×
Register Here to Apply for Jobs or Post Jobs. X

DevSecOps - Application Security

Job in Riyadh, Riyadh Region, Saudi Arabia
Listing for: Asiacell Communications PJSC
Full Time position
Listed on 2026-08-20
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 450000 - 675000 SAR Yearly SAR 450000.00 675000.00 YEAR
Job Description & How to Apply Below

Job Title: Development Security Operations Senior Expert

Job Location: Sulymaniyah - Iraq

Job Purpose:

Lead the implementation and continuous improvement of Dev Sec Ops  practices by embedding security controls, automated assurance, and secure‑by‑design principles across the SDLC, CI/CD pipelines, cloud platforms, and infrastructure. Act as the primary security partner for engineering and operations teams by driving secure delivery, vulnerability management, secure code review, cloud and platform security, compliance support, security assessments, Dev Sec Ops  and MSSP services requests while enabling measurable risk reduction and operational resilience.

Key Accountabilities:

Dev Sec Ops
  • Design, implement, and operate CI/CD security controls including: SAST, DAST, SCA, secret detection, license compliance, and artifact signing/attestation.
  • Build automations and pipeline integrations using Python, Bash, or Go to strengthen security tooling, deployment workflows, and runtime controls.
  • Build and maintain secure platform guardrails: hardened CI runners/agents, secure build environments, least‑privilege service accounts, and segregation of duties for pipelines.
  • Implement and manage vulnerability management workflows: triage processes, risk‑based prioritization, remediation SLAs, false‑positive handling, and verification/re‑test automation.
  • Establish and enforce secure configuration baselines for:
  • Cloud (AWS/Azure/GCP): IAM least privilege, logging/monitoring, key management, network segmentation, storage security, and posture management.
  • Containers/Kubernetes: image scanning, runtime policies, admission controls, RBAC, network policies, and cluster hardening.
  • Infrastructure‑as‑Code: automated scanning and policy‑as‑code for Terraform/Cloud Formation/ARM/Kubernetes manifests, with pull‑request enforcement.
  • Own software supply chain security initiatives: SBOM generation/management, dependency controls, secure package repositories, artifact integrity, and build provenance.
  • Implement secrets management practices: centralized vaulting, automated rotation, elimination of hardcoded credentials, and CI/CD secret hygiene controls.
  • Enable secure engineering standards: secure coding guidelines, secure design patterns, threat modeling facilitation, and secure architecture reviews for critical services.
  • Define and track Dev Sec Ops  security metrics/KPIs (e.g., coverage, pipeline adoption, MTTR for critical vulns, deployment security gate pass rate, policy exceptions).
  • Lead security tool onboarding and lifecycle management: evaluation, PoCs, licensing, configuration, tuning, integrations (SIEM/SOAR, ticketing, repos), and operations.
  • Provide technical leadership and enablement: developer training, secure coding workshops, pipeline onboarding support, and playbooks/runbooks for secure delivery.
  • Coordinate with SOC/IR and infrastructure teams to ensure: centralized logging for pipelines and platforms, incident‑ready telemetry, and response procedures for supply chain events.
Security Assessment & Testing Operations
  • Conduct manual secure code reviews and vulnerability assessments
  • Manage the security assessment and penetration testing activities and project plans to ensure SDLC through Security‑by‑Design (SBD)
  • Execute comprehensive web application and API testing for common security vulnerabilities as defined by OWASP including input validation vulnerabilities, broken access controls, session management vulnerabilities, cross‑site scripting issues, SQL injection, and web server configuration issues
  • Provide security validation for corporate customers' commercial projects (MSSP) relevant to network, application, and IT systems Vulnerability Assessment and Penetration Testing
  • Conduct mobile applications (iOS/Android) security assessment and penetration testing
  • Conduct OS and database security assessment and penetration testing
  • Conduct security testing for routing & switching, platforms, services, IP networks, and infrastructure
  • Conduct functional business logic security testing.
Cloud and Container Security Assessment
  • Develop and manage Infrastructure‑as‑Code using Helm, Terraform, and Ansible to automate deployment and configuration of…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary