An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.
Key Responsibilities
Web Application & API Security Testing
Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services. Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security. Assess applications against recognized security frameworks and industry best practices.
File & Document Security Assessment
Evaluate security controls governing file uploads, downloads, storage, and processing workflows. Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure.
Access Control & Authorization Review
Validate role-based and attribute-based access controls across multiple user types and permission levels. Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access. Assess segregation and isolation controls within shared application environments.
Identity & Authentication Security
Review authentication and authorization mechanisms, including OAuth 2.0, Open ID Connect (OIDC), SAML, and JWT implementations. Test token validation, session handling, replay protection, and identity federation controls. Identify weaknesses in identity lifecycle management and access governance.
Business Logic Security Analysis
Assess critical user journeys and application workflows for logic flaws and abuse cases. Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls. Evaluate protections against fraud, abuse, and unauthorized transaction manipulation.
Security Advisory & Remediation Support
Produce clear, risk-based security assessment reports with prioritized remediation recommendations. Collaborate with stakeholders to validate fixes and perform security re-testing. Support secure development practices throughout the software delivery lifecycle.
Required Skills & Experience
Security Assessment Expertise
Minimum 5 years of hands-on experience conducting web application and API penetration testing. Strong understanding of modern attack techniques and security testing methodologies.
Security Frameworks & Methodologies
Expert knowledge of:OWASP Top 10 OWASP API Security Top 10 OWASP Web Security Testing Guide (WSTG) Threat modeling and risk-based assessment approaches
Security Tools
Advanced proficiency with:Burp Suite Professional Postman Web application and API testing tools
Identity & Access Management Security
Proven experience identifying and exploiting weaknesses in:OAuth 2.0 Open ID Connect (OIDC) JWT SAML 2.0
Secure File Handling
Strong understanding of secure file processing, archive parsing, storage isolation, and content validation. Experience assessing file management controls and secure object storage implementations.
Preferred Qualifications
Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions. Familiarity with security automation and vulnerability assessment tools such as:Nuclei Semgrep OWASP ZAP Knowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP). Understanding of secure architecture principles for internet-facing applications and distributed environments.
Preferred Certifications
Offensive Security OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) Port Swigger BSCP (Burp Suite Certified Practitioner) Other relevant application security, penetration testing, or cloud security certifications are advantageous.
Senior Web App Security Engineer in Abu Dhabi, United Arab Emirates