📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Security Engineer – Product Security & DevSecOps

Rihal · Mascate

New
🇬🇧 English
Security code review Threat modeling Secure design patterns OWASP Top 10 CWE/SANS Top 25 DAST tools SCA tools Authentication Authorization Data protection AWS Azure GCP Docker Kubernetes

Job description

About the role

The Security Engineer will work closely with product and engineering teams to embed security throughout the software development lifecycle. You will act as the primary liaison for all product security matters, ensuring that our digital assets remain protected against emerging threats.

Key responsibilities

  • Serve as the single point of contact between the security team and product/engineering teams.
  • Perform manual and tool‑assisted security code reviews to uncover vulnerabilities, insecure patterns, and logic flaws.
  • Contribute to security architecture, threat modeling, and risk assessments for new and existing products.
  • Partner early in the SDLC to embed security requirements (Secure SDLC / DevSecOps practices).
  • Triage, validate, and remediate findings from code reviews, SAST/DAST tools, penetration tests, and bug bounty reports.
  • Define and maintain secure coding standards, guidelines, and checklists.
  • Integrate security tooling (SAST, SCA, secrets detection, container scanning) into CI/CD pipelines.
  • Provide guidance on API design, authentication/authorization, data protection, and third‑party integrations.
  • Track and report product security posture, open findings, and remediation timelines.
  • Stay current on emerging threats, vulnerability classes, and industry best practices (OWASP, CWE/SANS Top 25).

Required profile

  • Proven experience in security code review, able to analyze code for injection flaws, broken authentication, insecure deserialization, and business‑logic issues.
  • Solid understanding of security architecture principles, threat modeling, secure design patterns, defense‑in‑depth, and zero‑trust concepts.
  • Familiarity with OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes across web, API, mobile, and cloud‑native applications.
  • Working knowledge of SAST/DAST/SCA tools and their CI/CD integration.
  • Strong communication skills to convey findings to technical and non‑technical stakeholders.

Required skills

  • Security code review
  • Threat modeling
  • Secure design patterns
  • OWASP Top 10
  • CWE/SANS Top 25
  • SAST/DAST/SCA tools (e.g., Semgrep, SonarQube, Checkmarx, Snyk)
  • CI/CD pipeline integration
  • API security, authentication/authorization
  • Data protection
  • Cloud platforms (AWS, Azure, GCP)
  • Container security (Docker, Kubernetes)

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Rihal.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 5 days ago

Expires 1 month from now

23 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Rihal

Mascate