Application Security Engineer

3 weeks ago


Dubai, Dubai, United Arab Emirates Agoda Full time
Roles and responsibilities

You will be working in a fast pacedDevSecOps environment where code change happens at a rapid speedand where it is paramount to control security testing into acontinuous deployment/integrationflow.

In this Role,you'll get to:

  • Play a lead role in developing anddesigning application-level security controls andstandards.
  • Perform application security designreviews against new products andservices.
  • Track and prioritize all securityissues.
  • Build internal security tools that helpfix security problems at scale.
  • Perform codereview and drive remediation of discoveredissues.
  • Enable automated security testing atscale to measure vulnerability, and report on risk across allmicroservice, web and mobile platforms.
  • Executesecurity tests on thousands of servers which are spread acrosson-premise and public cloud data centers.

What you'llNeed to Succeed:

  • Strong foundations in softwareengineering.
  • Minimum of 7 years of technicalexperience with any combination of the following: threat modelingexperience, secure coding, identity management and authentication,software development, cryptography, system administration andnetwork security.
  • Minimum 2 years experiencewith Software Development Life Cycle in one or more languages(Rust, Python, Go, Nodejs, etc.)
  • Minimum 1 yearexperience with public/private cloud environments (Openshift,Rancher, K8s, AWS, GCP, Azure, etc.)
  • Experiencein running assessments using OWASP MASVS andASVS
  • Working knowledge on exploiting and fixingapplication vulnerabilities
  • Strong backgroundin threat modeling
  • In-depth knowledge of commonweb application vulnerabilities (i.e. OWASP Top10)
  • Familiarity with automated dynamicscanners, fuzzers, and proxy tools
  • Ananalytical mind for problem solving, abstract thought, andoffensive security tactics
  • Highly effectivecommunication skills, in both verbal and written forms, toeffectively convey technical and non-technical concepts to a widevariety of audiences
  • Relocation package isprovided in case you prefer to relocate to Bangkok, Thailand. Ourbenefits are…
  • Hybrid WorkingModel
  • WFH Set UpAllowance
  • 30 Days of Remote Working fromanywhere globally every year
  • Employee discountfor accommodation globally
  • Global team of 90+nationalities
  • 40+ offices and 25+countries
  • Annual CSR / Volunteer Timeoff
  • Benevity Subscription for employeedonations
  • Volunteering opportunitiesglobally
  • Free Headspacesubscription
  • Free Odilo & Udemysubscriptions
  • Access to Employee AssistanceProgram (third party for personal and workplacesupport)
  • Enhanced ParentalLeave
  • Life, TPD & AccidentInsurance
Desired candidate profile
  • Security Testing andVulnerabilityAssessment:

    • StaticApplication Security Testing (SAST): Perform staticcode analysis to identify security vulnerabilities in the sourcecode early in the development lifecycle, before the code isexecuted.
    • Dynamic ApplicationSecurity Testing (DAST): Use automated tools andmanual techniques to simulate attacks on running applications toidentify vulnerabilities such as SQL injection, cross-sitescripting (XSS), and insecure datastorage.
    • PenetrationTesting: Conduct manual and automated penetrationtesting to exploit vulnerabilities in applications and reportfindings. This helps simulate real-world cyberattacks to assess therobustness of securitymeasures.
    • ThreatModeling: Work with development teams to conductthreat modeling exercises, identifying potential security threatsand weaknesses in the application's architecture anddesign.
  • VulnerabilityManagement:

    • IdentifyingSecurity Flaws: Work with development and operationsteams to identify security flaws in applications and ensure thatthey are addressed beforerelease.
    • PrioritizingVulnerabilities: Assess the severity and risk ofvulnerabilities, and provide guidance on which flaws to prioritizebased on the potential impact andexploitability.
    • Fixing andMitigating Vulnerabilities: Collaborate withdevelopers to implement fixes for identified vulnerabilities,ensuring that the necessary patches are applied withoutcompromising applicationfunctionality.
  • SecurityDesign andArchitecture:

    • SecureCode Practices: Promote the adoption of securecoding practices and provide guidance on writing secure code toprevent vulnerabilities from being introduced duringdevelopment.
    • SecurityArchitecture: Ensure that security is incorporatedinto the software architecture, including secure authenticationmechanisms, encryption, and secure accesscontrols.
    • Integrating SecurityTools: Work with DevOps teams to integrate securitytools into the continuous integration/continuous deployment (CI/CD)pipeline to automatically test applications for vulnerabilitiesthroughoutdevelopment.
  • IncidentResponse andInvestigation:

    • Respondingto Security Incidents: Investigate applicationsecurity incidents, including security breaches, data leaks, andexploitation of vulnerabilities. Work with incident response teamsto contain and mitigatedamage.
    • Post-IncidentAnalysis: Conduct post-incident reviews to identifywhat went wrong and recommend improvements to prevent similarincidents in thefuture.
  • ComplianceandStandards:

    • RegulatoryCompliance: Ensure that applications comply withrelevant regulations and industry standards (e.g.,GDPR,HIPAA, PCIDSS) to protect sensitive data and ensureprivacy.
    • SecurityAudits: Participate in or conduct internal andexternal security audits to evaluate the effectiveness of securitycontrols and identify areas forimprovement.
    • Security BestPractices: Advocate for security best practiceswithin the development process, ensuring that the product is securebydesign.
  • TrainingandAwareness:

    • DeveloperTraining: Conduct training sessions for developersto educate them on secure coding practices, common vulnerabilities(e.g., OWASP Top 10), and securitytools.
    • AwarenessPrograms: Raise awareness about security issuesacross the development team and organization, encouraging a cultureof security-consciousdevelopment.
  • SecurityAutomation:

    • AutomatingSecurity Testing: Implement automated securitytesting tools and scripts to scan for vulnerabilities continuouslyas part of the developmentpipeline.
    • ContinuousMonitoring: Set up systems to continuously monitorapplications for new vulnerabilities or security threats, ensuringthat they remain secure even afterdeployment.
Key Skills
ApplicationManagement,Application Support,Information System
Employment Type : Full-time
Department / Functional Area: ApplicationDevelopment
Experience: years
Gender: Male
Vacancy: 1

  • Dubai, Dubai, United Arab Emirates Agoda Full time

    Roles and responsibilitiesYou will be working in a fast paced DevSecOps environment where code change happens at a rapid speed and where it is paramount to control security testing into a continuous deployment/integration flow.In this Role, you'll get to:Play a lead role in developing and designing application-level security controls and standards.Perform...


  • Dubai, Dubai, United Arab Emirates Agoda Full time

    Roles and responsibilities You will be working in a fast paced DevSecOps environment where code change happens at a rapid speed and where it is paramount to control security testing into a continuous deployment/integration flow.In this Role, you'll get to: Play a lead role in developing and designing application-level security controls and standards....


  • Dubai, Dubai, United Arab Emirates Client of Talentmate Full time

    We are currently seeking a highly skilled Senior Application Security Engineer to join our dynamic team. The ideal candidate will be responsible for evaluating, implementing, and managing application security measures to protect our company's software and systems from potential cyber threats. Key responsibilities will include conducting security assessments,...


  • Dubai, Dubai, United Arab Emirates Binance Full time

    Binance is the leading global blockchain ecosystem and cryptocurrency infrastructure provider whose suite of financial products includes the world's largest digital-asset exchange. Our mission is to accelerate cryptocurrency adoption and increase the freedom of money. If you're looking for a fast-paced, mission-driven organization where opportunities to...


  • Dubai, Dubai, United Arab Emirates Oak HCFT Full time

    Rapyd has unified payments, payouts and fintech on one worldwide platform, and we're assembling the world's best team to liberate global commerce. With offices in Tel Aviv, Amsterdam, Singapore, Iceland, London, Dubai, Hong Kong, and the U.S., the opportunities at Rapyd are limitless.We believe in straight talk, quick decisions, strong execution and elegant...


  • Dubai, Dubai, United Arab Emirates Oak HCFT Full time

    Description Rapyd has unified payments, payouts and fintech on one worldwide platform, and we're assembling the world's best team to liberate global commerce. With offices in Tel Aviv, Amsterdam, Singapore, Iceland, London, Dubai, Hong Kong, and the U.S., the opportunities at Rapyd are limitless.We believe in straight talk, quick decisions, strong execution...


  • Dubai, Dubai, United Arab Emirates Agoda Full time

    Job SummaryWe are seeking an experienced Application Security Lead to join our team at Agoda. In this role, you will be responsible for leading the application security program and ensuring that all applications meet the highest standards of security and compliance.You will work closely with cross-functional teams to design and implement secure application...


  • Dubai, Dubai, United Arab Emirates ARRISE Full time

    About Us:ARRISE sets the benchmark for service delivery and excellence in the iGaming industry. Playing a key role in the success of its clients, which include Pragmatic Play, a brand relied upon by the world's biggest online casinos for its cutting-edge products, ARRISE helps to deliver exceptional gaming experiences to millions of players worldwide.Our...


  • Dubai, Dubai, United Arab Emirates Teachmecode Full time

    Job Description:We are seeking a highly skilled Senior Android Developer to enhance the security, performance, and reliability of our mobile application shield.The primary role will be to analyze and optimize existing Android codebases to prevent memory corruption, race conditions, and security vulnerabilities. This includes building and maintaining robust...

  • Security Engineer

    3 days ago


    Dubai, Dubai, United Arab Emirates Incode Full time

    The OpportunityWe are looking for a trustworthy and proactive Senior Security Engineer to be the technical thought leader and driver of holistic security operations across Incode. As an early security hire at Incode, you will work across the security operations lifecycle for detection engineering and incident response, influence the security operations...


  • Dubai, Dubai, United Arab Emirates Netsentries Full time

    Job DescriptionNetsentries is seeking an experienced Mobile Application Penetration Tester & Source Code Review Specialist to join our team. This role will involve performing code-aware security assessments, threat modeling, SAST, SCA, and security engineering reviews of enterprise Web/Mobile applications on various platforms developed in different...

  • Security Engineer

    4 weeks ago


    Dubai, Dubai, United Arab Emirates LanceSoft UAE Full time

    Direct message the job poster from LanceSoft UAEExecutive EMEA recruitment & delivery | @lancesoftuae | Technical recruitment | IT Recruitment | Delivery | Naukri certified | LinkedIn CertifiedWe have a new opportunity for Security Engineer with our client. Interested candidates send me your CV to ashwitha.sharukhan@lancesoft.comDuration: 12+ Months...


  • Dubai, Dubai, United Arab Emirates Agoda Full time

    Job Title: Cloud Security EngineerWe are looking for a skilled Cloud Security Engineer to join our team at Agoda. As a Cloud Security Engineer, you will be responsible for designing and implementing secure cloud-based systems and applications.You will work closely with cross-functional teams to ensure that cloud infrastructure and applications meet the...


  • Dubai, Dubai, United Arab Emirates Mackenzie Jones Middle East Full time

    Our Client is looking for an experienced IT Security Engineer with deep expertise in infrastructure security and a strong background in designing and implementing comprehensive security solutions in the cloud. The ideal candidate will have extensive experience in network security, firewall management, and ensuring compliance with enterprise security...

  • Security engineer

    7 days ago


    Dubai, Dubai, United Arab Emirates BlackStone eIT Full time

    At BlackStone eIT, we are seeking a highly motivated Security Engineer to join our talented team. As a Security Engineer, you will be responsible for protecting our systems and infrastructure from cyber threats. You will work closely with various departments to ensure our security practices meet industry standards and regulatory requirements.Your primary...


  • Dubai, Dubai, United Arab Emirates Schlumberger Full time

    Job Requirements">To be considered for this role, you must meet the following requirements:">">Familiarity with business systems, security processes, and application change cycles.">Well-versed in technologies used in designated applications and their security designs.">Ability to work independently with minimal supervision.">Excellent communication and...


  • Dubai, Dubai, United Arab Emirates Teachmecode Full time

    We are looking for an exceptional Android Engineer to join our team at ether.fi in Dubai. As a key member, you'll be responsible for designing, developing, and maintaining high-quality Android applications that meet the highest standards of security and performance.About Usether.fi is a rapidly growing Ethereum liquid staking protocol where stakeholders...


  • Dubai, Dubai, United Arab Emirates Lumina Tech Group Full time

    About the RoleLumina Tech Group is seeking a highly skilled Application Security Architect to join our team. This role combines technical expertise with strategic leadership to drive security-first initiatives that protect mission-critical applications.Key ResponsibilitiesDesign and implement comprehensive application security strategies aligned with...

  • Security Engineer

    2 days ago


    Dubai, Dubai, United Arab Emirates MIRA- Search Full time

    Our client is a hybrid trading exchange, merging CeFi and DeFi for a seamless trading experience. They are looking for a Security Engineer to strengthen our platform's security, safeguard smart contracts, and ensure the integrity of our backend infrastructure. This role is critical in mitigating risks, securing protocol releases, and proactively identifying...


  • Dubai, Dubai, United Arab Emirates Dubaicareers Full time

    As a key member of the Dubaicareers team, you will play a crucial role in ensuring the security and integrity of our systems and data. We are seeking an experienced Application Security Specialist to join our Information Security team.About the RoleThe successful candidate will be responsible for coordinating administrative aspects of information security...