Application Security Specialist - Local - HQ Amman
Provide expertise in application security and vulnerability assessment
Overview
Provide expertise in application security and vulnerability assessment
You have:
- University degree in computer science, information technology, or a related discipline.
- 5-6 years of experience in application development or management area, including 3 years in web and mobile application security.
- Good command of spoken and written English.
- Experience with MS Azure DevOps, particularly integrating security tools into DevOps pipelines.
- Experience in using automated security tools for code analysis and vulnerability scanning.
Result of Service The consultant is responsible to one of IMTD’s Software Engineers or Senior Technical Leads. The consultant will provide specialized expertise in application security and ensure that sound security measures and controls are embedded in the application lifecycle.
Work Location HQA
Expected duration The duration of the consultancy is 6 months with the expected starting as soon as possible.
Duties and Responsibilities - Perform vulnerability assessment for web (.Net/SQL) and mobile (Android/IOS) applications through structured walkthroughs and through the use of automated tools. - Suggest and implement corrective measures for the vulnerabilities that have been identified in coordination with technical application managers. - Ensure that application security is embedded in the software lifecycle, especially during the early stages of projects, that is, during requirement collection and system design. - Suggest and help in the implementation of automated application security tools. - Create an application security standards document and related guidelines to ensure that these standards are observed during application development and operation phases. - Provide application security training for scrum and support teams. - Performs other related duties as required.
Qualifications/special skills Academic Qualifications:
A university degree from an accredited educational institution in computer science, information technology, or a related discipline.
DESIRABLE QUALIFICATIONS:
Experience in MS Azure DevOps, especially in integrating security tools in DevOps pipelines. Knowledge & experience in Agile Development.
COMPETENCIES
Planning and organizing. Applying technical expertise. Communications. Learning and researching.
Experience: 5-6 years of experience in the application development or management area, 3 of which must be in the area of web and mobile application security. Good experience in the use of automated security tools for code analysis and vulnerability scanning. Language: Good command of spoken and written English.
No Fee THE UNITED NATIONS DOES NOT CHARGE A FEE AT ANY STAGE OF THE RECRUITMENT PROCESS (APPLICATION, INTERVIEW MEETING, PROCESSING, OR TRAINING). THE UNITED NATIONS DOES NOT CONCERN ITSELF WITH INFORMATION ON APPLICANTS’ BANK ACCOUNTS.
Potential interview questions
| Can you explain a time when you identified a major security vulnerability? | This question assesses your hands-on experience with security vulnerabilities. | Describe the situation, your actions, and the outcome. |
| How do you integrate security measures in the application development lifecycle? | The interviewer wants to understand your approach to embedding security early in development. | Pro members can see the explanation. |
| What tools have you used for vulnerability scanning? | Pro members can see the explanation. | Pro members can see the explanation. |
| Describe your experience with Agile methodologies in software development. | Pro members can see the explanation. | Pro members can see the explanation. |
| How would you handle team training on application security standards? | Pro members can see the explanation. | Pro members can see the explanation. |