expert to evaluate and enhance the security posture of telecommunications products, applications, and platforms. This position will emphasize threat modeling, penetration testing, static and dynamic application security testing (SAST/DAST), secure code review, vulnerability analysis, and integration of security practices within DevSecOps frameworks targeting enterprise, telecom, and customer-facing software.
Key Responsibilities
- Conduct penetration tests on web applications, mobile apps, and APIs, alongside vulnerability assessments and security validations using both automated tools and manual techniques.
- Perform static and dynamic application security testing, software composition analysis, and secure code reviews, including analysis of false positives and negatives and validation of remediation efforts.
- Apply threat modeling and risk assessment methodologies such as STRIDE and DREAD for application security evaluation.
- Protect telecom applications, including BSS/OSS, CRM, Billing, Charging, Provisioning, Order Management, Subscriber Management, Self-Care portals, mobile applications, and APIs.
- Evaluate security across mobile networks like 4G/5G, EPC/5GC, IMS, API gateways, microservices, and network-facing software components.
- Integrate security controls and gates into continuous integration and deployment pipelines using tools like GitLab and Jenkins.
- Secure cloud-native architectures involving containers, Kubernetes, and Infrastructure-as-Code provisioning.
- Assist in analyzing application security incidents, identifying root causes, and recommending corrective actions.
- Assess security challenges related to AI/ML-based applications, APIs, and their data flows.
- Collaborate with developers, architects, DevOps, cloud teams, and cybersecurity professionals to embed security best practices throughout the software development lifecycle.
Required Skills & Experience
- Over 10 years of experience in Application Security or Cybersecurity with strong practical knowledge of application security.
- Demonstrated expertise in dynamic and static application security testing, penetration testing, and secure code evaluation.
- Extensive experience with telecommunications application security.
- Comprehensive understanding of standards and frameworks including OWASP Top 10, API Security, NIST, PCI DSS, and NIA.
- Hands-on proficiency with security tools such as Burp Suite, Metasploit, Kali Linux, SonarQube, Checkmarx, and Fortify.
- Experience using vulnerability scanners like Tenable, Qualys, or Rapid7.
- Strong knowledge of DevSecOps processes and tools including GitLab, Jenkins, Docker, Kubernetes, and Terraform.
- Experience in securing cloud environments such as AWS, Azure, or Google Cloud Platform.
- Familiarity with programming languages like Java, Python, JavaScript, .NET, or Ruby.
- Expertise in software composition analysis, CVE tracking, and security of third-party and open-source dependencies.
Preferred Certifications
Certifications such as CISSP, OSCP, CEH, CCSP, or equivalent are highly desirable.