شركة جودين تعلن عن وظيفة قائد مبادرة أمن البرمجيات (SSI) في الرياض
Software Security Initiative (SSI) Lead
تفاصيل الوظيفة
تسعى شركة جودين (JODAYN) إلى توظيف قائد لمبادرة أمن البرمجيات (SSI Lead) في الرياض، ليقود برنامج أمن التطبيقات المركزي للعميل ويحدد توجهاته الاستراتيجية.
المهام والمسؤوليات
- تطوير وصيانة وتحسين إطار أمن التطبيقات المركزي للعميل باستمرار.
- تحديد ومراقبة مؤشرات الأداء الرئيسية (KPIs) ومؤشرات الأهداف الرئيسية (KGIs) عبر وظائف أمن التطبيقات.
- مراجعة وتحديث وصيانة سياسات ومعايير وإرشادات أمن التطبيقات.
- تصميم وإنشاء خارطة طريق متعددة الأعوام لنضج DevSecOps، تتضمن المبادرات والملكية والأولويات والجداول الزمنية.
- تصميم إطار حوكمة أمن التطبيقات وتحديد مصفوفة RACI واضحة بين فرق الأمن والتطوير و DevOps.
- مراجعة والتحقق من صحة نتائج تقييم نضج DevSecOps بناءً على BSIMM 15 أو OWASP DSOMM أو أطر مكافئة.
- التحقق بشكل مستقل من الفجوات المحددة، وازدواجية الضوابط، والمناطق عالية المخاطر التي تتطلب اهتمام الإدارة التنفيذية.
- إنشاء مقاييس لقياس نضج البرنامج، وتغطية الضوابط الأمنية، وتبني المطورين.
- مراجعة ومواءمة سياسات ومعايير أمن التطبيقات مع NCA و OWASP SAMM و NIST SSDF.
- تطوير والتوصية ببرامج تمكين وحوافز وتقدير للمطورين لتشجيع الالتزام بمعايير الترميز الآمن وأهداف أمن التطبيقات.
- تصميم وتقديم برنامج توعية بأمن التطبيقات يستهدف المطورين والمختبرين ومديري المنتجات.
- إجراء مراجعات دورية مع الإدارة العليا للعميل لإبلاغ التقدم والتحديات والمخاطر والخطوات التالية.
- تقديم توصيات استراتيجية لتحسين قدرات أمن التطبيقات و DevSecOps في المؤسسة باستمرار.
- تسهيل نقل المعرفة إلى فرق الأمن و DevOps لضمان الملكية المستدامة لإطار أمن التطبيقات وخارطة الطريق.
الشروط والمتطلبات
- خبرة مهنية لا تقل عن 6 سنوات في أمن التطبيقات، تتضمن خبرة قيادية مثبتة.
- خبرة مثبتة في قيادة برامج أمن التطبيقات أو DevSecOps على مستوى المؤسسات.
- خبرة مثبتة في إجراء أو مراجعة أو العمل مع تقييمات نضج BSIMM و/أو OWASP SAMM أو أطر مكافئة.
- خبرة قوية في تصميم أطر أمن التطبيقات ونماذج الحوكمة ومصفوفات RACI وهياكل KPI/KGI وبرامج التوعية.
- قدرة مثبتة على تطوير وتنفيذ خرائط طريق متعددة الأعوام لأمن التطبيقات ونضج DevSecOps.
- مهارات قوية في إدارة أصحاب المصلحة مع خبرة في التواصل مع الإدارة العليا والتنفيذية.
- خبرة عملية قوية في تطوير البرمجيات الآمنة وممارسات DevSecOps.
- خبرة مثبتة في العمل مع منصات CI/CD مثل GitLab و Azure DevOps و/أو CloudBees.
- فهم قوي لتكامل أدوات الأمن في دورة حياة تطوير البرمجيات (SDLC) بما في ذلك: SAST و SCA و DAST وإدارة الأسرار وفحص البنية التحتية كرمز (IaC Scanning).
- معرفة قوية بأطر ومعايير أمن التطبيقات والأمن السيبراني: OWASP SAMM و OWASP DSOMM و OWASP DSOVS و BSIMM و NIST SSDF وإرشادات الأمن السيبراني الصادرة عن الهيئة الوطنية للأمن السيبراني (NCA).
- إجادة استخدام الأتمتة والبرمجة النصية باستخدام Python و Bash و/أو PowerShell.
- مهارات تواصل قوية كتابية وشفهية باللغة الإنجليزية.
- إجادة اللغة العربية ميزة إضافية.
- يجب أن يحمل المرشح شهادتين (2) على الأقل من القائمة التالية: GCSA، GDSA، DevSecOps Foundation/Professional، CSSLP، GWEB، OSWE، CKS، AZ-400، AWS Certified DevOps Engineer - Professional، يفضل بشدة CISSP أو CISM، تدريب معتمد في الترميز الآمن (SANS، Secure Code Warrior، OWASP)، تدريب رسمي في BSIMM أو OWASP SAMM أو OWASP DSOMM أو OWASP DSOVS أو NIST SSDF (تعطى أولوية قوية للحاصلين على تدريب رسمي في BSIMM أو OWASP SAMM أو NIST SSDF).
- سيخضع المرشحون لفحص أمني والتحقق من الخلفية قبل منح الوصول إلى بيئات العميل.
- الامتثال للضوابط الأساسية للأمن السيبراني الصادرة عن الهيئة الوطنية للأمن السيبراني (NCA ECC) مطلوب.
- يجب أن تبقى جميع بيانات العميل داخل المملكة العربية السعودية.
- يجب على المرشح الناجح الامتثال للسياسات الداخلية للعميل ومعايير الترميز الآمن وإجراءات إدارة التغيير وأطر الحوكمة المطبقة بما في ذلك OWASP و BSIMM و NIST SSDF و NCA.
عرض النص الأصلي للإعلان
We are looking for an experienced Software Security Initiative (SSI) Lead to establish and lead a centralized, measurable Application Security program for the client.
The SSI Lead will be responsible for defining the strategic direction of the Application Security program, strengthening DevSecOps maturity based on the outcomes of BSIMM, OWASP DSOMM, and OWASP DSOVS assessments, and establishing the governance, metrics, standards, and enablement programs required to drive sustainable adoption of secure software development practices across the organization.
The role requires strong leadership, stakeholder management, and executive communication skills, with the ability to translate Application Security objectives into measurable initiatives and actionable roadmaps.
Requirements
Candidates must hold at least two (2) certifications or recognized training credentials from the following list:
General Project Requirements
The SSI Lead will be responsible for defining the strategic direction of the Application Security program, strengthening DevSecOps maturity based on the outcomes of BSIMM, OWASP DSOMM, and OWASP DSOVS assessments, and establishing the governance, metrics, standards, and enablement programs required to drive sustainable adoption of secure software development practices across the organization.
The role requires strong leadership, stakeholder management, and executive communication skills, with the ability to translate Application Security objectives into measurable initiatives and actionable roadmaps.
Requirements
- Develop, maintain, and continuously improve the client's centralized Application Security Framework
- Define and monitor Key Performance Indicators (KPIs) and Key Goal Indicators (KGIs) across Application Security functions
- Review, update, and maintain Application Security policies, standards, and guidelines
- Design and establish a multi-year DevSecOps maturity roadmap, including initiatives, ownership, priorities, and timelines
- Design the Application Security Governance Framework and define a clear RACI matrix across Security, Development, and DevOps teams
- Review and validate DevSecOps maturity assessment results based on BSIMM 15, OWASP DSOMM, or equivalent frameworks
- Independently validate identified gaps, control duplication, and high-risk areas requiring executive management attention
- Establish metrics to measure program maturity, security control coverage, and developer adoption
- Review and align Application Security policies and standards with NCA, OWASP SAMM, and NIST SSDF
- Develop and recommend developer enablement, incentive, and recognition programs to encourage adherence to secure coding standards and Application Security objectives
- Design and deliver an Application Security Awareness Program targeting developers, testers, and product managers
- Conduct periodic reviews with the client's senior management to communicate progress, challenges, risks, and next steps
- Provide strategic recommendations to continuously improve the organization's Application Security and DevSecOps capabilities
- Facilitate knowledge transfer to Security and DevOps teams to ensure sustainable ownership of the Application Security framework and roadmap
- Minimum 6 years of professional experience in Application Security, including proven leadership experience
- Proven experience leading enterprise-level Application Security or DevSecOps programs
- Proven experience conducting, reviewing, or working with BSIMM and/or OWASP SAMM maturity assessments, or equivalent Application Security maturity frameworks
- Strong experience designing Application Security frameworks, governance models, RACI matrices, KPI/KGI structures, and awareness programs
- Proven ability to develop and execute multi-year Application Security and DevSecOps maturity roadmaps
- Strong stakeholder management skills with experience engaging and communicating with senior and executive management
- Strong practical experience in Secure Software Development and DevSecOps practices
- Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees
- Strong understanding of integrating security tools into the Software Development Life Cycle (SDLC), including:
- SAST
- SCA
- DAST
- Secrets Management
- Infrastructure as Code (IaC) Scanning
- Strong knowledge of Application Security and cybersecurity frameworks and standards, including:
- OWASP SAMM
- OWASP DSOMM
- OWASP DSOVS
- BSIMM
- NIST SSDF
- NCA Cybersecurity Guidelines
- Proficiency in automation and scripting using Python, Bash, and/or PowerShell
- Strong written and verbal communication skills in English
- Arabic language proficiency is an advantage
Candidates must hold at least two (2) certifications or recognized training credentials from the following list:
- GCSA - GIAC Cloud Security Automation (SANS)
- GDSA - GIAC Defensible Security Architecture (SANS)
- DevSecOps Foundation / Professional - DevOps Institute
- CSSLP - Certified Secure Software Lifecycle Professional (ISC²)
- GWEB - GIAC Web Application Defender (SANS)
- OSWE - Offensive Security Web Expert
- CKS - Certified Kubernetes Security Specialist
- AZ-400 - Microsoft Azure DevOps Engineer Expert
- AWS Certified DevOps Engineer - Professional
- CISSP or CISM - strongly preferred for the SSI Lead role
- Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP
- Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDF
General Project Requirements
- Candidates will be subject to security screening and background verification before being granted access to client environments
- Compliance with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) is required
- All client data must remain within the Kingdom of Saudi Arabia
- The successful candidate must comply with the client's internal policies, secure coding standards, change management procedures, and applicable governance frameworks, including OWASP, BSIMM, NIST SSDF, and NCA
المصدر: LinkedIn - أُضيفت للموقع في 16 سبتمبر 2026
رقم الإعلان لدى المصدر: 4467984421
رقم الإعلان لدى المصدر: 4467984421