Software Security Initiative (SSI) Lead
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 6+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are seeking a seasoned leader to spearhead a consolidated and measurable Application Security program. This individual will shape the strategic vision of the Application Security initiatives, enhance DevSecOps maturity using assessments such as BSIMM, OWASP DSOMM, and OWASP DSOVS, and set up governance frameworks, metrics, standards, and enablement efforts to ensure long-term adoption of secure software development practices throughout the organization.
Key Responsibilities
- Develop, maintain, and refine a centralized Application Security Framework tailored to the client.
- Set up and track Key Performance Indicators (KPIs) and Key Goal Indicators (KGIs) associated with Application Security activities.
- Continuously review and update Application Security policies, standards, and best practice guidelines.
- Plan and establish a multi-year DevSecOps maturity roadmap detailing initiatives, responsibilities, priorities, and timelines.
- Create an Application Security Governance Framework and define clear roles and responsibilities (RACI matrix) bridging Security, Development, and DevOps teams.
- Assess and validate DevSecOps maturity outcomes based on BSIMM 15, OWASP DSOMM, or similar frameworks, identifying risks and remediation needs.
- Manage duplication of controls and detect high-risk audit areas needing executive intervention.
- Define measurement methods for program maturity, security control coverage, and developer adoption levels.
- Ensure Application Security policies align with standards such as NCA, OWASP SAMM, and NIST SSDF.
- Design developer-focused enablement, incentive, and recognition schemes to promote compliance with secure coding practices.
- Develop and implement Application Security Awareness initiatives targeting developers, testers, and product managers.
- Regularly review program progress, challenges, risks, and future plans with senior leadership.
- Provide strategic guidance for continuous improvement of Application Security and DevSecOps capabilities.
- Transfer relevant knowledge to Security and DevOps teams to enable sustainable governance of Application Security frameworks and roadmaps.
Candidate Qualifications
- At least six years of professional experience in Application Security with demonstrated leadership skills.
- Proven track record managing enterprise-level Application Security or DevSecOps programs.
- Experience conducting or reviewing maturity assessments using BSIMM, OWASP SAMM, or similar frameworks.
- Expertise in designing Application Security frameworks, governance structures, and KPI/KGI systems, along with awareness programs.
- Ability to create and execute multi-year maturity roadmaps for Application Security and DevSecOps.
- Strong stakeholder engagement and executive communication capabilities.
- Practical experience implementing Secure Software Development and DevSecOps methodologies.
- Experience integrating security tools into CI/CD pipelines, including platforms like GitLab, Azure DevOps, and CloudBees.
- Knowledge of security tool categories such as SAST, SCA, DAST, Secrets Management, and Infrastructure as Code scanning.
- Thorough understanding of key cybersecurity frameworks and standards: OWASP SAMM, OWASP DSOMM, OWASP DSOVS, BSIMM, NIST SSDF, NCA Cybersecurity Guidelines.
- Proficiency in scripting and automation using Python, Bash, and/or PowerShell.
- Excellent written and spoken English communication skills; Arabic proficiency is a plus.
Preferred Certifications
- Holds at least two recognized certifications such as GCSA, GDSA, DevSecOps Foundation/Professional, CSSLP, GWEB, OSWE, CKS, AZ-400, AWS DevOps Engineer – Professional, CISSP or CISM (highly preferred), or recognized secure coding training from SANS, OWASP, or Secure Code Warrior.
- Formal training in BSIMM, OWASP SAMM, DSOMM, DSOVS, or NIST SSDF is strongly favored.
Additional Project Requirements
- Subject to security screening and background checks prior to accessing client systems.
- Compliance with National Cybersecurity Authority (NCA) Essential Cybersecurity Controls is mandatory.
- All client information must remain within Saudi Arabia's borders.
- The incumbent must abide by internal policies, secure coding standards, change management protocols, and all relevant governance frameworks such as OWASP, BSIMM, NIST SSDF, and NCA directives.
How they work
Communication
Leadership
Strategic Thinking
Relationship Building