This is a remote position.
Strengthen cloud, application, and AI security by embedding practical controls across infrastructure, delivery pipelines, and incident workflows.
Organization: A confidential client; further details will be shared with shortlisted candidates, subject to client confidentiality requirements
Location: Remote - open to candidates in Egypt, Jordan, and other countries nearshore to the client's operating region
Role Type: Full-time | Consultant/contractor | Fixed-term project (6-8 months)
Reports to: To be confirmed
The opportunity
Our client is looking for a Middle+ Security Engineer to assess and reduce security risk across AWS infrastructure, application delivery, containers, and LLM/AI integrations. In this role, you will combine hands-on security engineering with automation, vulnerability remediation, and cross-functional technical review.
About the organization
Our client is a UAE-based HRTech scale-up transforming workplace operations across HR, Payroll, Finance, and Insurance in the MENA region. It helps employers and employees manage the full workplace lifecycle through a unified platform.
What you will do
- Conduct threat modeling and security reviews for cloud infrastructure and LLM/AI integrations.
- Integrate SAST, DAST, and SCA tools directly into CI/CD pipelines.
- Harden AWS environments, Infrastructure as Code scripts, and Kubernetes workloads and containers.
- Automate repetitive security tasks, alerting, and incident-response workflows using custom scripts.
- Triage, investigate, and remediate vulnerabilities identified through automated scans and Bug Bounty programs.
What you bring
- At least 3 years of professional experience in Security Engineering, DevSecOps, or a related role.
- Scripting proficiency in Python, Go, or Ruby.
- Deep hands-on experience with AWS cloud security services (IAM, VPC, GuardDuty, WAF, Inspector).
- Practical experience with AppSec tooling (Burp Suite, OWASP ZAP, Snyk, or SonarQube).
- Experience with container and orchestration security controls (Docker, Kubernetes).
- Knowledge of Infrastructure as Code (IaC) security reviews (Terraform or CloudFormation).
- Familiarity with AI/LLM security risks (OWASP Top 10 for LLMs, RAG architectures, API security).
How the engagement works
Contracting party: You will contract directly with Apricot, which will manage contracting, invoicing/payroll, payments, and administrative support. Day to day, you will work closely with the client team and follow the agreed scope, deliverables, and security requirements.
You are expected to provide your own laptop and basic equipment, maintain reliable connectivity and a secure working environment, and follow required security controls, including two-factor authentication.
Planned check-ins are at month 1 to see how the engagement is working and help address issues, given the shorter 6–8 month duration.
About Apricot
Apricot is a nonprofit sourcing firm connecting displaced and underserved professionals from Palestine and the wider MENA region with global employment opportunities. We combine a clear social-impact mission with fast, high-quality recruitment delivery for international clients.