img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role

Jodayn is seeking a Senior DevSecOps Engineer to join our team in Riyadh, Saudi Arabia. This full-time position requires 5-10 years of experience and involves serving as the primary technical reference for projects and leading initiatives to enhance DevSecOps maturity across the organization.

Role Overview

The successful candidate will be responsible for integrating security practices and tools into CI/CD pipelines. This includes managing vulnerability remediation processes, establishing secure software development practices, and providing technical guidance and mentorship to security, development, and DevSecOps teams.

Key Responsibilities

  • Lead initiatives to improve and enhance DevSecOps maturity across the organization.
  • Conduct DevSecOps and Application Security maturity assessments against recognized frameworks and standards, including BSIMM 15, OWASP DSOMM, and OWASP DSOVS.
  • Assess control coverage, pipeline maturity, security practices, control duplication, and high-risk areas, identifying gaps and improvement opportunities.
  • Design, review, and coordinate the integration of security controls into CI/CD pipelines, including SAST, SCA, DAST, IAST, Secrets Management, and Infrastructure as Code (IaC) Scanning.
  • Establish and govern vulnerability triage, prioritization, tracking, and remediation processes, including defined SLAs.
  • Lead the implementation, configuration, and optimization of application, API, and secure development security tools.
  • Develop and maintain technical standards, documentation, security guidelines, templates, checklists, and operational runbooks.
  • Lead knowledge transfer activities and provide technical guidance to client teams.
  • Provide technical mentorship and guidance to DevSecOps, cybersecurity, and software development teams.
  • Monitor and report on Application Security KPIs, metrics, and DevSecOps maturity indicators.
  • Support the alignment of security policies and standards with global best practices and applicable local regulatory requirements.
  • Promote secure software development practices throughout the Software Development Life Cycle (SDLC).

Experience and Qualifications

  • A minimum of 5 to 10 years of experience in a relevant field.
  • Demonstrated experience in DevSecOps practices and application security.
  • Proficiency in integrating security tools into CI/CD pipelines.
  • Strong understanding of vulnerability management and remediation processes.

Work Environment

This is a full-time position based in Riyadh, Riyadh, Saudi Arabia. The role involves working within a team-oriented environment, collaborating with various technical departments.

Application Process

Salary details for this position will be disclosed during the interview process. Interested candidates are encouraged to apply.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة