Apply now »

Application Security Consultant Job

Date:  25 Aug 2026
Custom Field 1:  680865
Location: 

Riyadh, SA

Facility:  Technology & Engineering

 

Job Description

OVERVIEW

Job Title

Consultant

Job Code

680865

Grade

I3

Group

-

Division

Legal, Risk & Governance

Department

Cybersecurity

Unit

Application Security

 

ROLE PURPOSE

The aim is to state the overall significance of the job from the organization’s perspective.

The role exists to perform application security assessments and support the integration of security throughout the software development lifecycle by identifying application vulnerabilities, conducting code and design reviews, assessing APIs and integrations, and providing security guidance to development teams to strengthen the security of Elm's applications and digital solutions.

 

KEY ACCOUNTABILITIES & ACTIVITIES

This section describes the principal outputs required from the job.

Key Accountabilities

Key Activities

  1. Application Security Assessment
  • Perform security assessments for applications and digital solutions.
  • Evaluate applications against approved security requirements and standards.
  • Document identified vulnerabilities, risks, and recommended remediation actions.
  1. Secure Code Review
  • Conduct security-focused source code reviews to identify vulnerabilities and insecure coding practices.
  • Assess code against secure coding standards and common application security risks.
  • Provide remediation guidance to development teams.
  1. Threat Modeling
  • Conduct threat modeling for new and existing applications and services.
  • Identify potential attack scenarios, threats, and security control gaps.
  • Recommend security controls based on identified risks.
  1. Application Vulnerability Management
  • Identify, analyze, and assess application-layer vulnerabilities.
  • Coordinate with development teams on vulnerability remediation activities.
  • Validate remediation and monitor outstanding application security findings.
  1. API & Integration Security
  • Assess APIs, microservices, and third-party integrations for cybersecurity risks.
  • Evaluate authentication, authorization, data protection, and integration controls.
  • Recommend appropriate security improvements.
  1. Secure Design & Development Advisory
  • Provide security guidance to development and engineering teams throughout the development lifecycle.
  • Support the application of secure design and development practices.
  • Recommend security controls appropriate to solution risks and requirements.
  1. Application Security Standards & Frameworks
  • Develop and maintain application security standards, guidelines, and technical requirements.
  • Support alignment with secure software development practices and applicable cybersecurity standards.
  • Evaluate emerging application security practices and recommend enhancements.
  1. Developer Security Awareness
  • Support secure coding awareness and technical security training for developers.
  • Develop security guidance and knowledge materials addressing common application vulnerabilities.
  • Promote secure development practices across engineering teams.
  1. Policies, Processes & Procedures
  • Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.
  • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.
  1. Information Security
  • Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.

 

 

JOB SPECIFICATIONS

Academic and professional qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field.
  • Professional certifications in Application Security, Secure Software Development, or related cybersecurity disciplines are considered an advantage.

Years and Nature of Experience

  • 4–6 years of experience in application security, secure software development, security assessments, vulnerability management, or related cybersecurity domains.

 

 


Job Segment: Information Security, Software Engineer, Computer Science, Engineer, Consulting, Technology, Engineering, Service

Apply now »