Security Engineer – Product Security & DevSecOps
Rihal · Mascate
وصف الوظيفة
About the role
The Security Engineer will work closely with product and engineering teams to embed security throughout the software development lifecycle. You will act as the primary liaison for all product security matters, ensuring that our digital assets remain protected against emerging threats.
Key responsibilities
- Serve as the single point of contact between the security team and product/engineering teams.
- Perform manual and tool‑assisted security code reviews to uncover vulnerabilities, insecure patterns, and logic flaws.
- Contribute to security architecture, threat modeling, and risk assessments for new and existing products.
- Partner early in the SDLC to embed security requirements (Secure SDLC / DevSecOps practices).
- Triage, validate, and remediate findings from code reviews, SAST/DAST tools, penetration tests, and bug bounty reports.
- Define and maintain secure coding standards, guidelines, and checklists.
- Integrate security tooling (SAST, SCA, secrets detection, container scanning) into CI/CD pipelines.
- Provide guidance on API design, authentication/authorization, data protection, and third‑party integrations.
- Track and report product security posture, open findings, and remediation timelines.
- Stay current on emerging threats, vulnerability classes, and industry best practices (OWASP, CWE/SANS Top 25).
Required profile
- Proven experience in security code review, able to analyze code for injection flaws, broken authentication, insecure deserialization, and business‑logic issues.
- Solid understanding of security architecture principles, threat modeling, secure design patterns, defense‑in‑depth, and zero‑trust concepts.
- Familiarity with OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes across web, API, mobile, and cloud‑native applications.
- Working knowledge of SAST/DAST/SCA tools and their CI/CD integration.
- Strong communication skills to convey findings to technical and non‑technical stakeholders.
Required skills
- Security code review
- Threat modeling
- Secure design patterns
- OWASP Top 10
- CWE/SANS Top 25
- SAST/DAST/SCA tools (e.g., Semgrep, SonarQube, Checkmarx, Snyk)
- CI/CD pipeline integration
- API security, authentication/authorization
- Data protection
- Cloud platforms (AWS, Azure, GCP)
- Container security (Docker, Kubernetes)
Questions fréquentes
لماذا تبلغ عن هذا العرض؟
اكتشف المزيد
الرواتب والأدلة وعمليات البحث في Oman.
قدم طلبك في 30 ثانية
أدخل بريدك الإلكتروني للتقديم. سيتم إنشاء حساب تلقائياً.
بالمتابعة، أنت توافق على شروط الاستخدام.
لديك حساب بالفعل؟ تسجيل الدخول
عزز فرصك
حمّل سيرتك الذاتية وسنقترح عليك الوظائف التي تناسب ملفك.
جاري تحليل سيرتك الذاتية...
Rihal
Mascate
عروض عمل ذات صلة
-
Service Delivery Manager – Oman (Omanization)
Confidential Jobs Mascate -
Head of Security Architecture & Engineering
The IN Group Mascate -
EUC Engineer – End User Computing Services (EUCS)
Happiest Minds Technologies Mascate -
IT Auditor – Oracle ERP & IT Risk-CPA
Mogi I/O : OTT/Podcast/Short Video Apps for you Oman -
IT Auditor – Oracle Fusion & IT Risk
Mogi I/O : OTT/Podcast/Short Video Apps for you Oman