Application Security Lead
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 3+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 12 seconds ago
- Work mode
- In office
- Education
- Bachelor’s / college degree in Computer Science or Information Security or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Summary
We are looking for a knowledgeable Application Security Engineer to strengthen our Cybersecurity Practice. In this role, you will collaborate closely with application security, development, and quality assurance teams to ensure robust security for client applications throughout their lifecycle. Your duties will include conducting security testing, penetration testing, and vulnerability assessments across web, mobile, and API platforms.
Key Responsibilities
- Carry out penetration tests on a variety of applications including web, mobile, APIs, and thick-client setups and produce detailed reports highlighting risks and actions to mitigate them.
- Manage and optimize automated security scanning tools such as SAST, DAST, and SCA to continuously detect vulnerabilities in code, configurations, and third-party dependencies.
- Perform threat modeling to identify security risks early in application design and advise on mitigation methods.
- Conduct secure code reviews across multiple platforms and languages, providing actionable, developer-oriented remediation recommendations.
- Integrate security controls and testing into CI/CD pipelines to facilitate continuous automated security validation.
- Develop and present secure coding training sessions to raise awareness among development teams and stakeholders.
- Evaluate and recommend security testing and monitoring tools for application security enhancement.
- Maintain comprehensive documentation on security assessments, vulnerability management, and security policies.
Qualifications and Skills
- Bachelor’s or college degree in Computer Science, Information Security, or a related discipline.
- A minimum of three years’ experience specializing in application security, secure software development, penetration testing, or a closely related field.
- Desirable certifications include OffSec credentials (OSWA, OSWE), eLearnSecurity certifications (eWPT, eWPTX), GIAC/SANS certifications (SEC542, GWAPT), BCSP, or other recognized application security qualifications.
- Technical proficiency with key tools such as Burp Suite (mandatory) and familiarity with Snyk, HCL AppScan, Fority, and Postman is preferred.
- Solid knowledge of secure coding principles and practical experience in at least one programming language.
- Understanding of DevSecOps concepts and CI/CD pipeline integration is advantageous.
- Well-versed in application security standards and frameworks, including OWASP Top 10, ASVS, MASVS, WSTG, and MSTG.
- Awareness of common vulnerabilities, attack methods, and remediation practices, with added value for knowledge of Qatar National Information Assurance guidelines.
About Malomatia
Malomatia is a premier IT services and solutions company based in Qatar, combining local and international expertise to deliver innovative technology solutions that empower clients to achieve strategic objectives. Since 2008, we have led digital transformation efforts in Qatar, offering ISO-certified solutions across sectors such as Government, Healthcare, Education, Customs, and Transportation.
Our mission is to enable businesses and governments in Qatar to accelerate their digital journeys with agile and knowledge-driven solutions. We aspire to become Qatar’s trusted knowledge partner in digital transformation, driving industry disruption and fostering a world-class technology ecosystem.
Our culture emphasizes ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation. We invite passionate professionals to join us in shaping the technological future of Qatar.
Minimum education
Bachelor's Degree