كمهندس أمان تطبيقات في Luciq، ستُسهم في تشكيل وبناء برنامج أمان تطبيقاتنا إلى جانب الفريق الأوسع. هذا دور عملي عالي الملكية حيث ستعمل عن كثب مع فرق المنتجات والتطوير عبر دورة حياة تطوير البرمجيات كاملة، مع مراجعة التصاميم قبل كتابة الشفرة، وتحديد المخاطر أثناء تشكيل الميزات، وضمان تضمين الأمان في كيفية بناء البرمجيات وشحنها، وليس كخيار يضاف لاحقاً. تقنيتنا تستخدم Ruby on Rails وGo وPython، وتُنفَّذ على AWS مع Terraform كأداة لإدارة البنية التحتية كرمز وJenkins لتشغيل CI/CD. ستقرأ وتراجع الشفرة بلغات هذه اللغات وليس الاعتماد فقط على نتائج الماسح؛ وستعمل مع خدمات أمان AWS (SecurityHub وInspector وGuardDuty وCloudTrail وCloudFront) لتوفير الرؤية والحماية عبر بنيتنا التحتية. الدور يشمل تطبيقات الويب وواجهات برمجة التطبيقات وSDK المحمول لدينا (iOS وAndroid)، والسحابة وCI/CD بالشراكة مع المهندسين ومديري المنتجات والمنصة وفريق الأمن لجعل المسار الآمن هو المسار الافتراضي. يمكن شغل هذا الدور في مستوى متوسط مع مسار نمو واضح إلى مستوى سكري ووظيفته كخطة للوصول إلى مستوى أعلى عند تطويرك للمساهمة في تشكيل برنامج أمان التطبيقات لدينا، أو في المستوى العالي إذا كنت تعمل بالفعل ضمن هذا النطاق. ستنضم إلى فريق أمني بسيط، ما يعني التوسع خارج النواة AppSec للفرز الحادث، ومعالجة استبيانات أمان العملاء، أو دعم المراجعات المشتركة بين الأقسام والسحابة والامتثال. نحن نثمن هذا التنوع كجانب أساسي من الدور؛ إذا كنت تبحث عن عمل ذو تخصص عالٍ مقصور strictly على أمان التطبيق، قد لا يكون هذا هو الخيار المناسب.
الملف المرشح المطلوب
المتطلبات الأساسية
- الخبرة: 3-6 سنوات في أمان التطبيقات أو هندسة الأمان
- التعليم: درجة بكالوريوس في علوم الحاسوب، أمن المعلومات، أو خبرة عملية مكافئة
- مراجعة شفرة آمنة في واحدة على الأقل من: Python أو Ruby أو Go، يمكنها قراءة الشفرة واستنتاج الثغرات دون الاعتماد على مخرجات الماسح
- OWASP Top 10 (الويب وAPI) كنماذج جذرية للمشكلة، وليس قائمة تحقق محفوظة بما في ذلك SSRF، وتفكيك غير آمن، وأنواع الحقن، ومواطن ضعف التحكم بالوصول
- تخطيط التهديدات: خبرة عملية مع STRIDE ومخططات تدفق البيانات؛ يمكنه قيادة جلسة مع فريق المنتج وإنتاج مخرجات قابلة للتنفيذ
- المصادقة والهوية: عمق عمل في إدارة الجلسات ونماذج RBAC/ABAC
- أتمتة أمان CI/CD: خبرة عملية في دمج SAST وSCA وفحص الأسرار في خطوط الأنابيب وضبطها لإشارة قابلة للتنفيذ
- استباقية وتملك مسؤولية وعدم الانتظار لتحديد ما يجب تأمينه
- التكيف مع العمل عبر الفرق مع مهندسي المنتجات والمهندسين الأساسيين والفريق الأوسع
- قدرات تحليلية وحل مشكلات قوية
- الطلاقة في الإنجليزية، مع مهارات اتصال كتابية وشفوية قوية
- الاتصال: قدرة على شرح ثغرة لمهندس أو PM أو نائب الرئيس بوضوح كتابياً وشفوياً
التأهيل القوي+
نتوقع أن لدى المرشحين القويين بعض هذه المتطلبات وليس كلها. كلما زادت كلما كان أفضل.
- أمن SDK المحمول: OWASP Mobile Top 10 وMASVS/MASTG؛ Android (Kotlin) أو iOS (Swift)؛ خبرة مع Frida أو objection أو MobSF
- عمق خدمات أمان AWS: SecurityHub وInspector وGuardDuty وCloudTrail وCloudFront بخلاف IAM
- أساسيات أمان الحاويات وKubernetes
- عمق سلسلة التوريد: إطار SLSA، SBOM
- أمان AI/LLM: التخفيف من حقن الاستدعاءات، OWASP LLM Top 10، تأمين العماريات الذكية وحدود استخدام الأدوات
- إلمام بـ ISO 27001 أو SOC 2.
مثالي لو كان
- Terraform وسياسة كرموز: tfsec وCheckov وOPA/Conftest
- خبرة في بناء أو تهيئة برنامج أمان
- مشاركة في برامج الجوائز البرمجية، أو CVEs منشورة، أو أبحاث أمان موثقة
- شهادات عملية: OSCP وOSWE وeMAPT
- خبرة استجابة للحوادث: الفرز، الاحتواء، تحليل السبب الجذري
- خبرة في Red Teaming أو Purple Teaming
As an Application Security Engineer at Luciq, you will help shape and build our application security program alongside the wider team. This is a hands-on, high-ownership role where you will work closely with product and development teams across the full software development lifecycle reviewing designs before code is written, identifying risks as features take shape, and ensuring security is embedded into how we build and ship software, not bolted on after the fact. Our stack runs on Ruby on Rails, Go, and Python, deployed on AWS with Terraform managing infrastructure as code and Jenkins powering CI/CD. You will read and review code in these languages not just rely on scanner output and work with AWS security services (SecurityHub, Inspector, GuardDuty, CloudTrail, CloudFront) to provide visibility and protection across our infrastructure. The role spans web applications, APIs, our mobile SDK (iOS and Android), cloud, and CI/CD partnering with engineers, PMs, Platform, and the Security team to make the secure path the default path. This role can be filled at mid-level with a clear growth path to senior-level as you grow into shaping our application security program, or at senior-level if you're already operating at that scope. You will join a lean Security team, which entails stepping beyond core AppSec for incident triage, addressing customer security questionnaires, or supporting cross-functional cloud and compliance reviews. We value this variety as a core facet of the role; if you are seeking hyper-specialized work restricted strictly to application security, this may not be the right fit.
Desired Candidate Profile
Must-Haves
- Experience: 3-6 years in application security, or security engineering
- Education: Bachelor's degree in Computer Science, Information Security, or equivalent practical experience
- Secure code review in at least one of: Python, Ruby, Go can read code and reason about vulnerabilities, not rely on scanner output
- OWASP Top 10 (Web and API) as root-cause patterns, not a memorized checklist including SSRF, insecure deserialization, injection classes, and access-control flaws
- Threat modeling: practical experience with STRIDE and data flow diagrams; can lead a session with a product team and produce actionable output
- Auth and identity: working depth in session management, RBAC/ABAC models
- CI/CD security automation: hands-on experience integrating SAST, SCA, and secret scanning into pipelines and tuning for actionable signal
- Proactive and ownership-driven does not wait to be told what to secure
- Comfortable working cross-functionally with product engineers, platform engineers, and the wider team
- Strong analytical and problem-solving abilities
- Fluent in English, with strong written and verbal communication
- Communication: clear written and verbal communication can explain a vulnerability to an engineer, a PM, or a VP
Strong Plus
We expect strong candidates to have some of these not all. The more, the better.
- Mobile SDK security: OWASP Mobile Top 10 and MASVS/MASTG; Android (Kotlin) or iOS (Swift); experience with Frida, objection, or MobSF
- AWS security service depth: SecurityHub, Inspector, GuardDuty, CloudTrail, CloudFront beyond IAM
- Container and Kubernetes security fundamentals
- Supply chain depth: SLSA framework, SBOM
- AI/LLM security: prompt injection mitigations, OWASP LLM Top 10, securing agentic architectures and tool-use boundaries
- Familiarity with ISO 27001 or SOC 2.
Nice to Have
- Terraform and policy-as-code: tfsec, Checkov, OPA/Conftest
- Experience building or bootstrapping a security program
- Bug bounty participation, published CVEs, or documented security research
- Hands-on certifications: OSCP, OSWE, eMAPT
- Incident response experience triage, containment, root-cause analysis
- Red teaming or purple teaming experience