Application Security Analyst

2 days ago


Doha, Baladīyat ad Dawḩah, Qatar Management Solutions International (MSI) Full time 120,000 - 240,000 per year

Location

Doha, Qatar

Experience

10

Job Type

Outsourcing

Job Description

Job Objectives

The Information Security Application Consultants develops, operates, and manages the application security frameworks to continuously monitor and improve organization's security posture to build secure applications and reduce threat footprint. The role also provides subject matter expertise and operational direction on application security governance, application security control and risk analysis, security assessment automation, secure development practices and incident response.

Description

  1. Establish and manage industry-leading application security processes and practices at each phase of the software development lifecycle and implement operational roadmap for assessment, penetration testing and source code reviews.

  2. Ensure acquired and developed applications are consistent with secure software development lifecycle and security architecture guidelines.

  3. Conduct regular manual and automated application security testing, assessments, review results, track issues and follow up to ensure remediation in line with secure software development lifecycle.

  4. Coordinate and scope Third party penetration testing and application assessments activities including configuration reviews for compliance and additional assurance of secured implementation and operation of solutions.

  5. Design, develop and implement the integration and automation of threat modelling, security assessments and testing tools with DevOps, application development and QA tools to improve detection and prevention capabilities.

  6. Recommend improvements to the secure reference architecture through continuous review and assessment of the application security requirements, policies, and procedures.

  7. Ensure secure coding practices and Software Development Life Cycle (SDLC) are followed by providing training and awareness to the internal stakeholders.

  8. Ensure Data Protection, privacy concerns and regulations are in place and addressed in Policies and procedures.

  9. Help support and enhance existing cloud security model, ensuring adherence to best practice in alignment with industry standards at technology, operational, legal measures.

  10. Define the high-level requirements for preserving the confidentiality, integrity, and availability of information and assets, protecting assets from threats based on an assessment of risks to the organization, and supporting the fulfillment of relevant legal, regulatory, operational, and contractual requirements.

  11. Provide regular updates to management on application security and vulnerability management posture by defining operational KPIs and metrics, build dashboard and reports.

  12. Manage follow up, close and report upon all department's information security regulatory requirements, audits, inconformity reports, compliance issues and observations that arise during conducted internal and external assurance engagements.

  13. Conduct Risk Assessments on the required Applications to identify applicable risk scenarios and mitigating controls as per Qatargas Information security risk management practices.

  14. Perform other related duties or assignments as directed.

Requirements

Minimum Qualifications:

Bachelor's degree in Computer Engineering/Science, Electronics Engineering, or any other appropriately relevant field.

Minimum Experience:

10 years of progressive experience in a directly related field.

7 years of professional experience in ICT information, application security in an enterprise level environment.

3 years in similarly relevant Application security role with around the same team capacity and complexity of assigned tasks.

Job Specific Skills:

Certifications in industry relative standards, frameworks, and schools of practice, such as CSSLP, GWAPT, OSCP, etc.

Excellent knowledge in maintaining effective working relationships with staff and clients; excellent people management skills.

Excellent written and verbal communication skills.

Strong analytical and problem-solving skills.

Proven success in working in a similarly complex ICT information security within same industry.

Professional experience in conducting manual and automated application assessments (DAST, SAST & RAST), penetration testing and configuration review.

Excellent understanding of modern development approaches and environments, secure Software Development Life Cycle (SDLC), secure coding practices and DevSecOps.

Good understanding of cryptography, web service frameworks, mobile application architectures, and service architectures (such as event-driven, service-oriented, or serverless architectures)

Good understanding of implementing enterprise information security architectures and frameworks.

Strong understanding of project management principles and requirements.

Excellent knowledge and understanding of Information Technology industry, trends, architectures, integrations, operational security, and process computing.

Excellent knowledge and understanding of leading industry standards, frameworks, methodologies, and best practices.

Excellent knowledge and understanding of information security governance, compliance, architecture components, technical solutions, and operational services.

Understanding of SAP products, Applications development concepts, change management and landscape

Propose security guidelines for new SAP systems ensuring critical design and implementation elements are captured addressed.

Excellent knowledge and understanding of SAP cloud platform Application services, types of deployments and security requirements to ensuring secure operations and data integrity.

Skills

Information Technology, Risk Assessment, Css, Verbal Communication Skill, Devops, Information Security, Verbal Communication Skills, Sdlc, Management Skill, Analytical And Problem-solving Skill, Application Security, Compliance, Aris, Change Management, Application Development, Web Service, Problem-solving Skill, Methodologies, Excel, People Management, Communication Skill, Written And Verbal Communication, Strong Understanding, Trends, Project Management, Strong Analytical, Software Development



  • Doha, Baladīyat ad Dawḩah, Qatar Intrinsic Security Full time 90,000 - 120,000 per year

    Role:Cyber Security Engineer (SOC Analyst)Location:Qatar (Onsite)Department:Cybersecurity OperationsReports To:Head of Security OperationsRole Overview:We are seeking a highly skilled and motivated Cyber Security Engineer (SOC Analyst) to join our security team. The ideal candidate will bring hands-on experience in SOC environments, advanced knowledge of...


  • Doha, Baladīyat ad Dawḩah, Qatar Naufar Full time 120,000 - 240,000 per year

    JOB PURPOSE:The Cyber Security Analyst creates a comprehensive program for establishing a Healthcare carrier-class Security Operation Center. S/he develop and maintain threat monitoring and security incident response procedures within Naufar. The analyst designs frameworks, procedures, and toolkits to enhance capabilities in professional forensic collection...

  • Application Analyst

    2 days ago


    Doha, Baladīyat ad Dawḩah, Qatar Management Solutions International (MSI) Full time 60,000 - 120,000 per year

    LocationDoha, QatarExperience3-6Job TypeOutsourcingJob DescriptionJob TitleApplication Analyst(Power Platform) – Enterprise PortalDepartmentInformation TechnologyDirect SupervisorLead of Enterprise PortalPart A: Job SpecificationJob PurposeAs a technical SME, the position is responsible for managing and supporting services managed by Enterprise Portal Team...


  • Doha, Baladīyat ad Dawḩah, Qatar PPL Dynamics Full time $90,000 - $180,000 per year

    Job Objective :  The role of the ICT Senior Applications Development Analyst is to develop, implement and integrate high-quality, innovative application coding and configuration to fulfill business departments requirements.  The job includes all aspects of analysis, research, definition, planning, designing, programming and documenting developed...


  • Doha, Baladīyat ad Dawḩah, Qatar ECCO Gulf Majorel Qatar Full time 90,000 - 120,000 per year

    Information Security AnalystJob PurposeResponsible to support Information Security Governance, Risk and Controlactivities. Assist in all information security activities in order to protect theorganization's information technology assets from cyber-attacks.Function Information TechnologyKey ResponsibilitiesSupporting and maintaining the required Information...


  • Doha, Baladīyat ad Dawḩah, Qatar Al Adyat consultancy Full time 192,000 - 240,000 per year

    Job SummaryWe are seeking a highly skilled and experienced Application Security Expert to join our team. The ideal candidate will have a minimum of 5 years of experience in application security, vulnerability assessment, threat modeling, secure coding practices, and security testing. The candidate should be a graduate in Computer Science, IT, or any...

  • Applications Analyst

    4 hours ago


    Doha, Baladīyat ad Dawḩah, Qatar Mekdam Technical Services Full time $60,000 - $120,000 per year

    Job PurposeSupport business functions and provide detailed IT technical expertise to maintain applications support environment and resolve day to day issues. Key Job Accountabilities - IInvestigate operational issues, problems and requests for support, in coordination with colleagues and other stakeholders, seeking effective solutions...


  • Doha, Baladīyat ad Dawḩah, Qatar Mekdam Technical Services Full time $80,000 - $120,000 per year

    We currentlyhave an opening for the position of Sr. Security ApplicationEngineer with one of our prestigious client (through Secondment Mekdam)Main Responsibilities: Be a member of the ICS Security Enhancement Project (ICSSEP) management team as a focal point for engineering design of Cybersecurity infrastructure for Industrial Control Systems. Apply best...

  • Security Analyst

    5 hours ago


    Doha, Baladīyat ad Dawḩah, Qatar Mekdam Technical Services Full time $70,000 - $140,000 per year

    RequirementsMinimum Qualifications: Bachelors degree in Computer Engineering/Science, Electronics Engineering, or any other appropriately relevant field.Minimum Experience: years of progressive experience in a directly related field. 7 years of professional experience in ICT information, application security in an enterprise level environment.


  • Doha, Baladīyat ad Dawḩah, Qatar Mekdam Technical Services Full time $90,000 - $180,000 per year

    Job ObjectivesThe Information Security Consultant manages the IT Operations security for existing Infrastructure and new required services as part of business portfolio to continuously monitor and improve organization's security posture to build secure Infrastructure and reduce threat footprint. The role also provides subject matter expertise and operational...