←  Back to all vacancies

Senior DevSecOps Engineer

JODAYN

Technology & IT

πŸ“ Saudi Arabia
πŸ’Ό Full-time
πŸ•’ Posted 11 days ago

Job description

Role Overview

Senior DevSecOps Engineer at JODAYN. The successful candidate will serve as the primary technical reference for the project and lead initiatives to enhance DevSecOps maturity across the organization.

Role Purpose

Integrate security practices and tools into CI/CD pipelines, manage vulnerability remediation processes, establish secure software development practices, and provide technical guidance and mentorship to security, development, and DevSecOps teams.

Key Responsibilities

DevSecOps Maturity & Assessment

  • Lead initiatives to improve and enhance DevSecOps maturity across the organization.
  • Conduct DevSecOps and Application Security maturity assessments against recognized frameworks and standards, including BSIMM 15, OWASP DSOMM, and OWASP DSOVS.
  • Assess control coverage, pipeline maturity, security practices, control duplication, and high-risk areas.
  • Identify gaps and improvement opportunities based on assessment findings.

Security Controls & Integration

  • Design, review, and coordinate the integration of security controls into CI/CD pipelines, including SAST, SCA, DAST, IAST, Secrets Management, and Infrastructure as Code (IaC) Scanning.
  • Lead the implementation, configuration, and optimization of application, API, and secure development security tools.

Vulnerability & Process Management

  • Establish and govern vulnerability triage, prioritization, tracking, and remediation processes with defined SLAs.
  • Monitor and report on Application Security KPIs, metrics, and DevSecOps maturity indicators.

Standards & Documentation

  • Develop and maintain technical standards, documentation, security guidelines, templates, checklists, and operational runbooks.
  • Support the alignment of security policies and standards with global best practices and applicable local regulatory requirements.

Mentorship & Guidance

  • Provide technical mentorship and guidance to DevSecOps, cybersecurity, and software development teams.
  • Lead knowledge transfer activities and provide technical guidance to client teams.
  • Promote secure software development practices throughout the Software Development Life Cycle (SDLC).

Qualifications & Experience

  • Minimum 7 years of relevant professional experience, including experience in Senior and/or Lead-level roles.
  • Proven experience leading Threat Modeling, secure design reviews, and end-to-end implementation of security tools.
  • Proven experience conducting DevSecOps and/or Application Security maturity assessments using frameworks such as BSIMM and/or OWASP DSOMM, including evidence collection, assessment, gap analysis, and reporting.
  • Experience defining, tracking, and reporting Application Security KPIs, metrics, and maturity indicators.
  • Experience developing, updating, and aligning security policies and technical standards with international best practices and local compliance requirements, including NCA requirements.
  • Strong practical experience in Secure Software Development and DevSecOps practices.

Skills & Competencies

  • Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
  • Strong understanding of integrating security tools into the SDLC, including SAST, SCA, DAST, IAST, Secrets Management, and IaC Scanning.
  • Good knowledge of security frameworks and standards, including OWASP SAMM, OWASP DSOMM, OWASP DSOVS, BSIMM, NIST SSDF, and NCA Cybersecurity Guidelines.
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
  • Strong written and verbal communication skills in English.
  • Arabic language proficiency is an advantage.

Additional Information

Professional Certifications

Candidates must hold at least two (2) certifications or recognized training credentials from the following list:

  • GCSA – GIAC Cloud Security Automation (SANS)
  • GDSA – GIAC Defensible Security Architecture (SANS)
  • DevSecOps Foundation / Professional – DevOps Institute
  • CSSLP – Certified Secure Software Lifecycle Professional (ISCΒ²)
  • GWEB – GIAC Web Application Defender (SANS)
  • OSWE – Offensive Security Web Expert
  • CKS – Certified Kubernetes Security Specialist
  • AZ-400 – Microsoft Azure DevOps Engineer Expert
  • AWS Certified DevOps Engineer – Professional
  • CISSP or CISM
  • Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP
  • Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDF

People looking at this role also searched

Report this job

⚑ Quick Apply

Create your account and upload your CV to apply for β€” takes less than a minute.

✨ Get a free AI ATS Score Report for your CV the moment you sign up.