Senior DevSecOps Engineer

JODAYN | جودين

Riyadh

On-site

SAR 280,000 - 420,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

JODAYN | جودين in Riyadh, Saudi Arabia seeks a Senior DevSecOps Engineer to serve as the technical reference for the project and lead initiatives to mature DevSecOps across the organization.

You will integrate security into CI/CD pipelines, manage vulnerability remediation, establish secure software development practices, and mentor security, development, and DevSecOps teams.

Qualifications

  • Minimum 7 years of relevant professional experience in Senior/Lead roles.
  • Proven experience leading Threat Modeling, secure design reviews, and end-to-end security tool implementation.
  • Experience conducting DevSecOps and Application Security maturity assessments using BSIMM and OWASP DSOMM/DSOVS.
  • Experience defining, tracking, and reporting Application Security KPIs and maturity indicators.
  • Experience aligning security policies with international best practices and local compliance (NCA).
  • Strong practical experience in Secure SDLC and DevSecOps practices; CI/CD platforms such as GitLab, Azure DevOps, CloudBees.
  • Proficiency in Python, Bash, or PowerShell; excellent written and verbal English; Arabic is an advantage.

Responsibilities

  • Lead initiatives to improve and enhance DevSecOps maturity across the organization.
  • Conduct maturity assessments against BSIMM, OWASP DSOMM, and OWASP DSOVS with evidence collection and reporting.
  • Assess control coverage, pipeline maturity, security practices, and identify gaps and improvements.
  • Design, review, and coordinate integration of security controls into CI/CD pipelines (SAST, SCA, DAST, IAST, Secrets Management, IaC Scanning).
  • Establish vulnerability triage, prioritization, tracking, and remediation processes with defined SLAs.
  • Lead implementation and optimization of application, API, and secure development tools; develop technical standards and runbooks.
  • Provide knowledge transfer and mentorship to client teams and internal security, development, and DevSecOps teams.
  • Monitor and report on Application Security KPIs and DevSecOps maturity indicators, align with best practices and local regulations.
  • Promote secure SDLC throughout the Software Development Life Cycle.

Skills

DevSecOps leadership
Threat modeling
Security assessments
CI/CD security
SAST
SCA
DAST
IAST
IaC scanning
Python scripting
English communication

Tools

GitLab CI/CD
Azure DevOps
CloudBees

Job description

Job Description

We are looking for a Senior DevSecOps Engineer to serve as the primary technical reference for the project and lead initiatives to enhance DevSecOps maturity across the organization.

The successful candidate will be responsible for integrating security practices and tools into CI/CD pipelines, managing vulnerability remediation processes, establishing secure software development practices, and providing technical guidance and mentorship to security, development, and DevSecOps teams.

Requirements
  • Lead initiatives to improve and enhance DevSecOps maturity across the organization
  • Conduct DevSecOps and Application Security maturity assessments against recognized frameworks and standards, including BSIMM 15, OWASP DSOMM, and OWASP DSOVS
  • Assess control coverage, pipeline maturity, security practices, control duplication, and high-risk areas, and identify gaps and improvement opportunities
  • Design, review, and coordinate the integration of security controls into CI/CD pipelines, including:
    • SAST
    • SCA
    • DAST
    • IAST
    • Secrets Management
    • Infrastructure as Code (IaC) Scanning
  • Establish and govern vulnerability triage, prioritization, tracking, and remediation processes, including defined SLAs
  • Lead the implementation, configuration, and optimization of application, API, and secure development security tools
  • Develop and maintain technical standards, documentation, security guidelines, templates, checklists, and operational runbooks
  • Lead knowledge transfer activities and provide technical guidance to client teams
  • Provide technical mentorship and guidance to DevSecOps, cybersecurity, and software development teams
  • Monitor and report on Application Security KPIs, metrics, and DevSecOps maturity indicators
  • Support the alignment of security policies and standards with global best practices and applicable local regulatory requirements
  • Promote secure software development practices throughout the Software Development Life Cycle (SDLC)
Requirements & Qualifications
  • Minimum 7 years of relevant professional experience, including experience in Senior and/or Lead-level roles
  • Proven experience leading Threat Modeling, secure design reviews, and end-to-end implementation of security tools
  • Proven experience conducting DevSecOps and/or Application Security maturity assessments using frameworks such as BSIMM and/or OWASP DSOMM, including evidence collection, assessment, gap analysis, and reporting
  • Experience defining, tracking, and reporting Application Security KPIs, metrics, and maturity indicators
  • Experience developing, updating, and aligning security policies and technical standards with international best practices and local compliance requirements, including NCA requirements
  • Strong practical experience in Secure Software Development and DevSecOps practices
  • Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees
  • Strong understanding of integrating security tools into the SDLC, including SAST, SCA, DAST, IAST, Secrets Management, and IaC Scanning
  • Good knowledge of security frameworks and standards, including:
    • OWASP SAMM
    • OWASP DSOMM
    • OWASP DSOVS
    • BSIMM
    • NIST SSDF
    • NCA Cybersecurity Guidelines
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell
  • Strong written and verbal communication skills in English
  • Arabic language proficiency is an advantage
Preferred / Required Professional Certifications

Candidates must hold at least two (2) certifications or recognized training credentials from the following list:

  • GCSA - GIAC Cloud Security Automation (SANS)
  • GDSA - GIAC Defensible Security Architecture (SANS)
  • DevSecOps Foundation / Professional - DevOps Institute
  • CSSLP - Certified Secure Software Lifecycle Professional (ISC²)
  • GWEB - GIAC Web Application Defender (SANS)
  • OSWE - Offensive Security Web Expert
  • CKS - Certified Kubernetes Security Specialist
  • AZ-400 - Microsoft Azure DevOps Engineer Expert
  • AWS Certified DevOps Engineer - Professional
  • CISSP or CISM
  • Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP
  • Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDF
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Specialist Senior - Metro
Cybersecurity Specialist Senior - Metro

Egis • Riyadh

On-site
SAR 300,000 - 600,000
Security Architect
Security Architect

IT Security Training & Solutions - I(TS)² • Riyadh

On-site
SAR 250,000 - 450,000
System Security Analyst
System Security Analyst

Accenture Middle East • Riyadh

On-site
SAR 120,000 - 180,000
DevOps Engineer
DevOps Engineer

Devoteam • Riyadh

On-site
SAR 220,000 - 360,000
Senior Lead - IT Security Delivery
Senior Lead - IT Security Delivery

Qiddiya • Riyadh

On-site
SAR 300,000 - 540,000
Cybersecurity Engineer
Cybersecurity Engineer

Tibah Airports Operation | طيبة لتشغيل المطارات • Medina

On-site
SAR 200,000 - 260,000
Application & Security Architecture Consultant
Application & Security Architecture Consultant

Paramount Computer Systems Co • Saudi Arabia

On-site
SAR 180,000 - 300,000
Information Security Specialist | IDM Technologies | Riyadh, Saudi Arabia
Information Security Specialist | IDM Technologies | Riyadh, Saudi Arabia

Tech Junction Ltd • Riyadh

On-site
SAR 180,000 - 300,000
Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • Saudi Arabia

Remote
OMR 33,000 - 53,000
Remote-first environment
Learning budget USD 2,000 per year
Annual bonus and performance rewards
+1
DevOps Engineer
DevOps Engineer

PrimeGate for Communications and IT • Riyadh

On-site
SAR 167,000 - 234,000