Secure Source Code Reviewer (SAST Specialist)
Client of Salt
Employer Active
Posted 2 hrs ago
Send me Jobs like this
Experience
3 - 7 Years
Job Location
Education
Bachelor of Science(Computers)
Nationality
Any Nationality
Gender
Not Mentioned
Vacancy
1 Vacancy
Job Description
Roles & Responsibilities
You will conduct in-depth manual secure code reviews across technologies including Java/Spring Boot, JavaScript/Node.js, Python, Go, TypeScript, and C#, validating SAST findings, eliminating false positives, and identifying deeper vulnerabilities related to insecure authentication flows, cryptographic misuse, insecure design patterns, and business logic weaknesses.
You will work closely with Security Engineering and DevSecOps teams to improve detection quality, reduce alert fatigue, and help development teams remediate vulnerabilities effectively.
Key Responsibilities:
- Perform detailed manual secure code reviews across critical application components and APIs
- Review authentication and authorization mechanisms, cryptographic implementations, and sensitive data handling logic
- Validate and triage findings generated by SAST tools including Fortify SCA, Semgrep, CodeQL, and GitLab SAST
- Differentiate true positives from false positives and provide developers with clear remediation guidance
- Develop and maintain secure coding standards and framework-specific hardening guidance
- Support engineering teams through secure coding workshops and developer remediation sessions
- Collaborate with DevSecOps teams to improve SAST rule tuning, detection accuracy, and pipeline effectiveness
- Participate in application security architecture reviews and threat modelling exercises
- Contribute to improving the organisation s secure development lifecycle maturity in alignment with NIST SSDF, ISO 27001, and OWASP SAMM
Key Objectives:
- Improve the signal-to-noise ratio of SAST findings
- Reduce false positives across the secure development pipeline
- Ensure all critical-path modules undergo secure code review on a defined rotation
- Raise the overall secure coding maturity across engineering teams
- Identify design- and logic-level vulnerabilities missed by automated tooling
Desired Candidate Profile
Minimum 3+ years of hands-on secure code review experience
- Strong knowledge of OWASP Top 10 and secure software development principles
- Deep technical expertise across:
- Java / Spring Boot
- JavaScript / Node.js
- Python
- Go
- C#
- REST APIs and microservices architectures
- Keycloak
- Strong understanding of:
- Authentication and authorization flows
- Cryptography implementation and misuse
- API security vulnerabilities
- Secure design principles
- Experience using SAST platforms such as:
- Fortify SCA
- Semgrep
- CodeQL
- GitLab SAST
- Strong scripting and automation capability using Python, Bash, or PowerShell
- Familiarity with NIST CSF 2.0, ISO 27001, MITRE ATT&CK, and UAE IA Regulation
- Relevant security certifications such as OSCP, CISSP, GCIH, or CCSP are advantageous
- Excellent communication skills with the ability to work directly with both engineers and senior stakeholders
Company Industry
- IT - Software Services
Department / Functional Area
- IT Software
Keywords
- Secure Source Code Reviewer (SAST Specialist)
Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com
Client of Salt
We are currently supporting a key enterprise client in Abu Dhabi that is looking to hire an experienced strong>Secure Source Code Reviewer (SAST Specialist)/strong> to join their Information Security function on an initial 12-month contract.
https://welovesalt.com/jobs/secure-source-code-reviewer-sast-specialist-713200