×
Register Here to Apply for Jobs or Post Jobs. X

Senior Web App Security Engineer (m​/f​/d

Job in Abu Dhabi, UAE/Dubai
Listing for: Halian
Full Time position
Listed on 2026-08-11
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations, IT Consultant
Salary/Wage Range or Industry Benchmark: 350000 - 520000 AED Yearly AED 350000.00 520000.00 YEAR
Job Description & How to Apply Below
Position: Senior Web App Security Engineer (m/f/d)

An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.

Key Responsibilities Web Application & API Security Testing
  • Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services.
  • Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security.
  • Assess applications against recognized security frameworks and industry best practices.
File & Document Security Assessment
  • Evaluate security controls governing file uploads, downloads, storage, and processing workflows.
  • Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure.
Access Control & Authorization Review
  • Validate role-based and attribute-based access controls across multiple user types and permission levels.
  • Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access.
  • Assess segregation and isolation controls within shared application environments.
Identity & Authentication Security
  • Review authentication and authorization mechanisms, including OAuth 2.0, OpenID Connect (OIDC), SAML, and JWT implementations.
  • Test token validation, session handling, replay protection, and identity federation controls.
  • Identify weaknesses in identity lifecycle management and access governance.
Business Logic Security Analysis
  • Assess critical user journeys and application workflows for logic flaws and abuse cases.
  • Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls.
  • Evaluate protections against fraud, abuse, and unauthorized transaction manipulation.
Security Advisory & Remediation Support
  • Produce clear, risk-based security assessment reports with prioritized remediation recommendations.
  • Collaborate with stakeholders to validate fixes and perform security re-testing.
  • Support secure development practices throughout the software delivery lifecycle.
Required Skills & Experience Security Assessment Expertise
  • Minimum 5 years of hands-on experience conducting web application and API penetration testing.
  • Strong understanding of modern attack techniques and security testing methodologies.
Security Frameworks & Methodologies
  • Expert knowledge of:
    • OWASP Top 10
    • OWASP API Security Top 10
    • OWASP Web Security Testing Guide (WSTG)
    • Threat modeling and risk-based assessment approaches
Security Tools
  • Advanced proficiency with:
    • Burp Suite Professional
    • Postman
    • Web application and API testing tools
Identity & Access Management Security
  • Proven experience identifying and exploiting weaknesses in:
    • OAuth 2.0
    • OpenID Connect (OIDC)
    • JWT
    • SAML 2.0
Secure File Handling
  • Strong understanding of secure file processing, archive parsing, storage isolation, and content validation.
  • Experience assessing file management controls and secure object storage implementations.
Preferred Qualifications
  • Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions.
  • Familiarity with security automation and vulnerability assessment tools such as:
    • Nuclei
    • Semgrep
    • OWASP ZAP
  • Knowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP).
  • Understanding of secure architecture principles for internet-facing applications and distributed environments.
Preferred Certifications
  • Offensive Security

    • OSCP (Offensive Security Certified Professional)
    • OSWE (Offensive Security Web Expert)
  • Port Swigger

    • BSCP (Burp Suite Certified Practitioner)
  • Other relevant application security, penetration testing, or cloud security certifications are advantageous.

#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary