Overview

Application Security & Penetration Tester Jobs in Doha, Qatar at TaskLoom Solutions

We’re seeking a highly skilled and certified Application Security and Penetration Tester to join our cybersecurity team. Will be responsible for ensuring the security of applications across the development lifecycle, identifying vulnerabilities, and working closely with development and operations teams to implement secure coding practices and remediation strategies. This role demands a deep understanding of security assessment methodologies, enterprise IT environments, and the ability to communicate effectively with technical and non-technical stakeholders.

Key Responsibilities

  • Perform security assessments and code reviews for web, mobile, and standalone applications.
  • Integrate security into the Software Development Life Cycle (SDLC) and Dev Sec Ops  pipelines.
  • Collaborate with development teams to implement secure coding practices and threat modeling.
  • Conduct vulnerability assessments using automated tools and manual techniques.
  • Develop and maintain application security standards, policies, and best practices.
  • Stay current with emerging threats, vulnerabilities, and security technologies.
  • Provide guidance and training to developers and stakeholders on application security topics.
  • Participate in incident response and root cause analysis for application-related security events.
  • Conduct comprehensive penetration tests on:
    • Web applications (black-box, grey-box, white-box)
    • Standalone and thick-client applications
  • Perform threat modeling, vulnerability assessments, and exploit development.
  • Utilize both commercial (e.g., Veracode, Checkmarx, Synopsys) and open-source tools (e.g., Burp Suite, etc.).
  • Develop detailed reports with risk ratings, technical findings, and actionable remediation guidance.
  • Collaborate with IT, network, and application teams to validate findings and support remediation efforts.
  • Stay current with emerging threats, vulnerabilities, and industry trends.
  • Participate in red team/blue team exercises and security architecture reviews.
  • Must-have professional documentation and executive reporting skills.
  • Must submit report on methodology of attack, detailed report of attack execution, detailed action plan for fix, recommendations on mitigations, controls.

Required Qualifications

Minimum 10 years of experience in penetration testing and application security. Proven expertise in:

  • Web and mobile application security testing
  • Standalone/thick-client application testing
  • Strong understanding of OWASP Top 10, MITRE ATT&CK, and secure SDLC.
  • Proficiency with scripting and automation (Python, Bash, Power Shell, etc.).
    • Application architecture and common vulnerabilities
    • Static and Dynamic Application Security Testing (SAST/DAST)
  • Familiarity with CI/CD tools and integrating security into Dev Ops workflows.
  • Excellent communication skills with the ability to explain technical issues to non-technical stakeholders.
  • Solid understanding of enterprise IT, networking, and application architectures.

Certifications (Required)

Candidates must hold at least two or more of the following industry-recognized certifications:

  • OSCP (Offensive Security Certified Professional) (Active)
  • CISSP, CSSLP, or other relevant credentials
    • GXPN (Exploit Researcher and Advanced Pen Tester)

Preferred Skills

  • Experience with cloud-native application security (AWS, Azure, GCP).
  • Knowledge of container security (Docker, Kubernetes).
  • Familiarity with threat modeling frameworks (e.g., STRIDE, DREAD).
  • Experience in Agile and Dev Sec Ops  environments.
  • Experience with CI/CD pipeline security.
  • Familiarity with cloud platforms (AWS, Azure, GCP) and their security models.
  • Knowledge of regulatory frameworks (e.g., PCI-DSS, HIPAA, GDPR).
  • Experience in red teaming or adversary emulation.

Why Join Us

  • Work with a team of elite cybersecurity professionals.
  • Access to cutting-edge tools and technologies.
  • Opportunities for continuous learning and certification support.
  • Competitive compensation and benefits.

Apply Now to be part of a mission-driven team securing critical systems and applications.

#J-18808-Ljbffr

Title: Application Security & Penetration Tester

Company: TaskLoom Solutions

Location: Doha, Qatar

Category:

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.