Date Posted: 22 July, 2026
Industry: IT Services and IT Consulting
Location: VAPORVM IT SERVICES DMCC
Job Description:
Based on the responsibilities and qualifications provided, here’s a comprehensive and professional Job Description (JD) for an Application Security On-Site Engineer role.
Job Summary
The Application Security On-Site Engineer is responsible for ensuring the security of enterprise applications throughout their lifecycle by performing security assessments, managing application security tools, identifying vulnerabilities, and supporting remediation efforts. The role serves as a key liaison between security, development, and IT operations teams to enhance the organization’s security posture and ensure compliance with security standards and regulatory requirements.
The successful candidate will possess strong technical expertise in application security, vulnerability management, secure software development practices, and security testing methodologies. This position requires hands-on operational support and active collaboration with stakeholders to drive security improvements across both internally developed and third-party applications.
Key Responsibilities
Application Security Operations
- Administer, configure, maintain, and optimize application security tools and platforms, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and vulnerability management solutions.
- Monitor application security controls and ensure continuous operational effectiveness.
- Support the deployment, integration, and ongoing management of security solutions within development and production environments.
- Troubleshoot and resolve technical issues related to application security tools and services.
Security Assessments and Testing
- Conduct comprehensive application security assessments for internally developed, commercial off-the-shelf (COTS), cloud-based, and third-party applications.
- Perform vulnerability assessments, secure code reviews, configuration reviews, and security testing activities.
- Identify security weaknesses, vulnerabilities, and misconfigurations within applications and supporting infrastructure.
- Validate security findings and eliminate false positives through detailed analysis.
Vulnerability Management
- Analyze, classify, and prioritize vulnerabilities based on risk, exploitability, business impact, and compliance requirements.
- Maintain vulnerability tracking processes and ensure accurate documentation of findings.
- Monitor remediation progress and verify the effectiveness of corrective actions.
- Support risk management activities by providing recommendations for mitigation strategies.
Secure Development Support
- Partner with software development teams to promote Secure Software Development Lifecycle (SSDLC) practices.
- Provide secure coding guidance and application security best practice recommendations.
- Review application architecture and design to identify potential security risks.
- Assist developers in understanding and addressing security vulnerabilities during development and testing phases.
Collaboration and Incident Support
- Work closely with development, infrastructure, DevOps, cloud, and IT operations teams to resolve security issues.
- Participate in security investigations involving application-related vulnerabilities and incidents.
- Support root cause analysis and implementation of preventive security controls.
- Serve as the on-site technical focal point for application security-related activities.
Documentation and Reporting
- Prepare detailed security assessment reports, risk reports, vulnerability summaries, and remediation recommendations.
- Develop and maintain security procedures, standards, and operational documentation.
- Produce metrics and dashboards related to application security posture and vulnerability trends.
- Ensure documentation aligns with organizational policies, regulatory requirements, and industry standards.
Compliance and Governance
- Support compliance initiatives related to ISO 27001, NIST, PCI DSS, OWASP, CIS Controls, and other applicable security frameworks.
- Participate in security audits and compliance reviews.
- Assist in developing and enforcing application security policies and procedures.
- Ensure application security activities meet internal governance requirements and industry best practices.
Required Qualifications
Education
- Bachelor’s Degree in Cybersecurity, Information Security, Computer Science, Software Engineering, Information Technology, or a related field.
Certifications (Preferred)
One or more of the following certifications are highly desirable:
- Certified Secure Software Lifecycle Professional (CSSLP)
- GIAC Web Application Penetration Tester (GWAPT)
- Certified Application Security Engineer (CASE)
- Certified Ethical Hacker (CEH)
- Offensive Security Web Expert (OSWE)
- Offensive Security Certified Professional (OSCP)
- Certified Information Systems Security Professional (CISSP)
Experience
- Minimum of three (3) years of hands-on experience in application security operations.
- Experience with application security testing and vulnerability management processes.
- Experience supporting secure software development initiatives.
- Experience working with developers, DevOps, and infrastructure teams in enterprise environments.
Required Technical Skills
Application Security
- Application Security Testing (SAST, DAST, IAST, SCA)
- Secure Code Review
- Vulnerability Assessment and Management
- Threat Modeling
- Web Application Security
- API Security
Security Frameworks & Standards
- OWASP Top 10
- OWASP ASVS
- NIST Cybersecurity Framework
- NIST Secure Software Development Framework (SSDF)
- PCI DSS
- ISO 27001
Development & Technologies
- Knowledge of programming languages such as Java, .NET, Python, JavaScript, PHP, or Node.js.
- Understanding of web technologies, REST APIs, microservices, and cloud-native applications.
- Familiarity with CI/CD pipelines and DevSecOps practices.
Security Tools (Examples)
- Veracode
- Fortify
- Checkmarx
- SonarQube
- Burp Suite
- OWASP ZAP
- Nessus
- Qualys
- Rapid7
- GitHub Advanced Security
Soft Skills
- Strong analytical and problem-solving capabilities.
- Excellent communication and stakeholder management skills.
- Ability to explain technical security risks to both technical and non-technical audiences.
- Strong report writing and documentation skills.
- Ability to work independently while effectively collaborating with cross-functional teams.
- Strong attention to detail and commitment to continuous improvement.
Key Deliverables
- Regular application security assessment reports.
- Vulnerability management dashboards and remediation tracking reports.
- Secure coding guidance documentation.
- Compliance-aligned security evidence and audit support documentation.
- Security metrics and risk analysis reports.
- Continuous improvement recommendations for application security maturity.
Working Environment
- Primarily on-site customer-facing role.
- Close interaction with development, IT operations, infrastructure, cloud, and cybersecurity teams.
- Participation in security reviews, audits, remediation workshops, and technical support activities.
Experience Level: Mid-Level (3-5 Years)
Employment Type: Full-Time
Department: Cybersecurity / Application Security
Reporting To: Application Security Lead / Cybersecurity Manager