Salary
≈ $44k – $100k per year (Estimated)
Location
In office (Riyadh)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Jodayn is a Saudi consulting and technology firm: enterprise architecture, digital governance, data, transformation, innovation, applied AI, and professional services.
Job Description
We are looking for a Senior DevSecOps Engineer to serve as the primary technical reference for the project and lead initiatives to enhance DevSecOps maturity across the organization.
The successful candidate will be responsible for integrating security practices and tools into CI/CD pipelines, managing vulnerability remediation processes, establishing secure software development practices, and providing technical guidance and mentorship to security, development, and DevSecOps teams.
Requirements
- Lead initiatives to improve and enhance DevSecOps maturity across the organization.
- Conduct DevSecOps and Application Security maturity assessments against recognized frameworks and standards, including BSIMM 15, OWASP DSOMM, and OWASP DSOVS.
- Assess control coverage, pipeline maturity, security practices, control duplication, and high-risk areas, and identify gaps and improvement opportunities.
- Design, review, and coordinate the integration of security controls into CI/CD pipelines, including:
- SAST
- SCA
- DAST
- IAST
- Secrets Management
- Infrastructure as Code (IaC) Scanning
- Establish and govern vulnerability triage, prioritization, tracking, and remediation processes, including defined SLAs.
- Lead the implementation, configuration, and optimization of application, API, and secure development security tools.
- Develop and maintain technical standards, documentation, security guidelines, templates, checklists, and operational runbooks.
- Lead knowledge transfer activities and provide technical guidance to client teams.
- Provide technical mentorship and guidance to DevSecOps, cybersecurity, and software development teams.
- Monitor and report on Application Security KPIs, metrics, and DevSecOps maturity indicators.
- Support the alignment of security policies and standards with global best practices and applicable local regulatory requirements.
- Promote secure software development practices throughout the Software Development Life Cycle (SDLC).
Requirements & Qualifications
- Minimum 7 years of relevant professional experience, including experience in Senior and/or Lead-level roles.
- Proven experience leading Threat Modeling, secure design reviews, and end-to-end implementation of security tools.
- Proven experience conducting DevSecOps and/or Application Security maturity assessments using frameworks such as BSIMM and/or OWASP DSOMM, including evidence collection, assessment, gap analysis, and reporting.
- Experience defining, tracking, and reporting Application Security KPIs, metrics, and maturity indicators.
- Experience developing, updating, and aligning security policies and technical standards with international best practices and local compliance requirements, including NCA requirements.
- Strong practical experience in Secure Software Development and DevSecOps practices.
- Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
- Strong understanding of integrating security tools into the SDLC, including SAST, SCA, DAST, IAST, Secrets Management, and IaC Scanning.
- Good knowledge of security frameworks and standards, including:
- OWASP SAMM
- OWASP DSOMM
- OWASP DSOVS
- BSIMM
- NIST SSDF
- NCA Cybersecurity Guidelines
- Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
- Strong written and verbal communication skills in English.
- Arabic language proficiency is an advantage.
Preferred / Required Professional Certifications
Candidates must hold at least two (2) certifications or recognized training credentials from the following list:
- GCSA - GIAC Cloud Security Automation (SANS)
- GDSA - GIAC Defensible Security Architecture (SANS)
- DevSecOps Foundation / Professional - DevOps Institute
- CSSLP - Certified Secure Software Lifecycle Professional (ISC²)
- GWEB - GIAC Web Application Defender (SANS)
- OSWE - Offensive Security Web Expert
- CKS - Certified Kubernetes Security Specialist
- AZ-400 - Microsoft Azure DevOps Engineer Expert
- AWS Certified DevOps Engineer - Professional
- CISSP or CISM
- Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP
- Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDF
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
665,767 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Similar stack
Same company
Riyadh
≈ $159k – $298k per year (Estimated) • Remote • 10+ years exp • PhD
DevOps
Azure
CI/CD
AWS
Management
Agile
Apply
Senior iOS Engineer (SwiftUI / KMP)
2 hours ago
In office • Full-Time • Athens
Kotlin
Swift
Swift
Swift Concurrency
Mobile
SwiftUI
MVVM
Firebase
iOS SDK
Kotlin Multiplatform
XCTest
Push Notifications
Crashlytics
DevOps
Azure DevOps
Azure
CI/CD
Platform Engineering
Cybersecurity
GDPR
Management
Agile
QA
XCUITest
Apply
In office • Full-Time • Athens
Java
Kotlin
Java
Gradle
Kotlin
Hilt
KSP
Mobile
Jetpack Compose
Kotlin Multiplatform
Fastlane
Dependency Injection
Firebase App Distribution
DevOps
Azure DevOps
New Relic
Azure
CI/CD
Git
Management
Agile
Apply
In office • 3+ years exp
AI/ML
Claude
ChatGPT
DevOps
Azure DevOps
Azure
Management
Confluence
Jira
Agile
Scrum
Kanban
Apply
≈ $38k – $77k per year (Estimated) • In office • Moscow
Python
SQL
Apply
Marketing Manager
4 days ago
≈ $26k – $78k per year (Estimated) • In office • Riyadh
Design
Canva
Marketing
Salesforce
HubSpot
LinkedIn
Apply
Senior Integration Engineer
1 month ago
≈ $48k – $101k per year (Estimated) • In office • Full-Time • Dammam
Python
SQL
DevOps
Rest API
GCP
Azure
AWS
Analytics
ETL/ELT
Apache NiFi
Apply
Digital Solution Engineer
1 month ago
≈ $41k – $97k per year (Estimated) • In office • Full-Time • Riyadh
Python
SQL
Bash
Databases
PostgreSQL
DevOps
Red Hat
Ubuntu
Apply
Talent Acquisition Trainee (Tamheer)
2 months ago
In office • Full-Time • Bachelor's Degree • Riyadh
Marketing
LinkedIn
Apply
Senior Account Manager
3 months ago
≈ $37k – $84k per year (Estimated) • In office • Full-Time • Riyadh
Apply
Core Operations, SA
1 day ago
≈ $18k – $46k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Riyadh
Apply
≈ $42k – $89k per year (Estimated) • In office • Full-Time • Riyadh
Apply
Apply
Senior Marketing Manager
1 day ago
In office • Full-Time • 8+ years exp • Bachelor's Degree • Riyadh
Apply
Leader, Sales - Commercial Sector – KSA
1 day ago
≈ $57k – $135k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • Riyadh
Apply
This is one of many
665,767 more open roles from verified company boards, updated every day.

