Malomatia

Application Security

Malomatia · Doha, Qatar

IT Services and IT Consulting · 1,001-5,000 employees

7 h ago
Mid (2-5 yrs) Full-time Qatar
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The specialist will conduct security testing, penetration tests, and vulnerability assessments across web, mobile, and API applications. They will also collaborate with development and DevOps teams to integrate security into CI/CD pipelines and provide actionable remediation guidance.

What they look for

Application security Penetration testing Security testing Vulnerability assessment SAST DAST SCA Threat modelling Secure code review DevSecOps CI/CD pipelines Burp Suite OWASP Top 10 Secure coding Remediation

Requirements

Candidates must hold a bachelor's degree in Computer Science or a related field and possess at least 3 years of experience in application security or penetration testing. Proficiency with security testing tools like Burp Suite and knowledge of security frameworks such as OWASP are required.

Full description

We are seeking a skilled Application Security Specialist to join our Cybersecurity Practice. In this role, you will work closely with our application security, development, and QA teams to secure our clients’ applications across their entire lifecycle. You will conduct security testing, perform penetration tests, and assess vulnerabilities across web, mobile, API applications.

Your responsibilities will span application penetration testing, automated security scanning (SAST, DAST, SCA), threat modelling, secure code review, and developer enablement. You will embed security best practices throughout the software development lifecycle and ensure that applications are designed and built with robust security controls.

You will collaborate with development and DevOps teams to integrate security into CI/CD pipelines, triage and validate findings, and provide clear, actionable remediation guidance. The role requires hands-on technical expertise, strong analytical skills, and the ability to translate complex security findings into practical fixes that developers can implement.