Senior Web Application Security Engineer – Abu Dhabi, UAE

Website Halian
Location
Abu Dhabi, United Arab Emirates
Job Category
- Information Technology (IT) & Software
- Engineering & Technical
- Security & Defence
- Government & Public Sector
Job Overview
We are seeking an experienced Senior Web Application Security Engineer to join an onsite technology and cybersecurity team in Abu Dhabi, UAE. This is a 6-month extendable contract opportunity for a cybersecurity professional with strong hands-on experience in web application and API penetration testing.
The successful candidate will conduct security assessments, identify vulnerabilities in web applications and APIs, evaluate authentication and authorization mechanisms, and assess file-processing and security controls. The role requires practical expertise with industry-standard security testing tools and methodologies, along with knowledge of cloud security controls across AWS, Azure, and Google Cloud Platform.
This position provides opportunities for career growth in application security, API security, penetration testing, cloud security, and offensive security. Professional development and industry-recognized certifications such as OSCP, OSWE, and BSCP can further support progression within cybersecurity and application security careers.
Key Responsibilities
- Conduct web application and API penetration testing.
- Identify and assess application security vulnerabilities.
- Perform API security testing using appropriate testing methodologies and tools.
- Assess authentication and authorization mechanisms involving JWT, OAuth 2.0, and SAML 2.0.
- Perform file upload security testing.
- Assess security risks associated with binary and archive file parsing.
- Evaluate Content Disarm & Reconstruction (CDR) controls and automated file-scanning pipelines.
- Use security testing tools including Burp Suite Professional, Postman, Nuclei, Semgrep, and OWASP ZAP.
- Identify vulnerabilities and provide appropriate technical findings and recommendations.
- Assess cloud security controls across AWS, Azure, and GCP environments.
- Support security assessments and communicate findings to relevant technical stakeholders.
- Maintain appropriate security assessment documentation and reports.
- Contribute to improving application security testing methodologies and processes.
Requirements & Qualifications
- Minimum 5 years of hands-on experience in Web Application and API Penetration Testing.
- Strong practical expertise with:
- Burp Suite Professional
- Postman
- OWASP testing methodologies
- API Security Testing
- Hands-on experience identifying security flaws involving:
- JWT
- OAuth 2.0
- SAML 2.0
- Experience with file upload security testing.
- Experience with binary and archive parsing security.
- Experience with Content Disarm & Reconstruction (CDR) and automated file-scanning pipelines.
- Familiarity with Nuclei, Semgrep, and OWASP ZAP.
- Knowledge of cloud security controls across AWS, Azure, and GCP.
- Strong analytical and problem-solving capabilities.
- Strong technical documentation and communication skills.
- Candidates currently based in the UAE are preferred.
- Candidates available to start immediately are preferred.
- Maximum notice period: 30 days.
Preferred Certifications
- OSCP – Offensive Security Certified Professional
- OSWE – Offensive Security Web Expert
- BSCP – Burp Suite Certified Practitioner
Employment Type
6-Month Extendable Contract
Salary, Benefits & Career Growth
Salary details have not been provided by the employer and therefore are not included.
This role provides professional exposure to advanced web application security, API penetration testing, offensive security methodologies, cloud security, and enterprise cybersecurity controls. Candidates can strengthen their career through hands-on security assessments, professional development, technical training, and industry-recognized cybersecurity certifications.
The extendable contract may provide opportunities for continued project engagement, subject to business requirements and performance.
Application Process
Application Process (Website)
Apply only through the official job link.
Click Apply Now on the website and follow the application instructions.
Candidates must confirm their current location and notice period when applying.
HR Email for Application
Send your updated CV directly
Please confirm your notice period and current location in your application.
To apply for this job email your details to donna.aniceta@halian.com
