JODAYN | جودين

Senior DevSecOps Engineer

JODAYN | جودين

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
7+ yrs
Salary
—
Openings
1
Posted
1 week ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Job Overview

We are seeking a Senior DevSecOps Engineer to act as the key technical authority on our project and to spearhead efforts aimed at advancing DevSecOps maturity throughout the organization.

Key Responsibilities

  • Lead organizational initiatives to elevate DevSecOps maturity levels.
  • Perform assessments of DevSecOps and application security maturity using well-known frameworks and standards such as BSIMM 15, OWASP DSOMM, and OWASP DSOVS.
  • Evaluate control coverage, maturity of pipelines, security practices, duplication of controls, identify risk-prone segments, and pinpoint areas for enhancement.
  • Design, review, and oversee the incorporation of security controls within CI/CD pipelines including SAST, SCA, DAST, IAST, Secrets Management, and Infrastructure as Code scanning.
  • Establish and regulate processes for vulnerability triage, prioritization, tracking, and remediation backed by defined service level agreements.
  • Lead deployment, configuration, and tuning of application, API, and secure development security tools.
  • Create and maintain technical standards, documentation, guidelines, templates, checklists, and operational runbooks related to security.
  • Conduct knowledge sharing and provide technical guidance for client teams.
  • Offer technical mentorship to DevSecOps, cybersecurity, and software development teams.
  • Track and communicate Application Security KPIs, metrics, and DevSecOps maturity indicators.
  • Support alignment of security policies and standards with global best practices and local regulatory requirements.
  • Champion secure software development practices throughout the Software Development Life Cycle (SDLC).

Requirements and Qualifications

  • At least 7 years of relevant experience, including senior or lead positions.
  • Expertise in leading Threat Modeling, secure design reviews, and comprehensive security tool implementation.
  • Experience conducting DevSecOps or Application Security maturity assessments based on frameworks like BSIMM and OWASP DSOMM, including gathering evidence, performing gap analysis, and reporting.
  • Competence in defining, monitoring, and reporting AppSec KPIs, metrics, and maturity indicators.
  • Experience in formulating and aligning security policies and technical standards with international best practices and local compliance such as NCA requirements.
  • Strong hands-on experience with Secure Software Development and DevSecOps methodologies.
  • Familiarity with CI/CD platforms including GitLab, Azure DevOps, and CloudBees.
  • Solid understanding of security tool integration for SAST, SCA, DAST, IAST, Secrets Management, and IaC Scanning within SDLC.
  • Knowledge of security frameworks like OWASP SAMM, DSOMM, DSOVS, BSIMM, NIST SSDF, and NCA Cybersecurity Guidelines.
  • Proficiency in scripting and automation with Python, Bash, or PowerShell.
  • Excellent English communication skills; proficiency in Arabic is a plus.

Preferred Certifications

  • Must possess at least two certifications or recognized trainings from the following list: GCSA, GDSA, DevSecOps Foundation/Professional, CSSLP, GWEB, OSWE, CKS, AZ-400, AWS Certified DevOps Engineer Professional, CISSP or CISM, recognized secure coding training (SANS, Secure Code Warrior, or OWASP), formal trainings in BSIMM, OWASP SAMM, DSOMM, DSOVS, or NIST SSDF.

How they work

Communication Leadership

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer