Application Security Engineer
4 weeks ago
You will be working in a fast pacedDevSecOps environment where code change happens at a rapid speedand where it is paramount to control security testing into acontinuous deployment/integrationflow.
In this Role,you'll get to:
- Play a lead role in developing anddesigning application-level security controls andstandards.
- Perform application security designreviews against new products andservices.
- Track and prioritize all securityissues.
- Build internal security tools that helpfix security problems at scale.
- Perform codereview and drive remediation of discoveredissues.
- Enable automated security testing atscale to measure vulnerability, and report on risk across allmicroservice, web and mobile platforms.
- Executesecurity tests on thousands of servers which are spread acrosson-premise and public cloud data centers.
What you'llNeed to Succeed:
- Strong foundations in softwareengineering.
- Minimum of 7 years of technicalexperience with any combination of the following: threat modelingexperience, secure coding, identity management and authentication,software development, cryptography, system administration andnetwork security.
- Minimum 2 years experiencewith Software Development Life Cycle in one or more languages(Rust, Python, Go, Nodejs, etc.)
- Minimum 1 yearexperience with public/private cloud environments (Openshift,Rancher, K8s, AWS, GCP, Azure, etc.)
- Experiencein running assessments using OWASP MASVS andASVS
- Working knowledge on exploiting and fixingapplication vulnerabilities
- Strong backgroundin threat modeling
- In-depth knowledge of commonweb application vulnerabilities (i.e. OWASP Top10)
- Familiarity with automated dynamicscanners, fuzzers, and proxy tools
- Ananalytical mind for problem solving, abstract thought, andoffensive security tactics
- Highly effectivecommunication skills, in both verbal and written forms, toeffectively convey technical and non-technical concepts to a widevariety of audiences
- Relocation package isprovided in case you prefer to relocate to Bangkok, Thailand. Ourbenefits are…
- Hybrid WorkingModel
- WFH Set UpAllowance
- 30 Days of Remote Working fromanywhere globally every year
- Employee discountfor accommodation globally
- Global team of 90+nationalities
- 40+ offices and 25+countries
- Annual CSR / Volunteer Timeoff
- Benevity Subscription for employeedonations
- Volunteering opportunitiesglobally
- Free Headspacesubscription
- Free Odilo & Udemysubscriptions
- Access to Employee AssistanceProgram (third party for personal and workplacesupport)
- Enhanced ParentalLeave
- Life, TPD & AccidentInsurance
Security Testing andVulnerabilityAssessment:
- StaticApplication Security Testing (SAST): Perform staticcode analysis to identify security vulnerabilities in the sourcecode early in the development lifecycle, before the code isexecuted.
- Dynamic ApplicationSecurity Testing (DAST): Use automated tools andmanual techniques to simulate attacks on running applications toidentify vulnerabilities such as SQL injection, cross-sitescripting (XSS), and insecure datastorage.
- PenetrationTesting: Conduct manual and automated penetrationtesting to exploit vulnerabilities in applications and reportfindings. This helps simulate real-world cyberattacks to assess therobustness of securitymeasures.
- ThreatModeling: Work with development teams to conductthreat modeling exercises, identifying potential security threatsand weaknesses in the application's architecture anddesign.
VulnerabilityManagement:
- IdentifyingSecurity Flaws: Work with development and operationsteams to identify security flaws in applications and ensure thatthey are addressed beforerelease.
- PrioritizingVulnerabilities: Assess the severity and risk ofvulnerabilities, and provide guidance on which flaws to prioritizebased on the potential impact andexploitability.
- Fixing andMitigating Vulnerabilities: Collaborate withdevelopers to implement fixes for identified vulnerabilities,ensuring that the necessary patches are applied withoutcompromising applicationfunctionality.
SecurityDesign andArchitecture:
- SecureCode Practices: Promote the adoption of securecoding practices and provide guidance on writing secure code toprevent vulnerabilities from being introduced duringdevelopment.
- SecurityArchitecture: Ensure that security is incorporatedinto the software architecture, including secure authenticationmechanisms, encryption, and secure accesscontrols.
- Integrating SecurityTools: Work with DevOps teams to integrate securitytools into the continuous integration/continuous deployment (CI/CD)pipeline to automatically test applications for vulnerabilitiesthroughoutdevelopment.
IncidentResponse andInvestigation:
- Respondingto Security Incidents: Investigate applicationsecurity incidents, including security breaches, data leaks, andexploitation of vulnerabilities. Work with incident response teamsto contain and mitigatedamage.
- Post-IncidentAnalysis: Conduct post-incident reviews to identifywhat went wrong and recommend improvements to prevent similarincidents in thefuture.
ComplianceandStandards:
- RegulatoryCompliance: Ensure that applications comply withrelevant regulations and industry standards (e.g.,GDPR,HIPAA, PCIDSS) to protect sensitive data and ensureprivacy.
- SecurityAudits: Participate in or conduct internal andexternal security audits to evaluate the effectiveness of securitycontrols and identify areas forimprovement.
- Security BestPractices: Advocate for security best practiceswithin the development process, ensuring that the product is securebydesign.
TrainingandAwareness:
- DeveloperTraining: Conduct training sessions for developersto educate them on secure coding practices, common vulnerabilities(e.g., OWASP Top 10), and securitytools.
- AwarenessPrograms: Raise awareness about security issuesacross the development team and organization, encouraging a cultureof security-consciousdevelopment.
SecurityAutomation:
- AutomatingSecurity Testing: Implement automated securitytesting tools and scripts to scan for vulnerabilities continuouslyas part of the developmentpipeline.
- ContinuousMonitoring: Set up systems to continuously monitorapplications for new vulnerabilities or security threats, ensuringthat they remain secure even afterdeployment.
ApplicationManagement,Application Support,Information System
Employment Type : Full-time
Department / Functional Area: ApplicationDevelopment
Experience: NotMentioned years
Gender: Male
Vacancy: 1
Joining Date: Fri, 07 Feb 2025
-
Application Security Engineer
4 weeks ago
Dubai, Dubai, United Arab Emirates Agoda Full timeRoles and responsibilities You will be working in a fast-paced DevSecOps environment where code change happens at a rapid speed and where it is paramount to control security testing into a continuous deployment/integration flow.In this Role, you'll get to: Play a lead role in developing and designing application-level security controls and standards....
-
Application Security Engineer
5 days ago
Dubai, Dubai, United Arab Emirates Agoda Full timeRoles and responsibilities You will be working in a fast paced DevSecOps environment where code change happens at a rapid speed and where it is paramount to control security testing into a continuous deployment/integration flow.In this Role, you'll get to: Play a lead role in developing and designing application-level security controls and standards.Perform...
-
Mobile Application Security Engineer
3 weeks ago
Dubai, Dubai, United Arab Emirates Binance Full timeBinance is the leading global blockchain ecosystem and cryptocurrency infrastructure provider whose suite of financial products includes the world's largest digital-asset exchange. Our mission is to accelerate cryptocurrency adoption and increase the freedom of money. If you're looking for a fast-paced, mission-driven organization where opportunities to...
-
Application Security Engineer
2 weeks ago
Dubai, Dubai, United Arab Emirates Agoda Full timeRoles and responsibilitiesYou will be working in a fast pacedDevSecOps environment where code change happens at a rapid speedand where it is paramount to control security testing into acontinuous deployment/integrationflow.In this Role,you'll get to:Play a lead role in developing anddesigning application-level security controls andstandards.Perform...
-
Application Security Engineer
7 days ago
Dubai, Dubai, United Arab Emirates Agoda Full timeRoles and responsibilities You will be working in a fast pacedDevSecOps environment where code change happens at a rapid speedand where it is paramount to control security testing into acontinuous deployment/integrationflow.In this Role,you'll get to: Play a lead role in developing anddesigning application-level security controls andstandards. Perform...
-
Application Security Specialist
4 weeks ago
Dubai, Dubai, United Arab Emirates EDARI Uae Full timeResponsibilities:Explore cutting-edge techniques, develop innovative methodologies, and advance the practice of secure and safe AI development.Take the lead in closing application security vulnerabilities and resolving related issues.Formulate and implement a tailored application security architecture across the company.Draft guidelines for hardening...
-
Application Security Architect
3 weeks ago
Dubai, Dubai, United Arab Emirates ARRISE Full timeAbout Us:ARRISE sets the benchmark for service delivery and excellence in the iGaming industry. Playing a key role in the success of its clients, which include Pragmatic Play, a brand relied upon by the world's biggest online casinos for its cutting-edge products, ARRISE helps to deliver exceptional gaming experiences to millions of players worldwide.Our...
-
Mobile Application Security Specialist
44 minutes ago
Dubai, Dubai, United Arab Emirates Netsentries Full timeJob DescriptionNetsentries is seeking an experienced Mobile Application Penetration Tester & Source Code Review Specialist to join our team. This role will involve performing code-aware security assessments, threat modeling, SAST, SCA, and security engineering reviews of enterprise Web/Mobile applications on various platforms developed in different...
-
Security Engineer
3 weeks ago
Dubai, Dubai, United Arab Emirates LanceSoft UAE Full timeDirect message the job poster from LanceSoft UAEExecutive EMEA recruitment & delivery | @lancesoftuae | Technical recruitment | IT Recruitment | Delivery | Naukri certified | LinkedIn CertifiedWe have a new opportunity for Security Engineer with our client. Interested candidates send me your CV to ashwitha.sharukhan@lancesoft.comDuration: 12+ Months...
-
IT Security Engineer
4 days ago
Dubai, Dubai, United Arab Emirates Mackenzie Jones Middle East Full timeOur Client is looking for an experienced IT Security Engineer with deep expertise in infrastructure security and a strong background in designing and implementing comprehensive security solutions in the cloud. The ideal candidate will have extensive experience in network security, firewall management, and ensuring compliance with enterprise security...
-
Lead Process Engineer
21 hours ago
Dubai, Dubai, United Arab Emirates The Chemical Engineer Full timeJOB DESCRIPTION Wood is currently recruiting for Lead Process Engineer to strengthen our team in Dubai with occasional trips to Basra, South of Iraq RESPONSIBILITIES Overview & ResponsibilitiesThe Lead Process Engineer is engaged in the design, preparation of specification, data sheets and analysis of Process engineering requirements on a project.Review and...
-
Security engineer
2 days ago
Dubai, Dubai, United Arab Emirates BlackStone eIT Full timeAt BlackStone eIT, we are seeking a highly motivated Security Engineer to join our talented team. As a Security Engineer, you will be responsible for protecting our systems and infrastructure from cyber threats. You will work closely with various departments to ensure our security practices meet industry standards and regulatory requirements.Your primary...
-
Physical Security Engineer
4 weeks ago
Dubai, Dubai, United Arab Emirates AtkinsRéalis Full timeAbout AtkinsRéalisCreated by the integration of long-standing organizations dating back to 1911, AtkinsRéalis is a world-class engineering services and nuclear company dedicated to engineering a better future for our planet and its people. We create sustainable solutions that connect people, data and technology to transform the world's infrastructure and...
-
Application Security Specialist
18 hours ago
Dubai, Dubai, United Arab Emirates Dubaicareers Full timeAs a key member of the Dubaicareers team, you will play a crucial role in ensuring the security and integrity of our systems and data. We are seeking an experienced Application Security Specialist to join our Information Security team.About the RoleThe successful candidate will be responsible for coordinating administrative aspects of information security...
-
Security Software Engineer
4 weeks ago
Dubai, Dubai, United Arab Emirates Canonical Full timeRoles and responsibilities Define, implement and document new security features Lead security-oriented thinking in a product engineering team Analyze, fix, and test vulnerabilities in Canonical and open source Software Contribute to Ubuntu and upstream projects to benefit the community Audit and analyze source code for vulnerabilities Integrate new tools in...
-
Security Software Engineer
5 days ago
Dubai, Dubai, United Arab Emirates Canonical Full timeRoles and responsibilities Define, implement and document new security featuresLead security-oriented thinking in a product engineering teamAnalyze, fix, and test vulnerabilities in Canonical and open source SoftwareContribute to Ubuntu and upstream projects to benefit the communityAudit and analyze source code for vulnerabilitiesIntegrate new tools in our...
-
Consultant - Security Engineer
21 hours ago
Dubai, Dubai, United Arab Emirates NetSentries Technologies Full timeThe role involves managing cyber security, incident response, and system monitoring, requiring knowledge of security tools, risk assessments, and relevant certifications.Develop and implement security measures, conduct vulnerability assessments, and manage incident response while possessing expertise in various security tools and standards.Seeking a skilled...
-
Security Engineer
3 weeks ago
Dubai, Dubai, United Arab Emirates Hashtagweb3 Full timeNote to all applicants: We are a remote-first team, however, the majority of our employees are based in the EMEA region, so we have a preference for candidates who can work remotely in the EMEA time zones. Please also note: as a team who are looking to lead the way in Web 3, we require all applicants to have previous experience in the Web 3 / Blockchain...
-
Web Application Engineer
5 days ago
Dubai, Dubai, United Arab Emirates Teachmecode Full timeWe are looking for an experienced Web Application Engineer to join our team at TeachMeCode Institute in Dubai. The ideal candidate will have a strong background in web application development, with a focus on building secure, scalable, and efficient web applications using PHP, MySQL, and Laravel.Key responsibilities include:Designing and developing web...
-
Physical Security Engineer
3 weeks ago
Dubai, Dubai, United Arab Emirates AtkinsRéalis Full timeAbout AtkinsRéalis Created by the integration of long-standing organizations dating back to 1911, AtkinsRéalis is a world-class engineering services and nuclear company dedicated to engineering a better future for our planet and its people. We create sustainable solutions that connect people, data and technology to transform the world's infrastructure and...