Enable job alerts via email!

Application Security Engineer

Emdad By Elm

Riyadh

On-site

SAR 200,000 - 300,000

Full time

Today
Be an early applicant

Job summary

A technology solutions provider in Riyadh is seeking a skilled DevSecOps Engineer to design and manage secure software delivery practices. You will focus on integrating security into CI/CD pipelines, automating testing, and ensure compliance with industry standards. The ideal candidate has 4-6 years of experience in DevSecOps and strong scripting abilities. This role offers an opportunity to work collaboratively across IT and operations teams.

Qualifications

  • 4–6 years of experience in DevSecOps, Application Security, or related roles.
  • Hands-on expertise with security tools in DevSecOps.
  • Familiarity with compliance standards like CIS, NIST, and ISO.

Responsibilities

  • Onboard and integrate projects into the DevSecOps tool chain.
  • Automate security testing in CI/CD pipelines.
  • Conduct vulnerability assessments using security tools.

Skills

SAST tools
DAST tools
IAST Seeker
SCA
RASP tools
Scripting (Python)
Scripting (Bash)
Scripting (PowerShell)
Agile methodologies

Education

Bachelor’s degree in Computer Science

Tools

Qradar
Sonatype Nexus-IQ
Synopsys Coverity
Job description
Role Purpose

We are seeking a skilled DevSecOps Engineer to design, implement, and manage secure software delivery practices. The role focuses on integrating security into CI/CD pipelines, automating testing, and ensuring compliance with industry standards while collaborating across IT, operations, and audit teams.

Key Responsibilities
  • Onboard and integrate projects into the DevSecOps tool chain.
  • Design and implement secure software delivery practices.
  • Automate security testing in CI/CD pipelines to improve efficiency and reliability.
  • Develop and maintain security tools and automation scripts.
  • Create and tune DevSecOps security policies.
  • Collaborate with operations, compliance, and audit teams to meet security requirements.
  • Conduct vulnerability assessments using SAST, DAST, and IAST tools.
  • Generate CIS benchmark compliance reports and follow up on resolution.
  • Support encryption strategies (KMS, SSL/TLS, digital certificates, crypto policies).
  • Monitor and analyze security events through SIEM (QRadar).
  • Provide support for endpoint protection (EDR) and operational control.
Requirements
  • Bachelor’s degree in Computer Science, IT, or related field.
  • 4–6 years of experience in DevSecOps, Qradar, Application Security, or related roles.
  • Hands-on expertise with SAST, DAST, IAST Seeker, SCA, and RASP tools.
  • Experience with Sonatype Nexus-IQ and Synopsys Coverity.
  • Strong scripting skills (Python, Bash, PowerShell).
  • Familiarity with Agile/DevOps methodologies.
  • Knowledge of compliance standards (CIS, NIST, ISO).
  • Strong problem-solving, collaboration, and communication skills.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.