img
Contract TypeFull-time
Workplace typeOn-site
LocationSaudi Arabia

Job Description

About the Role

JODAYN is seeking an experienced Software Security Initiative (SSI) Lead to establish and manage a centralized, measurable Application Security program for its client. This full-time role involves defining the strategic direction of the Application Security program and enhancing DevSecOps maturity based on industry frameworks.

Key Responsibilities

  • Develop, maintain, and continuously improve the client's centralized Application Security Framework.
  • Define and monitor Key Performance Indicators (KPIs) and Key Goal Indicators (KGIs) across Application Security functions.
  • Review, update, and maintain Application Security policies, standards, and guidelines.
  • Design and establish a multi-year DevSecOps maturity roadmap, including initiatives, ownership, priorities, and timelines.
  • Design the Application Security Governance Framework and define a clear RACI matrix across Security, Development, and DevOps teams.
  • Review and validate DevSecOps maturity assessment results based on BSIMM 15, OWASP DSOMM, or equivalent frameworks.
  • Independently validate identified gaps, control duplication, and high-risk areas requiring executive management attention.
  • Establish metrics to measure program maturity, security control coverage, and developer adoption.
  • Review and align Application Security policies and standards with NCA, OWASP SAMM, and NIST SSDF.
  • Develop and recommend developer enablement, incentive, and recognition programs to encourage adherence to secure coding standards and Application Security objectives.
  • Design and deliver an Application Security Awareness Program targeting developers, testers, and product managers.
  • Conduct periodic reviews with the client's senior management to communicate progress, challenges, risks, and next steps.
  • Provide strategic recommendations to continuously improve the organization's Application Security and DevSecOps capabilities.
  • Facilitate knowledge transfer to Security and DevOps teams to ensure sustainable ownership of the Application Security framework and roadmap.

Qualifications and Experience

  • Minimum 6 years of professional experience in Application Security, including proven leadership experience.
  • Proven experience leading enterprise-level Application Security or DevSecOps programs.
  • Proven experience conducting, reviewing, or working with BSIMM and/or OWASP SAMM maturity assessments, or equivalent Application Security maturity frameworks.
  • Strong experience designing Application Security frameworks, governance models, RACI matrices, KPI/KGI structures, and awareness programs.
  • Proven ability to develop and execute multi-year Application Security and DevSecOps maturity roadmaps.
  • Strong stakeholder management skills with experience engaging and communicating with senior and executive management.
  • Strong practical experience in Secure Software Development and DevSecOps practices.
  • Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
  • Strong understanding of integrating security tools into the Software Development Life Cycle (SDLC), including SAST, SCA, DAST, Secrets Management, and Infrastructure as Code (IaC) Scanning.
  • Strong knowledge of Application Security and cybersecurity frameworks and standards, including OWASP SAMM, OWASP DSOMM, OWASP DSOVS, BSIMM, NIST SSDF, and NCA Cybersecurity Guidelines.
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell.

Project Requirements

  • Candidates will be subject to security screening and background verification before being granted access to client environments.
  • Compliance with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) is required.
  • All client data must remain within the Kingdom of Saudi Arabia.
  • The successful candidate must comply with the client's internal policies, secure coding standards, change management procedures, and applicable governance frameworks, including OWASP, BSIMM, NIST SSDF, and NCA.

Requirements

  • Requires 5-10 Years experience

Similar Jobs