Job Search and Career Advice Platform

Enable job alerts via email!

Cybersecurity Assurance Manager

HALA

Riyadh

On-site

SAR 100,000 - 140,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading fintech company in the Riyadh Region is looking for a skilled professional to lead its offensive security strategy. The role encompasses Penetration Testing, Vulnerability Management, and securing applications and infrastructure. The ideal candidate will have robust experience with security frameworks and DevSecOps practices. The company offers an inclusive culture, competitive compensation, and opportunities for personal development within a rapidly growing industry.

Benefits

Competitive compensation packages
Autonomy and mentoring
Personal development and training

Qualifications

  • Proven experience in developing and executing Penetration Testing and Red Teaming programs.
  • Expertise in Secure Software Development Lifecycle (S-SDLC) and CI/CD integration.
  • Deep understanding of security frameworks like OWASP Top 10 and MITRE ATT&CK.

Responsibilities

  • Develop and execute penetration testing and red teaming exercises.
  • Manage the vulnerability lifecycle and prioritize remediation.
  • Provide security assurance on new system designs.

Skills

Penetration testing expertise
DevSecOps integration
Threat Modeling
Security architecture design

Tools

Qualys
Nessus
SAST/DAST tools
Job description

HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools.

HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments, HALA Cashier and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations.

Founded in 2017, HALA is currently duly licensed by the Saudi Arabian Central Bank as well as the Financial Services Regulatory Authority (FSRA) in Abu Dhabi Global Market.

Job Summary

This role is responsible for leading, maturing, and executing the organization's offensive security and proactive defense programs, primarily encompassing Penetration Testing, Red Teaming, Vulnerability Management, and Secure Software Development Lifecycle (S‑SDLC). The successful candidate will be the subject matter expert in securing applications, infrastructure, and cloud environments, acting as a crucial bridge between security, development, and IT operations to implement a DevSecOps model.

Key Areas of Responsibility
  • Program Leadership: Develop and execute the organization's penetration testing and red teaming exercises across all critical assets.
  • Vulnerability Management: Own the full vulnerability lifecycle, prioritizing remediation based on business risk and impact.
  • Application Security (AppSec): Define and implement secure code review (SAST/DAST) processes and integrate security into the CI/CD pipeline.
  • Architecture & Design: Provide expert security assurance on new system designs, ensuring adherence to secure architecture patterns (e.g., Zero Trust).
Candidate Qualifications
  • Proven experience in developing, managing, and executing a formal Penetration Testing and Red Teaming program. Extensive hands‑on experience in conducting advanced, targeted penetration tests against various environments (web, mobile, cloud, API).
  • Demonstrated expertise in operating and optimizing Vulnerability Management tools (e.g., Qualys, Nessus) and implementing a risk‑based prioritization approach.
  • Strong background in Secure Software Development Lifecycle (S‑SDLC) implementation and integrating security practices into CI/CD pipelines (DevSecOps).
Experience
  • Experience with managing and configuring Static/Dynamic Application Security Testing (SAST/DAST) tools.
  • Experience with Threat Modeling methodologies for new applications and features.
  • Deep understanding of security frameworks such as OWASP Top 10, MITRE ATT&CK, and SAMA CSF (or similar financial/regulatory frameworks).
  • Knowledge of Zero Trust architecture, defense‑in‑depth principles, and cloud security best practices (OCI/Azure/GCP).
Skill
  • DevSecOps integration for security automation and speed.
  • Penetration testing expertise to validate defenses.
  • Security architecture design for resilient systems.
  • Threat Modeling, S‑SDLC Implementation, Zero Trust, Security Standards Development.
What We Offer You

We believe you will love working at HALA!

  • We have an inclusive and diverse culture that encourages innovation and flexibility in remote, in‑office, and hybrid work setups.
  • We offer highly competitive compensation packages, including the potential for shares.
  • We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper‑growth environment.
  • Join a talented team of over 30 nationalities working in 7 countries and gain valuable experience in an exciting industry.
  • We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.
  • You will be given a lot of responsibility and trust. We believe that the best results come when the people responsible for a function are given the freedom to do what they think is best.
If you think you have what it takes to join a remarkable team #apply_now
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.