Cyber Security Engineer - Web Application Security
Riyadh, Riyadh Province, Saudi Arabia · Part Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 13 ਘੰਟੇ ਪਹਿਲਾਂ
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
APTWatch is recruiting for a Cyber Security Engineer with expertise in Web Application Security to enhance their expanding technical team in Riyadh, Saudi Arabia. The main objective is to identify, evaluate, and mitigate security weaknesses in contemporary web applications, APIs, and related infrastructure.
Responsibilities
- Conduct security assessments for web applications and APIs.
- Perform vulnerability identification and penetration testing.
- Detect and validate security flaws based on OWASP Top 10 and OWASP API Security Top 10 standards.
- Evaluate mechanisms related to authentication, authorization, session management, and access controls.
- Test for prevalent vulnerabilities including Cross-Site Scripting (XSS), SQL/NoSQL injections, Server-Side Request Forgery (SSRF), Insecure Direct Object References (IDOR), Cross-Site Request Forgery (CSRF), and unsafe file handling.
- Conduct security examinations of RESTful APIs and modern web system architectures.
- Collaborate with developers to replicate, prioritize, and remedy security issues.
- Advocate for secure coding methods and security validation through the Software Development Life Cycle (SDLC).
- Develop precise technical reports detailing vulnerabilities, risk appraisals, and remediation strategies.
Requirements
- A Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a closely related discipline.
- Practical experience in web security and penetration testing.
- In-depth knowledge of HTTP/HTTPS protocols, REST APIs, authentication schemes, and fundamentals of web security.
- Hands-on proficiency with security tools such as Burp Suite, OWASP ZAP, Nmap, and Postman.
- Familiarity with Linux operating systems and scripting skills in Python, Bash, or comparable languages.
- Understanding of modern application architecture including front-end and back-end components, APIs, databases, containers, and cloud environments.
- Capability to document and articulate technical security findings effectively.
Preferred Qualifications
- Knowledge or experience in Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and DevSecOps methodologies.
- Exposure to continuous integration/continuous deployment (CI/CD) security processes and container security.
- Certifications such as OSCP, OSWE, eWPT, BSCP, or other relevant credentials are advantageous.
Additional Information
This position is based in Riyadh, Saudi Arabia and is a part-time onsite role. Interested applicants are encouraged to submit their resumes as specified.
Minimum education
Bachelor's Degree
Industry
Cybersecurity