SonicJobs Logo
Left arrow iconBack to search

Application Security Engineer

Siren
Posted 3 days ago, valid for 13 days
Location

Beirut, Beirut

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Application Security Engineer role involves assessing and enhancing the security of applications through penetration testing and vulnerability assessments.
  • Candidates should have a bachelor's degree in a relevant field and at least 3 years of hands-on experience in application security or penetration testing.
  • The position requires a strong understanding of common application vulnerabilities, as well as practical experience with security tools like Burp Suite and OWASP ZAP.
  • The expected salary for this role is competitive, although specific figures are not mentioned in the job description.
  • Siren is an equal opportunity employer, encouraging applications from all qualified candidates.

Our Opportunity

TheApplication Security Engineer will assess and strengthen the security ofapplications developed and maintained by our team. The role will conductpenetration tests and vulnerability assessments, provide practical remediationguidance, and verify fixes in close collaboration with Development, QA, andDevOps teams.

You Will


  • Plan andconduct manual and automated penetration testing of web applications, APIs, andmobile applications where applicable.
  • Evaluateauthentication, authorization, session management, input validation, businesslogic, and sensitive data protection.
  • Investigatevulnerability scanner results, eliminate false positives, and document clear,reproducible evidence.
  • Prioritizefindings based on severity, exploitability, and business impact, and promptlyescalate critical vulnerabilities.
  • Workwith developers to address root causes, recommend practical fixes, and retestvulnerabilities before closure.
  • Conducttargeted security code reviews, contribute to secure design reviews, andsupport security checks within development pipelines.
  • Maintaina vulnerability register and prepare detailed technical reports and concisemanagement updates.
  • Guidedevelopers on secure coding practices and help prevent recurringvulnerabilities.

·      Expected Deliverables

• Assessment plans outlining scope, approach, and schedule.
• Security reports with prioritized findings, evidence, reproduction steps, and remediation recommendations.
• Vulnerability register tracking ownership, deadlines, and resolution status.
• Retesting results confirming fixes and documenting outstanding risks.
• Periodic management summaries and practical secure coding guidance.




Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.
  • 3+ years of hands-on experience in application security or penetration testing, including web applications and APIs.
  • Strong understanding of common application vulnerabilities and OWASP testing practices.
  • Demonstrated ability to perform manual security testing beyond automated vulnerability scanning.
  • Practical experience with tools such as Burp Suite, OWASP ZAP, API testing tools, and vulnerability scanners.
  • Good understanding of HTTP/HTTPS, REST APIs, authentication, access controls, SQL, and application configurations.
  • Ability to review code in at least one relevant programming language and write basic testing or automation scripts.
  • Experience guiding developers through remediation and verifying implemented fixes.
  • Ability to manage assessments independently and communicate findings clearly to technical and nontechnical stakeholders.
  • Relevant practical certifications, such as OSCP, OSWE, or equivalent.
  • Experience with mobile security testing, threat modeling, and secure design reviews.
  • Familiarity with CI/CD security tools, dependency scanning, and secret detection.
  • Experience working in on-premises or restricted environments and handling sensitive information.
  • Certifications are an advantage; demonstrated practical competence remains the primary selection criterion.

Siren is an equal opportunity employer. At Siren we value ethics, dedication, sustainability, safeguarding, respect, and inclusion.

Are you interested to work with our dedicated team on impactful projects? We welcome applications from all qualified candidates, regardless of background. Do apply!





Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.