Skip to Content

Security Engineer

Oman, Oman

Job Purpose

The Security Engineer assists in implementing and maintaining security measures to protect the organization’s digital assets. This role requires foundational knowledge of cybersecurity principles and the ability to learn and grow under the guidance of senior engineers.

Key Responsibilities

  • Act as the single point of contact between the security team and product/engineering teams for all product security matters.
  • Perform security code reviews (manual and tool-assisted) across codebases to identify vulnerabilities, insecure patterns, and logic flaws before release.
  • Review and contribute to security architecture for new and existing products, including threat modeling, secure design patterns, and risk assessments.
  • Partner with engineering teams early in the SDLC to embed security requirements into design, development, and deployment stages (Secure SDLC / DevSecOps practices).
  • Triage, validate, and help remediate vulnerabilities identified through code review, SAST/DAST tools, penetration tests, and bug bounty reports.
  • Define and maintain secure coding standards, guidelines, and checklists tailored to the technology stacks in use.
  • Support integration of security tooling into CI/CD pipelines (SAST, dependency/SCA scanning, secrets detection, container scanning).
  • Provide security guidance on API design, authentication/authorization models, data protection, and third-party integrations.
  • Track and report on product security posture, open findings, and remediation timelines to management.
  • Stay current on emerging threats, vulnerability classes, and industry best practices (OWASP, CWE/SANS Top 25, etc.) relevant to the product portfolio.

Required Qualifications

  • Proven experience in security code review — able to read and analyze code (not just run automated scanners) to identify vulnerabilities such as injection flaws, broken authentication/authorization, insecure deserialization, business logic issues, etc.
  • Solid understanding of security architecture principles — threat modeling, secure design patterns, defense-in-depth, zero trust concepts, and secure API/data flow design.
  • Familiarity with the OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes across web, API, mobile, and cloud-native applications.
  • Working knowledge of SAST/DAST/SCA tools (e.g., Semgrep, SonarQube, Checkmarx, Snyk, or similar) and how to integrate them into CI/CD pipelines.
  • Ability to communicate security findings clearly to both technical and non-technical stakeholders, and to build collaborative relationships with development teams.

Preferred Qualifications

  • Prior software development experience (e.g., as a developer or in a hybrid dev/security role) — hands-on experience writing production code in one or more languages (e.g., JavaScript/TypeScript, Python, Java, Go, .NET) is a strong plus.
  • Experience with cloud platforms (AWS, Azure, or GCP) and container/orchestration security (Docker, Kubernetes) and on prem deployments also
  • Familiarity with DevSecOps practices and pipeline security (CI/CD security gates, IaC scanning).
  • Relevant certifications such as OSWE or similar are a plus but not mandatory.
  • Experience conducting or coordinating penetration tests and working with external security assessors.