img
Contract TypeFull-time
Workplace typeRemote
LocationRiyadh

Job Description

About Darb

Darb is a SAMA-regulated fintech company based in Riyadh, Saudi Arabia, specializing in building secure and compliant payments infrastructure. Security is a foundational principle for all operations and products within the organization.

The Opportunity: Senior DevSecOps Engineer

Darb is seeking a Senior DevSecOps Engineer to join our full-time team in Riyadh, Saudi Arabia. This role involves owning and strengthening our cloud infrastructure, operating at the intersection of platform engineering, security operations, and compliance. The successful candidate will be responsible for writing infrastructure as code, securing CI/CD pipelines, and developing detection capabilities to maintain a secure, regulated payments platform.

This is a hands-on senior position requiring direct engagement with Terraform deployments, Splunk detection tuning, and incident response.

Key Responsibilities

  • Design, build, and secure GCP infrastructure, including GKE, VPC networking, IAM, and Cloud Armor WAF.
  • Manage infrastructure as code using Terraform, focusing on reusable modules, remote state management, drift detection, and policy-as-code guardrails.
  • Develop and harden CI/CD pipelines in GitHub Actions, implementing least-privilege workflows (OIDC / Workload Identity Federation), secrets management, and supply chain security.
  • Operate and enhance the Splunk SIEM, covering log onboarding, detection engineering, alert tuning, and dashboarding.
  • Lead security hardening efforts across the technology stack, including workload identity, secret management, network segmentation, WAF rules, and Kubernetes security policies.
  • Support SAMA CSF compliance initiatives through control implementation, evidence collection, and audit readiness.
  • Participate in incident response activities, including triage, containment, root cause analysis, and blameless post-mortems.
  • Drive observability and reliability improvements, establishing SLOs, alerting mechanisms, and capacity planning for production workloads.

Required Qualifications and Experience

  • Minimum of 5 years of experience in DevOps, DevSecOps, SRE, or platform engineering roles.
  • Extensive hands-on experience with GCP services, including GKE, IAM, VPC, Cloud Armor, Cloud Logging, and Monitoring.
  • Proven production experience with Terraform, encompassing module design, state management, and CI-driven plan/apply workflows.
  • Strong proficiency with GitHub Actions, including pipeline security and runner management.
  • Working knowledge of Splunk, including SPL, alerting, and building or tuning detections.
  • Solid understanding of Kubernetes fundamentals, such as RBAC, network policies, and workload hardening.
  • Scripting ability in Bash and/or Python.
  • Experience operating in regulated or high-compliance environments, such as fintech or banking.
  • Clear written communication skills for documentation, runbooks, post-mortems, and audit materials.

Preferred Skills and Certifications

  • Certifications such as GCP Professional Cloud Security Engineer, CKA/CKS, or HashiCorp Terraform Associate.
  • Direct experience with SAMA CSF, PCI DSS, or comparable regulatory frameworks.
  • Background in detection engineering (*, Sigma rules, MITRE ATT&CK mapping).
  • Experience with zero-trust networking principles.
  • Exposure to payments infrastructure or fraud/abuse detection systems.

Our Hiring Process

The hiring process is designed to be efficient and respectful of your time, comprising the following stages:

  1. Shortlisting: Review of your application and experience.
  2. Technical Assessment: A practical, scenario-based evaluation.
  3. Technical Interview: An in-depth discussion with the engineering team covering architecture, security, and problem-solving approaches.

Requirements

  • Requires 5-10 Years experience

Similar Jobs