1,011,843open jobs
60,160companies
168,355added this week
Browse all
Salary
≈ $66k – $174k per year (Estimated)
Location
In office (Doha)
Seniority
Staff · 3+ years exp

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Sep 30, 2026. Malomatia scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Malomatia is a Qatar-born technology services and digital transformation provider founded to support the nation's public and private sectors. The company specializes in delivering integrated IT solutions, including cybersecurity, cloud services, data and AI, enterprise application modernization, and large-scale contact center operations. By partnering with government agencies, healthcare institutions, and major enterprises, it plays a key role in driving technology-led innovation and economic diversification.

We are seeking a skilled Application Security Engineer to join our Cybersecurity Practice. In this role, you will work closely with our application security, development, and QA teams to secure our clients’ applications across their entire lifecycle. You will conduct security testing, perform penetration tests, and assess vulnerabilities across web, mobile and API applications.

Your responsibilities will span application penetration testing, automated security scanning (SAST, DAST, SCA), threat modelling, secure code review, and developer enablement. You will embed security best practices throughout the software development lifecycle and ensure that applications are designed and built with robust security controls.

You will collaborate with development and DevOps teams to integrate security into CI/CD pipelines, triage and validate findings, and provide clear, actionable remediation guidance. The role requires hands-on technical expertise, strong analytical skills, and the ability to translate complex security findings into practical fixes that developers can implement.

  • Penetration Testing: Conduct penetration tests on web applications, mobile applications, APIs, and thick-client applications. Prepare detailed reports with clear risk ratings and actionable remediation recommendations.
  • Security Scanning: Implement, tune, and manage automated security scanning tools (SAST, DAST, SCA) to continuously identify vulnerabilities in code, configurations, and third-party dependencies across all application types.
  • Threat Modelling: Perform threat modelling to identify potential security risks and attack surfaces associated with applications early in the design process and provide guidance on mitigating these risks.
  • Secure Code Review: Review application source code for security vulnerabilities across multiple platforms and languages, and offer practical, developer-friendly recommendations for remediation.
  • DevSecOps Integration: Integrate security testing and controls into CI/CD pipelines, enabling continuous and automated security validation as part of the development workflow.
  • Training & Awareness: Develop and deliver secure coding training sessions and workshops to raise application security awareness among development teams and other stakeholders.
  • Tool Evaluation: Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms.
  • Documentation: Create and maintain comprehensive documentation related to security assessments, vulnerability management, and application security standards and policies.
  • Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.
  • Experience: At least 3 years of experience in application security, secure software development, penetration testing, or a closely related field.
  • Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
    • OffSec certifications (e.g., OSWA, OSWE)
    • eLearnSecurity (e.g., eWPT, eWPTX)
    • GIAC / SANS (e.g., SEC542, GWAPT)
    • BCSP or other application security certifications.
  • Technical Skills: Proficiency with security testing tools such as Burp Suite (required), and familiarity with Snyk, HCL AppScan, Fority, and Postman (preferred). Strong understanding of secure coding practices and hands-on experience with at least one programming language. Familiarity with DevSecOps practices and CI/CD pipelines is preferred.
  • Knowledge: In-depth knowledge of application security principles and practices, with strong familiarity with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Understanding of common vulnerability classes, exploitation techniques, and remediation strategies. Knowledge of Qatar National Information Assurance (NIA) is a plus.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,011,843 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Doha
$165k – $275k per year • In office • 12+ years exp • Bachelor's Degree • New York
AI/ML
AI Agents
Red Teaming
Cybersecurity
ISO 27001
MITRE ATT&CK
NIST CSF
Web3
Smart Contracts
Apply
≈ $85k – $227k per year (Estimated) • Remote (Canada) • Full-Time
Python
SQL
AI/ML
Copilot
Claude
Function Calling
OpenAI Codex
Agentic Workflows
Tool Use
DevOps
CI/CD
Git
GitHub
Cybersecurity
Least Privilege
Sophos
Apply
≈ $105k – $215k per year (Estimated) • Remote (Canada) • Full-Time • 5+ years exp
JavaScript
Node JS
Node JS
Commander.js
Cybersecurity
Sophos
Apply
$104k – $173k per year • In office • TS/SCI • 5+ years exp • Bachelor's Degree • Denver
DevOps
Splunk
Cybersecurity
Microsoft Sentinel
MITRE ATT&CK
Cyber Kill Chain
SIEM
Apply
$97k – $162k per year • In office • TS/SCI • 4+ years exp • Bachelor's Degree • Quantico
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Toronto
COBOL
COBOL
VSAM
JCL
Databases
Db2
IMS
DevOps
CI/CD
Incident Management
GitHub
Management
Agile
Scrum
Apply
≈ $17k – $42k per year (Estimated) • Remote (EAEU) • Moscow
DevOps
Kibana
CI/CD
Git
Docker
Kubernetes
Grafana
Management
Agile
QA
Sentry
Apply
Engineer II - DevOps 9 hours ago
≈ $11k – $29k per year (Estimated) • Hybrid • Full-Time • Pune
Python
PowerShell
AI/ML
Copilot
AI Agents
DevOps
Terraform
Ansible
Helm
GitHub Actions
Terragrunt
Datadog
Prometheus
GitLab CI
CI/CD
GitOps
ArgoCD
Jenkins
AWS
Kubernetes
Grafana
Platform Engineering
Cybersecurity
Sumo Logic
Apply
≈ $15k – $37k per year (Estimated) • In office • Moscow
Python
Bash
Databases
PostgreSQL
Redis
Apache Kafka
AI/ML
GigaChat
DevOps
Zabbix
Kibana
VictoriaMetrics
CI/CD
Git
Docker
Kubernetes
Nginx
Grafana
Error Budget
SLI/SLO/SLA
Linux
TCP/IP
DNS
Cybersecurity
Wireshark
Tcpdump
HashiCorp Vault
Apply
≈ $11k – $25k per year (Estimated) • In office • 1+ year exp • Saint Petersburg
Python
1C
DevOps
GitLab CI
CI/CD
Apply
≈ $46k – $115k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Doha
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Bicep
IAM
Cybersecurity
Prisma Cloud
ISO 27001
Microsoft Defender
CIS Benchmarks
Least Privilege
Microsoft Defender for Cloud
Microsoft Entra ID
Cryptography
Vault
Apply
≈ $46k – $114k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Doha
DevOps
Azure
Cybersecurity
Microsoft Sentinel
ISO 27001
Microsoft Defender
CIS Benchmarks
Zero Trust
Least Privilege
Microsoft Defender for Cloud
Microsoft Entra ID
Cryptography
Vault
Apply
≈ $67k – $151k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Doha
DevOps
Cloudflare
DNS
Cybersecurity
FortiGate
Zero Trust
Apply
≈ $64k – $146k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Doha
DevOps
GCP
Azure
Kubernetes
Azure AKS
DNS
Cybersecurity
Microsoft Defender
Microsoft Defender for Cloud
Microsoft Entra ID
PKI
Management
ITSM
Apply
≈ $33k – $94k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Doha
Python
PowerShell
Bash
DevOps
Terraform
GCP
Azure
CI/CD
Linux
Windows
Cybersecurity
FortiGate
HashiCorp Vault
Microsoft Entra ID
Active Directory
PKI
Cryptography
Vault
Apply
≈ $81k – $199k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Doha
Design
Adobe Photoshop
Adobe After Effects
Apply
≈ $48k – $124k per year (Estimated) • In office • Contractor • 6+ years exp • Bachelor's Degree • Doha
Management
Microsoft Office
Apply
Driver 1 day ago
In office • Full-Time • Doha
Apply
≈ $28k – $52k per year (Estimated) • In office • Internship • Bachelor's Degree • Doha
Management
Microsoft Office
Apply
Apply
See all jobs
This is one of many
1,011,843 more open roles from verified company boards, updated every day.