الوصف الوظيفي
نحن نبحث عن
كبير مهندسي أمن التطبيقات ماهر للانضمام إلى فريق الأمن السيبراني لدينا. في هذا الدور، ستعمل عن كثب مع فرق أمن التطبيقات والتطوير وضمان الجودة لتأمين تطبيقات عملائنا طوال دورة حياتها الكاملة. ستجري اختبارات الأمان، وتنفذ اختبارات الاختراق، وتقيم الثغرات الأمنية عبر تطبيقات الويب والمحمول وواجهات برمجة التطبيقات (APIs).
ستشمل مسؤولياتك اختبار اختراق التطبيقات، والفحص الأمني الآلي (SAST, DAST, SCA)، ونمذجة التهديدات، ومراجعة البرمجيات الآمنة، وتمكين المطورين. ستعمل على دمج أفضل ممارسات الأمان عبر دورة حياة تطوير البرمجيات وضمان تصميم التطبيقات وبنائها باستخدام ضوابط أمنية قوية.
ستتعاون مع فرق التطوير وDevOps لدمج الأمان في أنابيب CI/CD، وفرز النتائج والتحقق منها، تقديم إرشادات علاجية واضحة وقابلة للتنفيذ. يتطلب هذا الدور خبرة تقنية عملية، ومهارات تحليلية قوية، والقدرة على ترجمة نتائج الأمن المعقدة إلى إصلاحات عملية يمكن للمطورين تنفيذها.
المسؤوليات
- اختبار الاختراق: إجراء اختبارات الاختراق على تطبيقات الويب، وتطبيقات المحمول، وواجهات برمجة التطبيقات (APIs)، وتطبيقات العميل السميك (thick-client). إعداد تقارير تفصيلية مع تصنيفات مخاطر واضحة وتوصيات معالجة قابلة للتنفيذ.
- الفحص الأمني: تطبيق وضبط وإدارة أدوات الفحص الأمني الآلية (SAST, DAST, SCA) للتعرف باستمرار على الثغرات في الكود والتكوينات والاعتماديات الخارجية عبر جميع أنواع التطبيقات.
- نمذجة التهديدات: تنفيذ نمذجة التهديدات لتحديد المخاطر الأمنية المحتملة ونطاقات الهجوم المرتبطة بالتطبيقات في مرحلة مبكرة من عملية التصميم، وتقديم الإرشادات للتخفيف من هذه المخاطر.
- مراجعة الكود البرمجي الآمن: مراجعة الشفرة المصدرية للتطبيق بحثًا عن الثغرات الأمنية عبر منصات ولغات متعددة، وتقديم توصيات عملية وسهلة التنفيذ للمطورين للمعالجة.
- تكامل DevSecOps: دمج اختبارات وضوابط الأمان في أنابيب CI/CD، مما يسمح بالتحقق الأمني المستمر والآلي كجزء من سير عمل التطوير.
- التعليم والتوعية: تطوير تقديم دورات تدريبية وورش عمل حول الترميز الآمن لزيادة الوعي بأمن التطبيقات بين فرق التطوير وأصحاب المصلحة الآخرين.
- تقييم الأدوات: تقييم والتوصية بالأدوات والتقنيات لتعزيز قدرات اختبار أمن التطبيقات ومراقبتها عبر المنصات المختلفة.
- التوثيق: إنشاء وصيانة توثيق شامل يتعلق بالتقييمات الأمنية، وإدارة الثغرات الأمنية، ومعايير وسياسات أمن التطبيقات.
المؤهلات
- التعليم: درجة البكالوريوس / الجامعية في علوم الحاسوب، أو أمن المعلومات، أو مجال ذي صلة.
- الخبرة: خبرة لا تقل عن 4 سنوات في أمن التطبيقات، أو التطوير الآمن للبرمجيات، أو اختبار الاختراق، أو مجال وثيق الصلة.
- الشهادات: الشهادات المهنية ذات الصلة مرغوبة بشدة. قد تشمل هذه، على سبيل المثال لا الحصر:
- شهادات OffSec (مثل OSWA و OSWE)
- eLearnSecurity (مثل eWPT و eWPTX)
- GIAC / SANS (مثل SEC542 و GWAPT)
- شهادات BCSP أو شهادات أمن التطبيقات الأخرى.
- المهارات التقنية: إتقان أدوات اختبار الأمان مثل Burp Suite (مطلوب)، والمعرفة بأدوات Snyk و HCL AppScan و Fortify و Postman (يفضل). فهم قوي لممارسات الترميز الآمن وخبرة عملية في لغة برمجية واحدة على الأقل. يفضل وجود دراية بممارسات DevSecOps وأنابيب CI/CD.
- المعرفة: معرفة عميقة بمبادئ وممارسات أمن التطبيقات، مع دراية قوية بأطر عمل وإرشادات الأمان (مثل OWASP Top 10 و ASVS و MASVS و WSTG و MSTG). فهم فئات الثغرات الشائعة، وتقنيات الاستغلال، واستراتيجيات المعالجة. المعرفة بالمعايير الوطنية لتأمين المعلومات في قطر (NIA) تعتبر ميزة إضافية.
Job Description
We are seeking a skilled
Application Security Senior Engineer to join our Cybersecurity Practice. In this role, you will work closely with our application security, development, and QA teams to secure our clients’ applications across their entire lifecycle. You will conduct security testing, perform penetration tests, and assess vulnerabilities across web, mobile, API applications.
Your responsibilities will span application penetration testing, automated security scanning (SAST, DAST, SCA), threat modelling, secure code review, and developer enablement. You will embed security best practices throughout the software development lifecycle and ensure that applications are designed and built with robust security controls.
You will collaborate with development and DevOps teams to integrate security into CI/CD pipelines, triage and validate findings, and provide clear, actionable remediation guidance. The role requires hands-on technical expertise, strong analytical skills, and the ability to translate complex security findings into practical fixes that developers can implement.
Responsibilities
- Penetration Testing:Conduct penetration tests on web applications, mobile applications, APIs, and thick-client applications. Prepare detailed reports with clear risk ratings and actionable remediation recommendations.
- Security Scanning:Implement, tune, and manage automated security scanning tools (SAST, DAST, SCA) to continuously identify vulnerabilities in code, configurations, and third-party dependencies across all application types.
- Threat Modelling:Perform threat modelling to identify potential security risks and attack surfaces associated with applications early in the design process, and provide guidance on mitigating these risks.
- Secure Code Review:Review application source code for security vulnerabilities across multiple platforms and languages, and offer practical, developer-friendly recommendations for remediation.
- DevSecOps Integration:Integrate security testing and controls into CI/CD pipelines, enabling continuous and automated security validation as part of the development workflow.
- Training & Awareness:Develop and deliver secure coding training sessions and workshops to raise application security awareness among development teams and other stakeholders.
- Tool Evaluation:Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms.
- Documentation:Create and maintain comprehensive documentation related to security assessments, vulnerability management, and application security standards and policies.
Qualifications
- Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.
- Experience: At least 4 years of experience in application security, secure software development, penetration testing, or a closely related field.
- Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
- OffSec certifications (e.g., OSWA, OSWE)
- eLearnSecurity (e.g., eWPT, eWPTX)
- GIAC / SANS (e.g., SEC542, GWAPT)
- BCSP or other application security certifications.
- Technical Skills: Proficiency with security testing tools such as Burp Suite (required), and familiarity with Snyk, HCL AppScan, Fority, and Postman (preferred). Strong understanding of secure coding practices and hands-on experience with at least one programming language. Familiarity with DevSecOps practices and CI/CD pipelines is preferred.
- Knowledge: In-depth knowledge of application security principles and practices, with strong familiarity with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Understanding of common vulnerability classes, exploitation techniques, and remediation strategies. Knowledge of Qatar National Information Assurance (NIA) is a plus.