A

Cyber Security Engineer - Web Application Security

APTWatch

Riyadh, Riyadh Province, Saudi Arabia · Part Time

Be the first to apply

Experience
Any
Salary
Openings
1
Posted
17시간 전
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

APTWatch is recruiting for a Cyber Security Engineer with expertise in Web Application Security to enhance their expanding technical team in Riyadh, Saudi Arabia. The main objective is to identify, evaluate, and mitigate security weaknesses in contemporary web applications, APIs, and related infrastructure.

Responsibilities

  • Conduct security assessments for web applications and APIs.
  • Perform vulnerability identification and penetration testing.
  • Detect and validate security flaws based on OWASP Top 10 and OWASP API Security Top 10 standards.
  • Evaluate mechanisms related to authentication, authorization, session management, and access controls.
  • Test for prevalent vulnerabilities including Cross-Site Scripting (XSS), SQL/NoSQL injections, Server-Side Request Forgery (SSRF), Insecure Direct Object References (IDOR), Cross-Site Request Forgery (CSRF), and unsafe file handling.
  • Conduct security examinations of RESTful APIs and modern web system architectures.
  • Collaborate with developers to replicate, prioritize, and remedy security issues.
  • Advocate for secure coding methods and security validation through the Software Development Life Cycle (SDLC).
  • Develop precise technical reports detailing vulnerabilities, risk appraisals, and remediation strategies.

Requirements

  • A Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a closely related discipline.
  • Practical experience in web security and penetration testing.
  • In-depth knowledge of HTTP/HTTPS protocols, REST APIs, authentication schemes, and fundamentals of web security.
  • Hands-on proficiency with security tools such as Burp Suite, OWASP ZAP, Nmap, and Postman.
  • Familiarity with Linux operating systems and scripting skills in Python, Bash, or comparable languages.
  • Understanding of modern application architecture including front-end and back-end components, APIs, databases, containers, and cloud environments.
  • Capability to document and articulate technical security findings effectively.

Preferred Qualifications

  • Knowledge or experience in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and DevSecOps methodologies.
  • Exposure to continuous integration/continuous deployment (CI/CD) security processes and container security.
  • Certifications such as OSCP, OSWE, eWPT, BSCP, or other relevant credentials are advantageous.

Additional Information

This position is based in Riyadh, Saudi Arabia and is a part-time onsite role. Interested applicants are encouraged to submit their resumes as specified.

Minimum education

Bachelor's Degree

Industry

Cybersecurity

Tools & software

Linux required Postman required Nmap required Burp Suite required

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer