Application Security Engineer (AppSec Engineer)
Full-Time
Job Description
We are seeking an experienced
Application Security professional to assess, identify, and remediate security
vulnerabilities across web, mobile, and API applications. The role involves
conducting security assessments, penetration testing, secure code reviews,
threat modelling, vulnerability management, and integrating security practices
within the Software Development Lifecycle (SDLC)
- Role: Application Security Engineer (AppSec Engineer)
- Experience: 3-7 years
- Location: Qatar (On Site, 5 Days Working)
- Contract Duration: 8 months
Responsibilities
- Conduct Web Application, Mobile Application, and API Security Assessments.
- Perform Black Box, Grey Box, and Source Code Security Reviews.
- Execute Vulnerability Assessment and Penetration Testing (VAPT) activities.
- Identify, analyse, and validate security vulnerabilities in applications.
- Assess application security posture against OWASP Top 10, CWE, and industry security standards.
- Perform Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Conduct Threat Modelling and Risk Assessments for new and existing applications.
- Review Authentication, Authorization, Session Management, and Access Control mechanisms.
- Assess API security controls including authentication, authorization, rate limiting, and data exposure risks.
- Collaborate with development teams to remediate vulnerabilities and validate fixes through re-testing.
- Support Secure SDLC initiatives and security requirements during application development.
- Participate in security architecture reviews and provide recommendations for secure design.
- Coordinate with SOC, Infrastructure, Compliance, and WAF teams to ensure secure deployment and operation of applications.
- Review external VAPT reports and ensure appropriate remediation and risk closure.
- Maintain security assessment reports, dashboards, and vulnerability tracking metrics.
Stay updated with us
| Our Main Website | hrinsiderin.blogspot.com | |
| Follow on LinkedIn | linkedin.com/company/hrinsiderin | |
| Follow on Instagram | @hrinsiderin | |
| Join our WhatsApp Channel | Join Channel |
Minimum & preferred qualifications
Application Security (AppSec)
OWASP Top 10
VAPT / Penetration Testing
Secure Code Review
API Security
SAST, DAST, SCA
Threat Modelling
Secure SDLC / DevSecOps
Burp Suite, OWASP ZAP, Checkmarx, Fortify, Veracode
Preferred Certifications: OSCP, CEH, GWAPT, CSSLP, CISSP
Frequently asked questions
How do I apply for this position?
Click "Apply For Job" above. It will take you to the employer's official application page or open a mail draft to send your resume directly.
What documents do I need to apply?
You'll typically need an updated resume/CV. Some employers may also request a cover letter or supporting certificates, specified on the official application page.
How long does the hiring process usually take?
Timelines vary by employer and role, but most hiring processes take a few weeks from application to offer, including screening, interviews, and background checks.
Can I apply if I don't meet every requirement listed?
Yes. If you meet most of the core requirements and are confident in your ability to grow into the role, you're encouraged to apply. Employers often consider transferable skills and potential.
Will I be notified after I submit my application?
If you apply through the official career page, confirmation depends on the employer's process. If you submit your resume to us for future opportunities, we'll keep it on file and reach out when a matching role opens up.