Jobiglo

No results.

Cyber Security Engineer (Web Application Security)

APTWatch · Riyad

🇬🇧 English
Burp Suite OWASP ZAP Nmap Postman Python Bash Linux Web application security Penetration testing HTTP/HTTPS REST APIs Authentication protocols OWASP Top 10 OWASP API Security Top 10 SAST DAST SCA DevSecOps

Job description

About the role

We are seeking a Cyber Security Engineer specializing in web application security to join our technical team in Riyadh. The role focuses on identifying, assessing, and mitigating vulnerabilities in modern web applications, APIs, and supporting infrastructure.

Key responsibilities

  • Perform web application and API security assessments.
  • Conduct vulnerability assessments and penetration testing.
  • Identify and validate vulnerabilities based on OWASP Top 10 and OWASP API Security Top 10.
  • Review authentication, authorization, session management, and access‑control mechanisms.
  • Test for common vulnerabilities such as XSS, SQL/NoSQL injection, SSRF, IDOR, CSRF, and insecure file handling.
  • Perform security reviews of REST APIs and modern web architectures.
  • Work with developers to reproduce, prioritize, and remediate security findings.
  • Support secure coding practices and security testing throughout the SDLC.
  • Prepare clear technical vulnerability reports with evidence, risk assessment, and remediation recommendations.

Required profile

  • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a related field.
  • Hands‑on experience in web application security and penetration testing.
  • Strong understanding of HTTP/HTTPS, REST APIs, authentication protocols, and web security fundamentals.
  • Practical experience with tools such as Burp Suite, OWASP ZAP, Nmap, and Postman.
  • Familiarity with Linux and scripting using Python, Bash, or similar languages.
  • Understanding of modern application architectures, including frontend/backend applications, APIs, databases, containers, and cloud environments.
  • Ability to clearly document and communicate technical security findings.

Required skills

  • Burp Suite
  • OWASP ZAP
  • Nmap
  • Postman
  • Python
  • Bash
  • Linux
  • Web application security
  • Penetration testing
  • HTTP/HTTPS
  • REST APIs
  • Authentication protocols
  • OWASP Top 10
  • OWASP API Security Top 10
  • SAST
  • DAST
  • SCA
  • DevSecOps

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec APTWatch.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Saudi Arabia.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 3 weeks ago

Expires 1 month from now

13 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

APTWatch

Riyad