وظيفة مهندس أمن سيبراني (أمن تطبيقات الويب) شاغرة لدى APTWatch في الرياض
تفاصيل الوظيفة
تعلن شركة APTWatch عن حاجتها إلى مهندس أمن سيبراني متخصص في أمن تطبيقات الويب للعمل في الرياض، السعودية. سيركز الدور على تحديد وتقييم وتخفيف الثغرات الأمنية في تطبيقات الويب الحديثة وواجهات برمجة التطبيقات (APIs) والبنية التحتية الداعمة.
المهام والمسؤوليات
- إجراء تقييمات أمنية لتطبيقات الويب وواجهات برمجة التطبيقات (APIs).
- تنفيذ تقييمات الثغرات واختبارات الاختراق.
- تحديد والتحقق من الثغرات بناءً على OWASP Top 10 و OWASP API Security Top 10.
- مراجعة آليات المصادقة والترخيص وإدارة الجلسات والتحكم في الوصول.
- اختبار الثغرات الشائعة مثل XSS و SQL/NoSQL Injection و SSRF و IDOR و CSRF ومعالجة الملفات غير الآمنة.
- إجراء مراجعات أمنية لواجهات برمجة التطبيقات (REST APIs) والهياكل البرمجية الحديثة.
- العمل مع المطورين لإعادة إنتاج النتائج الأمنية وترتيب أولوياتها ومعالجتها.
- دعم ممارسات البرمجة الآمنة والاختبارات الأمنية طوال دورة حياة تطوير البرمجيات (SDLC).
- إعداد تقارير فنية واضحة عن الثغرات تتضمن الأدلة وتقييم المخاطر وتوصيات المعالجة.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو هندسة البرمجيات أو مجال ذي صلة.
- خبرة عملية في أمن تطبيقات الويب واختبار الاختراق.
- فهم قوي لـ HTTP/HTTPS و REST APIs وبروتوكولات المصادقة وأساسيات أمن الويب.
- خبرة عملية مع أدوات مثل Burp Suite و OWASP ZAP و Nmap و Postman.
- إلمام بنظام Linux والبرمجة النصية باستخدام Python أو Bash أو لغات مماثلة.
- فهم الهياكل البرمجية الحديثة بما في ذلك تطبيقات الواجهة الأمامية والخلفية وقواعد البيانات والحاويات والبيئات السحابية.
- القدرة على توثيق النتائج الأمنية التقنية وإيصالها بوضوح.
- يفضل الخبرة في SAST و DAST و SCA وممارسات DevSecOps.
- يفضل الإلمام بتكامل الأمن في CI/CD وأمن الحاويات.
- يفضل الشهادات مثل OSCP أو OSWE أو eWPT أو BSCP أو ما يعادلها.
عرض النص الأصلي للإعلان
We’re Hiring: Cybersecurity Engineer - Web Application Security
APTWatch is looking for a Cybersecurity Engineer with a strong focus on Web Application Security to join our growing technical team.
The role will focus on identifying, assessing, and mitigating security vulnerabilities across modern web applications, APIs, and supporting infrastructure.
Key Responsibilities
* Perform web application and API security assessments.
* Conduct vulnerability assessments and penetration testing.
* Identify and validate vulnerabilities based on OWASP Top 10 and OWASP API Security Top 10.
* Review authentication, authorization, session management, and access-control mechanisms.
* Test for common vulnerabilities such as XSS, SQL/NoSQL Injection, SSRF, IDOR, CSRF, and insecure file handling.
* Perform security reviews of REST APIs and modern web architectures.
* Work with developers to reproduce, prioritize, and remediate security findings.
* Support secure coding practices and security testing throughout the SDLC.
* Prepare clear technical vulnerability reports with evidence, risk assessment, and remediation recommendations.
Requirements
* Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a related field.
* Hands-on experience in web application security and penetration testing.
* Strong understanding of HTTP/HTTPS, REST APIs, authentication protocols, and web security fundamentals.
* Practical experience with tools such as Burp Suite, OWASP ZAP, Nmap, and Postman.
* Familiarity with Linux and scripting using Python, Bash, or similar languages.
* Understanding of modern application architectures, including frontend/backend applications, APIs, databases, containers, and cloud environments.
* Ability to clearly document and communicate technical security findings.
Preferred Qualifications
* Experience with SAST, DAST, SCA, and DevSecOps practices.
* Familiarity with CI/CD security integration and container security.
* Certifications such as OSCP, OSWE, eWPT, BSCP, or equivalent are a plus.
Location: Riyadh, Saudi Arabia
Employment Type: Full-time
Interested candidates may submit their CV to:
hr@apt-watch.com
رقم الإعلان لدى المصدر: 4459551821