img
Contract TypeFull-time
Workplace typeOn-site
LocationSaudi Arabia

Job Description

About the Role

JODAYN is seeking a Senior DevSecOps Engineer to serve as the primary technical reference for projects and lead initiatives to enhance DevSecOps maturity across the organization. This full-time role involves integrating security practices and tools into CI/CD pipelines, managing vulnerability remediation, and establishing secure software development practices. The successful candidate will also provide technical guidance and mentorship to security, development, and DevSecOps teams.

Key Responsibilities

  • Lead initiatives to improve and enhance DevSecOps maturity throughout the organization.
  • Conduct DevSecOps and Application Security maturity assessments against recognized frameworks such as BSIMM 15, OWASP DSOMM, and OWASP DSOVS.
  • Assess control coverage, pipeline maturity, security practices, control duplication, and high-risk areas, identifying gaps and improvement opportunities.
  • Design, review, and coordinate the integration of security controls into CI/CD pipelines, including SAST, SCA, DAST, IAST, Secrets Management, and Infrastructure as Code (IaC) Scanning.
  • Establish and govern vulnerability triage, prioritization, tracking, and remediation processes, including defined SLAs.
  • Lead the implementation, configuration, and optimization of application, API, and secure development security tools.
  • Develop and maintain technical standards, documentation, security guidelines, templates, checklists, and operational runbooks.
  • Lead knowledge transfer activities and provide technical guidance to client teams.
  • Provide technical mentorship and guidance to DevSecOps, cybersecurity, and software development teams.
  • Monitor and report on Application Security KPIs, metrics, and DevSecOps maturity indicators.
  • Support the alignment of security policies and standards with global best practices and applicable local regulatory requirements.
  • Promote secure software development practices throughout the Software Development Life Cycle (SDLC).

Required Qualifications and Experience

  • Minimum of 7 years of relevant professional experience, including experience in Senior and/or Lead-level roles.
  • Proven experience leading Threat Modeling, secure design reviews, and end-to-end implementation of security tools.
  • Demonstrated experience conducting DevSecOps and/or Application Security maturity assessments using frameworks such as BSIMM and/or OWASP DSOMM, including evidence collection, assessment, gap analysis, and reporting.
  • Experience defining, tracking, and reporting Application Security KPIs, metrics, and maturity indicators.
  • Experience developing, updating, and aligning security policies and technical standards with international best practices and local compliance requirements, including NCA requirements.
  • Strong practical experience in Secure Software Development and DevSecOps practices.
  • Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
  • Strong understanding of integrating security tools into the SDLC, including SAST, SCA, DAST, IAST, Secrets Management, and IaC Scanning.
  • Good knowledge of security frameworks and standards, including OWASP SAMM, OWASP DSOMM, OWASP DSOVS, BSIMM, NIST SSDF, and NCA Cybersecurity Guidelines.
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
  • Strong written and verbal communication skills in English are required.
  • Arabic language proficiency is considered an advantage.

Requirements

  • Requires 5-10 Years experience

Similar Jobs