Security Engineer

Rihal — Oman · Posted ~2 hours ago

Junior Full-time

Skills

Cybersecurity Security Code Review Threat Modeling Security Architecture Secure SDLC DevSecOps SAST DAST Vulnerability Management

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a security engineering team protecting digital assets and embedding security throughout the software development lifecycle. You will serve as a key security partner for engineering teams, conduct manual and tool-assisted code reviews, contribute to threat modeling and secure architecture, and help triage and remediate vulnerabilities identified by SAST and DAST tools. The role is designed to provide hands-on growth with guidance from experienced security engineers.

Highlights

Opportunity to grow under senior security engineers while gaining hands-on experience across product security, secure architecture, vulnerability management, and DevSecOps. The role provides broad collaboration with engineering teams and early involvement in the software development lifecycle.

Description

Job Purpose The Security Engineer assists in implementing and maintaining security measures to protect the organization’s digital assets. This role requires foundational knowledge of cybersecurity principles and the ability to learn and grow under the guidance of senior engineers. Key Responsibilities Act as the single point of contact between the security team and product/engineering teams for all product security matters.Perform security code reviews (manual and tool-assisted) across codebases to identify vulnerabilities, insecure patterns, and logic flaws before release.Review and contribute to security architecture for new and existing products, including threat modeling, secure design patterns, and risk assessments.Partner with engineering teams early in the SDLC to embed security requirements into design, development, and deployment stages (Secure SDLC / DevSecOps practices).Triage, validate, and help remediate vulnerabilities identified through code review, SAST/DAST tools, penetration tests, and bug bounty reports.Define and maintain secure coding standards, guidelines, and checklists tailored to the technology stacks in use.Support integration of security tooling into CI/CD pipelines (SAST, dependency/SCA scanning, secrets detection, container scanning).Provide security guidance on API design, authentication/authorization models, data protection, and third-party integrations.Track and report on product security posture, open findings, and remediation timelines to management.Stay current on emerging threats, vulnerability classes, and industry best practices (OWASP, CWE/SANS Top 25, etc.) relevant to the product portfolio. Required Qualifications Proven experience in security code review — able to read and analyze code (not just run automated scanners) to identify vulnerabilities such as injection flaws, broken authentication/authorization, insecure deserialization, business logic issues, etc.Solid understanding of security architecture principles — threat modeling, secure design patterns, defense-in-depth, zero trust concepts, and secure API/data flow design.Familiarity with the OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes across web, API, mobile, and cloud-native applications.Working knowledge of SAST/DAST/SCA tools (e.g., Semgrep, SonarQube, Checkmarx, Snyk, or similar) and how to integrate them into CI/CD pipelines.Ability to communicate security findings clearly to both technical and non-technical stakeholders, and to build collaborative relationships with development teams. Preferred Qualifications Prior software development experience (e.g., as a developer or in a hybrid dev/security role) — hands-on experience writing production code in one or more languages (e.g., JavaScript/TypeScript, Python, Java, Go, .NET) is a strong plus.Experience with cloud platforms (AWS, Azure, or GCP) and container/orchestration security (Docker, Kubernetes) and on prem deployments alsoFamiliarity with DevSecOps practices and pipeline security (CI/CD security gates, IaC scanning).Relevant certifications such as OSWE or similar are a plus but not mandatory.Experience conducting or coordinating penetration tests and working with external security assessors.