DevSecOps - Application Security
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-08-20
Listing for:
Asiacell Communications PJSC
Full Time
position Listed on 2026-08-20
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Job Description & How to Apply Below
Job Title: Development Security Operations Senior Expert
Job Location: Sulymaniyah - Iraq
Job Purpose:Lead the implementation and continuous improvement of Dev Sec Ops practices by embedding security controls, automated assurance, and secure‑by‑design principles across the SDLC, CI/CD pipelines, cloud platforms, and infrastructure. Act as the primary security partner for engineering and operations teams by driving secure delivery, vulnerability management, secure code review, cloud and platform security, compliance support, security assessments, Dev Sec Ops and MSSP services requests while enabling measurable risk reduction and operational resilience.
Key Accountabilities:Dev Sec Ops
- Design, implement, and operate CI/CD security controls including: SAST, DAST, SCA, secret detection, license compliance, and artifact signing/attestation.
- Build automations and pipeline integrations using Python, Bash, or Go to strengthen security tooling, deployment workflows, and runtime controls.
- Build and maintain secure platform guardrails: hardened CI runners/agents, secure build environments, least‑privilege service accounts, and segregation of duties for pipelines.
- Implement and manage vulnerability management workflows: triage processes, risk‑based prioritization, remediation SLAs, false‑positive handling, and verification/re‑test automation.
- Establish and enforce secure configuration baselines for:
- Cloud (AWS/Azure/GCP): IAM least privilege, logging/monitoring, key management, network segmentation, storage security, and posture management.
- Containers/Kubernetes: image scanning, runtime policies, admission controls, RBAC, network policies, and cluster hardening.
- Infrastructure‑as‑Code: automated scanning and policy‑as‑code for Terraform/Cloud Formation/ARM/Kubernetes manifests, with pull‑request enforcement.
- Own software supply chain security initiatives: SBOM generation/management, dependency controls, secure package repositories, artifact integrity, and build provenance.
- Implement secrets management practices: centralized vaulting, automated rotation, elimination of hardcoded credentials, and CI/CD secret hygiene controls.
- Enable secure engineering standards: secure coding guidelines, secure design patterns, threat modeling facilitation, and secure architecture reviews for critical services.
- Define and track Dev Sec Ops security metrics/KPIs (e.g., coverage, pipeline adoption, MTTR for critical vulns, deployment security gate pass rate, policy exceptions).
- Lead security tool onboarding and lifecycle management: evaluation, PoCs, licensing, configuration, tuning, integrations (SIEM/SOAR, ticketing, repos), and operations.
- Provide technical leadership and enablement: developer training, secure coding workshops, pipeline onboarding support, and playbooks/runbooks for secure delivery.
- Coordinate with SOC/IR and infrastructure teams to ensure: centralized logging for pipelines and platforms, incident‑ready telemetry, and response procedures for supply chain events.
- Conduct manual secure code reviews and vulnerability assessments
- Manage the security assessment and penetration testing activities and project plans to ensure SDLC through Security‑by‑Design (SBD)
- Execute comprehensive web application and API testing for common security vulnerabilities as defined by OWASP including input validation vulnerabilities, broken access controls, session management vulnerabilities, cross‑site scripting issues, SQL injection, and web server configuration issues
- Provide security validation for corporate customers' commercial projects (MSSP) relevant to network, application, and IT systems Vulnerability Assessment and Penetration Testing
- Conduct mobile applications (iOS/Android) security assessment and penetration testing
- Conduct OS and database security assessment and penetration testing
- Conduct security testing for routing & switching, platforms, services, IP networks, and infrastructure
- Conduct functional business logic security testing.
- Develop and manage Infrastructure‑as‑Code using Helm, Terraform, and Ansible to automate deployment and configuration of…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×