📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة مستشار أمن التطبيقات لدى علم بالرياض

Application Security Consultant Job
🏢 علم (Elm)
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة علم (ELM) عن توفر وظيفة مستشار أمن التطبيقات (Application Security Consultant) في الرياض، السعودية، بهدف إجراء تقييمات أمنية للتطبيقات ودعم دمج الأمن في دورة حياة تطوير البرمجيات.

المهام والمسؤوليات

  • إجراء تقييمات أمنية للتطبيقات والحلول الرقمية والتحقق من مطابقتها للمتطلبات والمعايير الأمنية المعتمدة، وتوثيق الثغرات والمخاطر والتوصيات العلاجية.
  • مراجعة أكواد المصدر من منظور أمني لتحديد الثغرات وممارسات البرمجة غير الآمنة، وتقديم إرشادات العلاج لفرق التطوير.
  • إجراء نمذجة التهديدات للتطبيقات والخدمات الحالية والجديدة، وتحديد سيناريوهات الهجوم المحتملة وفجوات الضبط الأمني، والتوصية بضوابط الأمن المناسبة.
  • إدارة ثغرات التطبيقات من خلال تحليل وتقييم الثغرات على مستوى الطبقة التطبيقية، والتنسيق مع فرق التطوير لمعالجتها، والتحقق من الإصلاحات ورصد النتائج المعلقة.
  • تقييم أمن واجهات برمجة التطبيقات (APIs) والخدمات المصغرة والتكاملات الخارجية، وتقييم ضوابط المصادقة والتفويض وحماية البيانات، والتوصية بالتحسينات الأمنية.
  • تقديم إرشادات أمنية لفرق التطوير والهندسة طوال دورة حياة التطوير، ودعم تطبيق ممارسات التصميم والتطوير الآمنة، والتوصية بضوابط الأمن المناسبة لمخاطر الحلول ومتطلباتها.
  • تطوير وصيانة معايير وإرشادات ومتطلبات فنية لأمن التطبيقات، ودعم التوافق مع ممارسات تطوير البرمجيات الآمنة والمعايير السيبرانية، وتقييم الممارسات الناشئة والتوصية بالتحسينات.
  • دعم التوعية بالبرمجة الآمنة وتدريب المطورين فنياً، وتطوير مواد إرشادية ومعرفية تتعلق بثغرات التطبيقات الشائعة، وتعزيز ممارسات التطوير الآمنة عبر فرق الهندسة.
  • اتباع جميع السياسات والإجراءات والمعايير التشغيلية القياسية ذات الصلة بالقسم لضمان سير العمل بشكل منضبط ومتسق، والامتثال لسياسات السلامة والجودة والبيئة.
  • الامتثال لجميع ممارسات ومعايير أمن المعلومات لضمان نزاهة وسرية البيانات.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني، علوم الحاسب، هندسة البرمجيات، هندسة الحاسب، أو مجال ذي صلة.
  • الشهادات المهنية في أمن التطبيقات أو تطوير البرمجيات الآمنة أو تخصصات الأمن السيبراني ذات الصلة تُعتبر ميزة إضافية.
  • خبرة من 4 إلى 6 سنوات في أمن التطبيقات، تطوير البرمجيات الآمنة، التقييمات الأمنية، إدارة الثغرات، أو مجالات الأمن السيبراني ذات الصلة.
عرض النص الأصلي للإعلان

 

Job Description

OVERVIEW

Job Title

Consultant

Job Code

680865

Grade

I3

Group

-

Division

Legal, Risk & Governance

Department

Cybersecurity

Unit

Application Security

 

ROLE PURPOSE

The aim is to state the overall significance of the job from the organization’s perspective.

The role exists to perform application security assessments and support the integration of security throughout the software development lifecycle by identifying application vulnerabilities, conducting code and design reviews, assessing APIs and integrations, and providing security guidance to development teams to strengthen the security of Elm's applications and digital solutions.

 

KEY ACCOUNTABILITIES & ACTIVITIES

This section describes the principal outputs required from the job.

Key Accountabilities

Key Activities

  1. Application Security Assessment
  • Perform security assessments for applications and digital solutions.
  • Evaluate applications against approved security requirements and standards.
  • Document identified vulnerabilities, risks, and recommended remediation actions.
  1. Secure Code Review
  • Conduct security-focused source code reviews to identify vulnerabilities and insecure coding practices.
  • Assess code against secure coding standards and common application security risks.
  • Provide remediation guidance to development teams.
  1. Threat Modeling
  • Conduct threat modeling for new and existing applications and services.
  • Identify potential attack scenarios, threats, and security control gaps.
  • Recommend security controls based on identified risks.
  1. Application Vulnerability Management
  • Identify, analyze, and assess application-layer vulnerabilities.
  • Coordinate with development teams on vulnerability remediation activities.
  • Validate remediation and monitor outstanding application security findings.
  1. API & Integration Security
  • Assess APIs, microservices, and third-party integrations for cybersecurity risks.
  • Evaluate authentication, authorization, data protection, and integration controls.
  • Recommend appropriate security improvements.
  1. Secure Design & Development Advisory
  • Provide security guidance to development and engineering teams throughout the development lifecycle.
  • Support the application of secure design and development practices.
  • Recommend security controls appropriate to solution risks and requirements.
  1. Application Security Standards & Frameworks
  • Develop and maintain application security standards, guidelines, and technical requirements.
  • Support alignment with secure software development practices and applicable cybersecurity standards.
  • Evaluate emerging application security practices and recommend enhancements.
  1. Developer Security Awareness
  • Support secure coding awareness and technical security training for developers.
  • Develop security guidance and knowledge materials addressing common application vulnerabilities.
  • Promote secure development practices across engineering teams.
  1. Policies, Processes & Procedures
  • Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.
  • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.
  1. Information Security
  • Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.

 

 

JOB SPECIFICATIONS

Academic and professional qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field.
  • Professional certifications in Application Security, Secure Software Development, or related cybersecurity disciplines are considered an advantage.

Years and Nature of Experience

  • 4-6 years of experience in application security, secure software development, security assessments, vulnerability management, or related cybersecurity domains.

 

 

المصدر: الموقع الرسمي للجهة - أُضيفت للموقع في 25 أغسطس 2026

وظائف أخرى لدى علم