Halian | Managed Services, Recruitment Agency & Contract Staffing

Senior Web Application Security Engineer

Halian | Managed Services, Recruitment Agency & Contract Staffing

Abu Dhabi Emirate, United Arab Emirates · Full Time

Be the first to apply

Experience
5+ yrs
Salary
Openings
1
Posted
17 hours ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

This position requires a seasoned security professional dedicated to evaluating and enhancing the security of intricate web applications, APIs, authentication frameworks, and digital platforms. The main objective is to detect weaknesses, validate security measures, and lead actions to safeguard essential business processes and confidential information from evolving cyber threats.

Primary Duties

  • Conduct thorough manual and automated penetration testing on web applications, APIs, microservices, and external-facing services.
  • Uncover vulnerabilities connected to authentication, user permissions, session integrity, input verification, and API protection.
  • Evaluate systems in relation to established security standards and industry best practices.
  • Analyze security protocols related to file operations including uploading, downloading, storage management, and processing workflows.
  • Detect risks involved with malicious file handling, content checks, storage segregation, and potential data leaks.
  • Verify role-based and attribute-driven access policies across varied user groups and permission hierarchies.
  • Spot authorization flaws like insecure direct object references, permission escalations, and unauthorized data retrieval.
  • Examine segregation and isolation tactics within shared operational environments.
  • Audit identity and authentication frameworks, with emphasis on OAuth 2.0, OpenID Connect (OIDC), SAML, and JWT implementations.
  • Test token validation processes, session management protocols, replay attack defenses, and identity federation security.
  • Identify vulnerabilities in identity lifecycle oversight and access governance.
  • Inspect key business workflows for logical errors, abuse scenarios, race conditions, and automation gaps.
  • Assess effectiveness of rate-limiting and protective measures against fraud, misuse, and unauthorized transaction alteration.
  • Generate detailed, prioritized risk-based security assessment reports and collaborate on mitigation strategies.
  • Work closely with relevant teams to confirm resolution effectiveness and perform follow-up security validations.
  • Advocate and contribute to secure coding and software delivery lifecycle practices.

Required Expertise

  • At least five years of practical experience conducting penetration testing on web applications and APIs.
  • Comprehensive knowledge of current attack methodologies and security assessment techniques.
  • In-depth familiarity with OWASP Top 10, OWASP API Security Top 10, and OWASP Web Security Testing Guide (WSTG).
  • Proficiency in threat modeling and risk-focused security evaluations.
  • Advanced skills with tools such as Burp Suite Professional, Postman, and other web/API testing utilities.
  • Expertise in identity and access management security, especially vulnerabilities in OAuth 2.0, OIDC, JWT, and SAML 2.0.
  • Strong understanding of secure file handling, including processing, archive analysis, storage isolation, and content validation.

Preferred Qualifications

  • Experience evaluating file-scanning, malware detection, or Content Disarm and Reconstruction (CDR) technologies.
  • Knowledge of automated security testing and vulnerability tools like Nuclei, Semgrep, and OWASP ZAP.
  • Familiarity with cloud security controls on AWS, Azure, and Google Cloud Platform.
  • Understanding of secure design principles for internet-facing applications and distributed systems.
  • Certifications such as Offensive Security Certified Professional (OSCP), Offensive Security Web Expert (OSWE), and Burp Suite Certified Practitioner (BSCP) are advantageous.

Location & Employment

This is a full-time onsite role based in Abu Dhabi, United Arab Emirates.

Level

Senior

Tools & software

Postman required

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help