Software Security Initiative (SSI) Lead
📣 إعلان| نوع العقد | دوام كامل | |
| طبيعة الوظيفة | بالموقع | |
| الموقع | الرياض |
وصف الوظيفة
About the Role
Jodayn is seeking an experienced Software Security Initiative (SSI) Lead to establish and manage a centralized, measurable Application Security program for a client in Riyadh, Saudi Arabia. This full-time role requires a professional with 5-10 years of experience to define the strategic direction of the Application Security program and strengthen DevSecOps maturity. The SSI Lead will be responsible for governance, metrics, standards, and enablement programs to drive the adoption of secure software development practices across the organization.
Key Responsibilities
- Develop, maintain, and continuously improve the client's centralized Application Security Framework.
- Define and monitor Key Performance Indicators (KPIs) and Key Goal Indicators (KGIs) across Application Security functions.
- Review, update, and maintain Application Security policies, standards, and guidelines.
- Design and establish a multi-year DevSecOps maturity roadmap, including initiatives, ownership, priorities, and timelines.
- Design the Application Security Governance Framework and define a clear RACI matrix across Security, Development, and DevOps teams.
- Review and validate DevSecOps maturity assessment results based on BSIMM 15, OWASP DSOMM, or equivalent frameworks.
- Independently validate identified gaps, control duplication, and high-risk areas requiring executive management attention.
- Establish metrics to measure program maturity, security control coverage, and developer adoption.
- Review and align Application Security policies and standards with NCA, OWASP SAMM, and NIST SSDF.
- Develop and recommend developer enablement, incentive, and recognition programs to encourage adherence to secure coding standards and Application Security objectives.
- Design and deliver an Application Security Awareness Program targeting developers, testers, and product managers.
- Conduct periodic reviews with the client's senior management to communicate progress, challenges, risks, and next steps.
- Provide strategic recommendations to continuously improve the organization's Application Security and DevSecOps capabilities.
- Facilitate knowledge transfer to Security and DevOps teams to ensure sustainable ownership of the Application Security framework and roadmap.
Qualifications and Requirements
- Minimum of 6 years of professional experience in Application Security, including proven leadership experience.
- Proven experience leading enterprise-level Application Security or DevSecOps programs.
- Proven experience conducting, reviewing, or working with BSIMM and/or OWASP SAMM maturity assessments, or equivalent Application Security maturity frameworks.
- Strong experience designing Application Security frameworks, governance models, RACI matrices, KPI/KGI structures, and awareness programs.
- Proven ability to develop and execute multi-year Application Security and DevSecOps maturity roadmaps.
- Strong stakeholder management skills with experience engaging and communicating with senior and executive management.
- Strong practical experience in Secure Software Development and DevSecOps practices.
- Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
- Strong understanding of integrating security tools into the Software Development Life Cycle (SDLC), including SAST, SCA, DAST, Secrets Management, and Infrastructure as Code (IaC) Scanning.
- Strong knowledge of Application Security and cybersecurity frameworks and standards, including OWASP SAMM, OWASP DSOMM, OWASP DSOVS, BSIMM, NIST SSDF, and NCA Cybersecurity Guidelines.
- Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
- Strong written and verbal communication skills in English.
Project-Specific Requirements
- Candidates will be subject to security screening and background verification before being granted access to client environments.
- Compliance with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) is required.
- All client data must remain within the Kingdom of Saudi Arabia.
- The successful candidate must comply with the client's internal policies, secure coding standards, change management procedures, and applicable governance frameworks, including OWASP, BSIMM, NIST SSDF, and NCA.
متطلبات الوظيفة
- تتطلب ٥-١٠ سنوات خبرة
وظائف مشابهة
قد يعجبك أيضاً
- وظائف ذات صلة بـ Software Security Initiative (SSI) Lead
- وظائف أخصائي إدارة حسابات تواصل إجتماعي في تبوك
- وظائف بائع في تبوك
- وظائف مهندس مدني في تبوك
- وظائف مندوب مبيعات في تبوك
- وظائف GIS Specialist في تبوك
- مجالات وظيفية أخرى في الرياض
- وظائف أخصائي إدارة حسابات تواصل إجتماعي في الرياض
- وظائف صانع محتوى للتواصل الاجتماعي في الرياض
- وظائف مدير مشتريات في الرياض
- وظائف أخصائي تسويق في الرياض
- وظائف مهندس معماري في الرياض
- وظائف بائع في الرياض
- وظائف Key Account Manager في الرياض
- وظائف Sales Manager في الرياض
- وظائف Data Scientist في الرياض
- وظائف Brand Manager في الرياض
- استكشف الوظائف في أنحاء المملكة
- وظائف فني كهربائي تمديدات كهربائية في الخرمة
- وظائف Document Controller في الرياض
- وظائف ميكانيكي تدفئة وتهوية وتكييف في الدمام
- وظائف أخصائي علاج نفسي في النعيرية
- وظائف اخصائي علاج طبيعي في المبرز
- وظائف فني تعقيم في المبرز
- وظائف أخصائي علاج نفسي في مكة المكرمة
- وظائف مدرب معتمد في خميس مشيط
- وظائف Quality Engineer في الرياض
- وظائف مهندس ميكانيكي في ثادق
