Job Title: Development Security Operations Senior Expert
Job Location: Sulymaniyah - Iraq
Job Purpose:
Lead the implementation and continuous improvement of DevSecOps practices by embedding security controls, automated assurance, and secure‑by‑design principles across the SDLC, CI/CD pipelines, cloud platforms, and infrastructure. Act as the primary security partner for engineering and operations teams by driving secure delivery, vulnerability management, secure code review, cloud and platform security, compliance support, security assessments, DevSecOps and MSSP services requests while enabling measurable risk reduction and operational resilience.
Key Accountabilities:
DevSecOps
- Design, implement, and operate CI/CD security controls including: SAST, DAST, SCA, secret detection, license compliance, and artifact signing/attestation.
- Build automations and pipeline integrations using Python, Bash, or Go to strengthen security tooling, deployment workflows, and runtime controls.
- Build and maintain secure platform guardrails: hardened CI runners/agents, secure build environments, least‑privilege service accounts, and segregation of duties for pipelines.
- Implement and manage vulnerability management workflows: triage processes, risk‑based prioritization, remediation SLAs, false‑positive handling, and verification/re‑test automation.
- Establish and enforce secure configuration baselines for:
- Cloud (AWS/Azure/GCP): IAM least privilege, logging/monitoring, key management, network segmentation, storage security, and posture management.
- Containers/Kubernetes: image scanning, runtime policies, admission controls, RBAC, network policies, and cluster hardening.
- Infrastructure‑as‑Code: automated scanning and policy‑as‑code for Terraform/CloudFormation/ARM/Kubernetes manifests, with pull‑request enforcement.
- Own software supply chain security initiatives: SBOM generation/management, dependency controls, secure package repositories, artifact integrity, and build provenance.
- Implement secrets management practices: centralized vaulting, automated rotation, elimination of hardcoded credentials, and CI/CD secret hygiene controls.
- Enable secure engineering standards: secure coding guidelines, secure design patterns, threat modeling facilitation, and secure architecture reviews for critical services.
- Define and track DevSecOps security metrics/KPIs (e.g., coverage, pipeline adoption, MTTR for critical vulns, deployment security gate pass rate, policy exceptions).
- Lead security tool onboarding and lifecycle management: evaluation, PoCs, licensing, configuration, tuning, integrations (SIEM/SOAR, ticketing, repos), and operations.
- Provide technical leadership and enablement: developer training, secure coding workshops, pipeline onboarding support, and playbooks/runbooks for secure delivery.
- Coordinate with SOC/IR and infrastructure teams to ensure: centralized logging for pipelines and platforms, incident‑ready telemetry, and response procedures for supply chain events.
Security Assessment & Testing Operations
- Conduct manual secure code reviews and vulnerability assessments
- Manage the security assessment and penetration testing activities and project plans to ensure SDLC through Security‑by‑Design (SBD)
- Execute comprehensive web application and API testing for common security vulnerabilities as defined by OWASP including input validation vulnerabilities, broken access controls, session management vulnerabilities, cross‑site scripting issues, SQL injection, and web server configuration issues
- Provide security validation for corporate customers' commercial projects (MSSP) relevant to network, application, and IT systems Vulnerability Assessment and Penetration Testing
- Conduct mobile applications (iOS/Android) security assessment and penetration testing
- Conduct OS and database security assessment and penetration testing
- Conduct security testing for routing & switching, platforms, services, IP networks, and infrastructure
- Conduct functional business logic security testing.
Cloud and Container Security Assessment
- Develop and manage Infrastructure‑as‑Code using Helm, Terraform, and Ansible to automate deployment and configuration of hybrid Kubernetes clusters (on‑prem and EKS), ensuring consistent and secure baselines.
- Implement and maintain Kubernetes and container security controls including RBAC least‑privilege, secrets management, network policies, Pod Security Admission, runtime protection tools and integrations with AWS IAM/KMS.
- Assess cloud‑native application security, including containerized applications, Kubernetes clusters, and serverless function security
- Evaluate CI/CD pipeline security within cloud environments and assess integration of security testing tools
- Conduct container image security assessments, including vulnerability scanning, runtime protection, and orchestration platform configurations
- Test Infrastructure as Code (IaC) security, including Terraform, and CloudFormation, for security misconfigurations
Consultation & Remediation
- Provide hardening recommendations and guidelines for technical teams
- Propose remediation recommendations to business and technology owners for identified vulnerabilities
- Provide innovative security solutions and consultancy services to improve security posture, reduce risk, control security threats, decrease assets and data exposure, prevent data loss, and control access, while benefiting from extensive hands‑on experience in secure solutions design, secure architectural development and probing, examination, audit, gap analysis, and forensic testing to meet internal and external security needs
- Provide support to the SOC team in investigating intrusion and hacking incidents.
- Mentor, and support junior security professionals
- Support compliance and audit readiness by producing evidence from pipelines, controls mapping (e.g., ISO 27001, NIST, PCI DSS), and secure SDLC documentation.
Qualifications & Competencies:
- A BE in computer science, cybersecurity, network engineering, security or related fields
- 7+ years of experience in DevOps/SRE/Platform Engineering and/or Application Security, with at least 3+ years directly implementing DevSecOps controls at scale.
- Programming and Scripting Languages: Proficiency in Python, Bash, PowerShell, or Ruby for automation and scripting.
- CI/CD Tools: Experience with continuous integration and continuous deployment tools such as GitHub,Jenkins, GitLab CI/CD, CircleCI, or Travis CI.
- Configuration Management: Knowledge of configuration management tools like Ansible, Puppet, or Chef.
- Cloud Platforms: Familiarity with cloud services such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).
- Infrastructure as Code (IaC): Proficiency in IaC tools like Terraform/Bicep or AWS CloudFormation.
- Required DevSecOps certification, along with preferred certifications in offensive security and cloud/platform technologies.
DevSecOps Certificates:
- DevSecOps Foundation (DevOps Institute) or equivalent DevSecOps certification.
- Terraform Associate (HashiCorp) and/or cloud DevOps certifications (AWS DevOps Engineer, Azure DevOps Engineer Expert).
Cloud/Platform:
- AWS Certified Security – Speciality, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, and/or Kubernetes CKS/CKA.
Offensive Security:
- OSCP/OSCP+, OSWA, OSWP, GWAPT, GPEN, GPPAT,eCCPT eWPTX, eWPT CCSP, CISA, CEH, LTP, ECSA, or equivalent