Senior Web Application Security Engineer

Our client in the UAE is looking for an expert to help them for 6 months on-site. If you are up for an interesting project and temporary relocation to a new environment, this could be the opportunity of the year!Role Overview

We are seeking an experienced Senior Application Security Engineer to lead the
security assessment and hardening of a high-impact, publicly accessible digital
platform. In this role, you will be responsible for evaluating multi-tenant architectures,
securing critical document workflows, and ensuring end-to-end API and authentication
security against advanced threats.

Key Responsibilities

  • Platform & API Testing: Conduct deep-dive manual and automated penetration testing on publicly accessible web applications, microservices, and APIs
  • Document & File Pipeline Security: Assess and harden document upload/download lifecycle controls
  • Multi-Tenant Isolation & Authorization: Validate cross-tenant boundaries, Insecure Direct Object References (IDOR), and granular access controls
  • (RBAC/ABAC) across diverse user roles and tenants
  • Identity & Session Security: Audit complex authentication and authorization architectures, including OAuth 2.0, OpenID Connect, and JWT implementation security (e.g., token signature validation, replay protection, and claim manipulation).
  • Business Logic & Workflow Security: Evaluate critical workflows to identify state-bypass flaws, race conditions, rate-limiting loopholes, and anti-automation gaps.
  • Remediation & Secure SDLC Support: Deliver clear, threat-modelled security reports with actionable mitigation guidance. Work directly with engineering teams to re-test fixes and support secure release pipelines.

Required Skills & Experience

  • Deep Web Pen Testing: 5+ years of hands-on experience in web application and API penetration testing
  • Threat Methodology: Mastery of OWASP Top 10, OWASP API Security Top 10, and the OWASP Web Security Testing Guide (WSTG).
  • Tooling Expertise: Advanced proficiency in Burp Suite Professional, Postman
  • Identity & Tokens: Hands-on experience identifying flaws in JWT, OAuth 2.0, and SAML 2.0 implementations.
  • File Handling Security: In-depth knowledge of binary/archive parsing security, safe file-storage practices (S3/Object storage isolation), and download header sanitization.
  • Good command of English

Preferred Skills

  • Experience testing Content Disarm & Reconstruction (CDR) or automated file-
scanning pipelines.
  • Familiarity with automated security tools (Nuclei, Semgrep, OWASP ZAP).
  • Knowledge of cloud security controls (AWS/Azure/GCP) for public-facing platforms.
  • Arabic language skills are a plus

Certifications (Highly Desirable):

  • OffSec: OSCP, OSWE
  • PortSwigger: BSCP

Please be in touch by Tuesday 11th if you are interested!
  • Locations: Remote
  • Technologies: Amazon Web Services (AWS), Azure, GCP, Microservices, SAFe