Qiddiya Investment Company is looking for a proactive and knowledgeable Senior Specialist - Application Security to join our dynamic team. This key role will focus on ensuring the security of our applications and systems, safeguarding sensitive data, and enabling our development teams to deliver robust and secure solutions.
As the Senior Specialist in Application Security, you will be responsible for implementing security best practices throughout the software development lifecycle (SDLC), conducting security assessments, and collaborating with stakeholders to mitigate risks associated with application vulnerabilities.
Key Responsibilities
- Conduct security assessments and vulnerability testing on applications and software to identify and remediate security flaws.
- Provide guidance and support to development teams to integrate security into the design, development, and deployment phases of the SDLC.
- Develop and maintain secure coding standards and guidelines to ensure adherence by all development teams.
- Monitor and analyze security threats related to applications and provide insights to improve security posture.
- Work closely with the IT security team to ensure alignment between application security and overall IT security policies and practices.
- Conduct training and awareness sessions for developers on best practices for secure coding and application security.
- Stay updated on emerging security threats and industry trends to continuously enhance application security measures.
- Collaborate with cross-functional teams to address and resolve security-related incidents and vulnerabilities effectively.
- Produce and present reports detailing application security assessments, incidents, and metrics to management.
Requirements
Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.Minimum of 5 years of experience in application security, software development, or related fields.Strong knowledge of application security principles, practices, and frameworks (e.g., OWASP).Experience with security testing tools (e.g., static / dynamic analysis tools) and methodologies.Familiarity with secure coding practices and experience working with developers to implement security controls.Excellent analytical skills and the ability to assess and mitigate risks effectively.Strong communication and interpersonal skills, with the ability to work collaboratively across departments.Relevant certifications (e.g., Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or similar) are a plus.Benefits
Comprehensive benefits package