JODAYN | جودين
الرياض / Global
Senior devsecops engineer
- ر.س.420000 SAR
الرياض / Global
Job Description We are looking for a Senior Dev Sec Ops Engineer to serve as the primary technical reference for the project and lead initiatives to enhance Dev Sec Ops maturity across the organization. The successful candidate will be responsible for integrating security practices and tools into CI/CD pipelines, managing vulnerability remediation processes, establishing secure software development practices, and providing technical guidance and mentorship to security, development, and Dev Sec Ops teams. Requirements Lead initiatives to improve and enhance Dev Sec Ops maturity across the organization Conduct Dev Sec Ops and Application Security maturity assessments against recognized frameworks and standards, including BSIMM 15, OWASP DSOMM, and OWASP DSOVS Assess control coverage, pipeline maturity, security practices, control duplication, and high-risk areas, and identify gaps and improvement opportunities Design, review, and coordinate the integration of security controls into CI/CD pipelines, including: SAST SCA DAST IAST Secrets Management Infrastructure as Code (Ia C) Scanning Establish and govern vulnerability triage, prioritization, tracking, and remediation processes, including defined SLAs Lead the implementation, configuration, and optimization of application, API, and secure development security tools Develop and maintain technical standards, documentation, security guidelines, templates, checklists, and operational runbooks Lead knowledge transfer activities and provide technical guidance to client teams Provide technical mentorship and guidance to Dev Sec Ops, cybersecurity, and software development teams Monitor and report on Application Security KPIs, metrics, and Dev Sec Ops maturity indicators Support the alignment of security policies and standards with global best practices and applicable local regulatory requirements Promote secure software development practices throughout the Software Development Life Cycle (SDLC) Requirements & Qualifications Minimum 7 years of relevant professional experience, including experience in Senior and/or Lead-level roles Proven experience leading Threat Modeling, secure design reviews, and end-to-end implementation of security tools Proven experience conducting Dev Sec Ops and/or Application Security maturity assessments using frameworks such as BSIMM and/or OWASP DSOMM, including evidence collection, assessment, gap analysis, and reporting Experience defining, tracking, and reporting Application Security KPIs, metrics, and maturity indicators Experience developing, updating, and aligning security policies and technical standards with international best practices and local compliance requirements, including NCA requirements Strong practical experience in Secure Software Development and Dev Sec Ops practices Proven experience working with CI/CD platforms such as Git Lab, Azure Dev Ops, and/or Cloud Bees Strong understanding of integrating security tools into the SDLC, including SAST, SCA, DAST, IAST, Secrets Management, and Ia C Scanning Good knowledge of security frameworks and standards, including: OWASP SAMM OWASP DSOMM OWASP DSOVS BSIMM NIST SSDF NCA Cybersecurity Guidelines Proficiency in automation and scripting using Python, Bash, and/or Power Shell Strong written and verbal communication skills in English Arabic language proficiency is an advantage Preferred / Required Professional Certifications Candidates must hold at least two (2) certifications or recognized training credentials from the following list: GCSA - GIAC Cloud Security Automation (SANS) GDSA - GIAC Defensible Security Architecture (SANS) Dev Sec Ops Foundation / Professional - Dev Ops Institute CSSLP - Certified Secure Software Lifecycle Professional (ISC²) GWEB - GIAC Web Application Defender (SANS) OSWE - Offensive Security Web Expert CKS - Certified Kubernetes Security Specialist AZ-400 - Microsoft Azure Dev Ops Engineer Expert AWS Certified Dev Ops Engineer - Professional CISSP or CISM Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDF #J-18808-Ljbffr
الرياض / Global
الرياض / Global
Saudi Arabia / Global
الرياض / Global
Saudi Arabia / Global
الرياض / Global