IT Application Security Specialist
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
About the Role
**Position Title:** IT Application Security Specialist **Department:** Information Security / Cybersecurity **Job Purpose:** The Application Security Architect is responsible for designing, implementing, and governing application security across enterprise systems, ensuring that all applications are secure by design and compliant with organizational and regulatory requirements. The role focuses on integrating security into the Software Development Lifecycle (SDL
Key Skills for This Role
Full Job Posting
Job Purpose
The Application Security Architect is responsible for designing, implementing, and governing application security across enterprise systems, ensuring that all applications are secure by design and compliant with organizational and regulatory requirements.
The role focuses on integrating security into the Software Development Lifecycle (SDLC), driving DevSecOps practices, and establishing secure architecture standards across cloud, on-premises, and hybrid environments.
1. Application Security Strategy
- Develop and maintain the enterprise Application Security program
- Define and implement secure-by-design principles across all applications
- Establish and monitor key security metrics (e.g., vulnerability reduction, remediation timelines)
- Continuously improve application security maturity
2. Security Architecture & Design
- Design and review secure architectures for applications, APIs, and microservices
- Lead threat modeling activities (e.g., STRIDE methodology)
- Define and enforce security design patterns, including authentication, encryption, and data protection
- Participate in architecture governance and review forums
3. DevSecOps & Secure SDLC
- Integrate security controls into CI/CD pipelines
- Implement and manage application security testing tools (SAST, DAST, SCA)
- Establish secure coding standards aligned with OWASP Top 10
- Automate security validation and enforcement across development pipelines
4. Cloud Security
- Design and implement secure cloud architectures across AWS and/or Azure environments
- Enforce Identity and Access Management (IAM) and Zero Trust principles
- Secure containerized environments (Kubernetes / OpenShift)
- Ensure effective monitoring, logging, and threat detection in cloud platforms
5. Security Testing & Assurance
- Coordinate vulnerability assessments, penetration testing, and application security reviews
- Ensure timely remediation and closure of identified vulnerabilities
- Validate security controls through regular testing and simulation exercises
6. Security Operations Integration
- Collaborate with SOC teams to enhance monitoring and incident response capabilities
- Support SIEM use case development and optimization
- Analyze security trends and proactively identify emerging risks
7. Governance, Risk & Compliance
- Ensure adherence to security standards and regulatory requirements, including:
- PCI DSS
- SWIFT CSP
- ISO 27001
- Support internal and external audits and regulatory assessments
- Develop and maintain security policies, standards, and procedures
8. Stakeholder Engagement & Awareness
- Provide security guidance to development, DevOps, and architecture teams
- Conduct training and awareness sessions on secure coding practices
- Act as a trusted advisor on application security matters
Qualifications & Experience
- Bachelor’s degree in computer science, Cybersecurity, Software Engineering, or a related field
- Minimum
- 8–12 years of experience
- in cybersecurity, with strong focus on:
- Application Security
- DevSecOps
- Cloud Security
- Experience in the
- banking or financial services sector preferred
Technical Skills
- Strong knowledge of:
- OWASP Top 10 and secure coding practices
- Secure SDLC and threat modeling techniques
- API and web application security
- Experience with application security tools:
- SAST, DAST, and SCA platforms
- Proficiency in cloud security (AWS / Azure)
- Knowledge of container security (Kubernetes / OpenShift)
- Familiarity with SIEM, vulnerability management, and security monitoring
Behavioral Competencies
- Strong analytical and problem-solving skills
- Effective communication and stakeholder management
- Ability to influence cross-functional teams
- Strong attention to detail and risk awareness
• CCSP (Certified Cloud Security Professional)
- CISM or CRISC
• CEH (Certified Ethical Hacker)
- Microsoft Azure Security Engineer (AZ-500) or AWS Security Specialty
Additional Information
- This role requires close collaboration with development, infrastructure, and security teams
- The position involves both strategic planning and hands-on technical contributions
- Experience in regulated environments is highly desirable
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at DOHA BANK
Transaction Monitoring Investigation Officer
Doha, QAT
Doha Bank is seeking a TM Investigation Officer to join our Compliance team. This role supports the Senior TM Investigation Officer in strengthening our Anti-Money Laundering (AML) and Countering Financing of Terrorism (
Section Head Data Governance
Doha, QAT
Section Head – Data Governance Unit Role Summary The Section Head – Data Governance Unit is responsible for leading and scaling the Bank’s enterprise data governance framework to ensure data quality, regulatory complianc
Data Steward
Doha, QAT
Role Summary The Data Steward is responsible for ensuring the accuracy, integrity, and governance of enterprise data assets by executing data governance policies and managing data quality at an operational level. This ro
Data Governance Officer
Doha, QAT
Data Governance Officer Role Summary The Data Governance Officer is responsible for executing and monitoring data governance policies across the bank to ensure data quality, integrity, and regulatory compliance. This rol
BCM Analyst
Doha, QAT
Role Objective The BCM Analys t will work closely with the Senior BCM Analyst and Section Head - Business Continuity in implementing and maintaining a Business Continuity program for the Bank, spanning domestic and overs
Head of Enterprise Architect
Doha, QAT
Department Head – Enterprise Architecture Location: Doha, Qatar Function: Technology & Operations – Information Technology Reporting Line: Chief Information Officer (CIO) Role Overview We are seeking a highly accomplishe
Section Head Fixed Income
Doha, QAT
Doha Bank is seeking an experienced Section Head – Fixed Income to lead the Bank’s Fixed Income portfolio strategy. This senior role carries overall responsibility for developing and implementing long-term investment str
Compliance Officer
Doha, QAT
The incumbent will support the Manager - FATCA/CRS & International Compliance in effective management and implementation of Foreign Account Tax Compliance Act (FATCA) and OECD Common Reporting Standard (CRS) across the D
Transaction Monitoring Investigation Officer
Doha, QAT
Section Head Data Governance
Doha, QAT
Data Steward
Doha, QAT
Data Governance Officer
Doha, QAT
BCM Analyst
Doha, QAT
Head of Enterprise Architect
Doha, QAT
Section Head Fixed Income
Doha, QAT
Compliance Officer
Doha, QAT