Software Security Initiative (SSI) Lead
📣 Job Ad| Contract Type | Full-time | |
| Workplace type | On-site | |
| Location | Saudi Arabia |
Job Description
About the Role
JODAYN is seeking an experienced Software Security Initiative (SSI) Lead to establish and manage a centralized, measurable Application Security program for its client. This full-time role involves defining the strategic direction of the Application Security program and enhancing DevSecOps maturity based on industry frameworks.
Key Responsibilities
- Develop, maintain, and continuously improve the client's centralized Application Security Framework.
- Define and monitor Key Performance Indicators (KPIs) and Key Goal Indicators (KGIs) across Application Security functions.
- Review, update, and maintain Application Security policies, standards, and guidelines.
- Design and establish a multi-year DevSecOps maturity roadmap, including initiatives, ownership, priorities, and timelines.
- Design the Application Security Governance Framework and define a clear RACI matrix across Security, Development, and DevOps teams.
- Review and validate DevSecOps maturity assessment results based on BSIMM 15, OWASP DSOMM, or equivalent frameworks.
- Independently validate identified gaps, control duplication, and high-risk areas requiring executive management attention.
- Establish metrics to measure program maturity, security control coverage, and developer adoption.
- Review and align Application Security policies and standards with NCA, OWASP SAMM, and NIST SSDF.
- Develop and recommend developer enablement, incentive, and recognition programs to encourage adherence to secure coding standards and Application Security objectives.
- Design and deliver an Application Security Awareness Program targeting developers, testers, and product managers.
- Conduct periodic reviews with the client's senior management to communicate progress, challenges, risks, and next steps.
- Provide strategic recommendations to continuously improve the organization's Application Security and DevSecOps capabilities.
- Facilitate knowledge transfer to Security and DevOps teams to ensure sustainable ownership of the Application Security framework and roadmap.
Qualifications and Experience
- Minimum 6 years of professional experience in Application Security, including proven leadership experience.
- Proven experience leading enterprise-level Application Security or DevSecOps programs.
- Proven experience conducting, reviewing, or working with BSIMM and/or OWASP SAMM maturity assessments, or equivalent Application Security maturity frameworks.
- Strong experience designing Application Security frameworks, governance models, RACI matrices, KPI/KGI structures, and awareness programs.
- Proven ability to develop and execute multi-year Application Security and DevSecOps maturity roadmaps.
- Strong stakeholder management skills with experience engaging and communicating with senior and executive management.
- Strong practical experience in Secure Software Development and DevSecOps practices.
- Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
- Strong understanding of integrating security tools into the Software Development Life Cycle (SDLC), including SAST, SCA, DAST, Secrets Management, and Infrastructure as Code (IaC) Scanning.
- Strong knowledge of Application Security and cybersecurity frameworks and standards, including OWASP SAMM, OWASP DSOMM, OWASP DSOVS, BSIMM, NIST SSDF, and NCA Cybersecurity Guidelines.
- Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
Project Requirements
- Candidates will be subject to security screening and background verification before being granted access to client environments.
- Compliance with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) is required.
- All client data must remain within the Kingdom of Saudi Arabia.
- The successful candidate must comply with the client's internal policies, secure coding standards, change management procedures, and applicable governance frameworks, including OWASP, BSIMM, NIST SSDF, and NCA.
Requirements
- Requires 5-10 Years experience
Similar Jobs
You may also like
- Related Software Security Initiative (SSI) Lead Opportunities
- Cashier Jobs in Medina
- Human Resources Specialist Jobs in Medina
- Sales Representative Jobs in Medina
- Marketing Specialist Jobs in Medina
- Electrical Engineer Jobs in Medina
- Other Job Fields in
- Cashier Jobs in Medina
- Human Resources Specialist Jobs in Medina
- Sales Representative Jobs in Medina
- Marketing Specialist Jobs in Medina
- Electrical Engineer Jobs in Medina
- Architect Jobs in Medina
- Seller Jobs in Medina
- Pharmacist Jobs in Medina
- Administrative Assistant Jobs in Medina
- Cost Controller Jobs in Medina
- Explore Jobs Across Saudi Arabia
- Kindergarten Teacher Jobs in Riyadh
- Financial Manager Jobs in Riyadh
- Cost Accountant Jobs in Jeddah
- Network Engineer Jobs in Dammam
- QA/QC Manager Jobs in Jeddah
- Nurse Specialist Jobs in Abu Arish
- Architect Jobs in Dhahran
- Cashier Jobs in Jeddah
- Sales Representative Jobs in Unayzah
- Sales Executive Jobs in Jeddah