img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role

Riyad Bank is seeking a Cyber Security DevOps Lead to join their team in Riyadh, Saudi Arabia. This full-time role involves assisting, reviewing, and validating the implementation of cybersecurity requirements across development activities within Business Technology.

Key Responsibilities

  • Follow all relevant departmental policies, processes, standard operating procedures, and instructions to ensure controlled and consistent work execution.
  • Support day-to-day operations to ensure work continuity.
  • Contribute to projects and change initiatives by preparing technical plans and applying cybersecurity and DevOps design principles.
  • Select appropriate testing approaches for automated testing of cybersecurity controls and countermeasures within the DevOps pipeline.
  • Analyze and report on test activities, results, issues, and risks for cybersecurity initiatives within the DevOps pipeline.
  • Plan the capture and management of configuration items and related information for cybersecurity controls and countermeasures within the DevOps pipeline.
  • Develop, configure, and maintain tools (including automation) to identify, track, log, and maintain accurate, complete, and current information for cybersecurity controls and countermeasures within the DevOps pipeline.
  • Report on the status of configuration management, identify problems and issues, recommend corrective actions, and report on progress of cybersecurity initiatives.
  • Assess and analyze release components for input to release scheduling, and administer tools and methods for cybersecurity software delivery, deployment, and configuration of the DevOps pipeline.
  • Conduct vulnerability and baseline configuration scanning, change-related penetration, and security testing activities, including initial information gathering and standard probing.
  • Engage with engineering/product teams to resolve identified security vulnerabilities.
  • Assist in embedding security as part of agile deployment, covering sprint planning, defining security user stories and test cases, and participating in scrum cadence and sprint retrospectives.
  • Utilize security testing and code scanning tools to conduct code reviews.
  • Perform secure program testing, review, and/or assessment to identify potential flaws in codes and mitigate vulnerabilities.
  • Address security implications in the software acceptance phase, including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing.
  • Perform risk analysis (*, threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
  • Apply coding and testing standards, apply security testing tools including "fuzzing" static-analysis code scanning tools, and conduct code reviews.
  • Contribute to identifying opportunities for continuous improvement of processes and practices, considering international best practices, business process improvement, cost reduction, and productivity improvement.
  • Assist in preparing timely and accurate reports for Riyad Bank to meet company and department requirements, policies, and standards.
  • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls.

Qualifications and Experience

  • A minimum of 5-10 years of relevant experience is required for this role.

Work Environment

This is a full-time position based in Riyadh, Saudi Arabia, focusing on cybersecurity within the Business Technology department.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة