📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

جودين تعلن عن وظيفة Senior DevSecOps Engineer في الرياض

Senior DevSecOps Engineer
🕒 نُشرت: (منذ 23 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

نحن في جودين (JODAYN) نبحث عن مهندس DevSecOps أول (Senior DevSecOps Engineer) للعمل في الرياض، ليكون المرجع التقني الأساسي للمشروع وقيادة مبادرات تحسين نضج DevSecOps عبر المؤسسة.

المهام والمسؤوليات

  • قيادة مبادرات تحسين ورفع نضج DevSecOps في المؤسسة
  • إجراء تقييمات نضج DevSecOps وأمن التطبيقات وفق أطر معترف بها مثل BSIMM 15 وOWASP DSOMM وOWASP DSOVS
  • تقييم تغطية الضوابط ونضج خط الأنابيب (Pipeline) والممارسات الأمنية وتحديد الفجوات وفرص التحسين
  • تصميم ومراجعة وتنسيق تكامل ضوابط الأمان في خطوط CI/CD، بما في ذلك SAST وSCA وDAST وIAST وإدارة الأسرار (Secrets Management) وفحص البنية التحتية ككود (IaC Scanning)
  • إنشاء وإدارة عمليات فرز الثغرات وتحديد أولوياتها وتتبعها ومعالجتها مع اتفاقيات مستوى الخدمة (SLAs) محددة
  • قيادة تنفيذ وتهيئة وتحسين أدوات أمن التطبيقات والواجهات البرمجية (API) والتطوير الآمن
  • تطوير وصيانة المعايير الفنية والوثائق والإرشادات الأمنية والقوالب وقوائم التدقيق وسجلات التشغيل (Runbooks)
  • قيادة أنشطة نقل المعرفة وتقديم التوجيه الفني لفرق العملاء
  • تقديم الإرشاد الفني لفرق DevSecOps والأمن السيبراني وتطوير البرمجيات
  • مراقبة مؤشرات الأداء الرئيسية (KPIs) لأمن التطبيقات ومقاييس النضج ورفع التقارير عنها
  • دعم مواءمة السياسات والمعايير الأمنية مع أفضل الممارسات العالمية والمتطلبات التنظيمية المحلية
  • تعزيز ممارسات تطوير البرمجيات الآمنة طوال دورة حياة تطوير البرمجيات (SDLC)

الشروط والمتطلبات

  • خبرة مهنية لا تقل عن 7 سنوات في المجال ذي الصلة، تتضمن أدواراً قيادية أو كبيرة (Senior/Lead)
  • خبرة مثبتة في قيادة نمذجة التهديدات (Threat Modeling) ومراجعات التصميم الآمن والتنفيذ الشامل لأدوات الأمان
  • خبرة مثبتة في إجراء تقييمات نضج DevSecOps أو أمن التطبيقات باستخدام أطر مثل BSIMM أو OWASP DSOMM، بما في ذلك جمع الأدلة والتقييم وتحليل الفجوات وإعداد التقارير
  • خبرة في تحديد وتتبع ورفع تقارير مؤشرات الأداء الرئيسية ومقاييس النضج لأمن التطبيقات
  • خبرة في تطوير وتحديث ومواءمة السياسات والمعايير الفنية الأمنية مع أفضل الممارسات الدولية ومتطلبات الامتثال المحلية (بما في ذلك متطلبات الهيئة الوطنية للأمن السيبراني - NCA)
  • خبرة عملية قوية في تطوير البرمجيات الآمنة وممارسات DevSecOps
  • خبرة مثبتة في العمل مع منصات CI/CD مثل GitLab وAzure DevOps و/أو CloudBees
  • فهم قوي لتكامل أدوات الأمان في دورة حياة تطوير البرمجيات (SDLC)، بما في ذلك SAST وSCA وDAST وIAST وإدارة الأسرار وفحص IaC
  • إجادة قوية في الأتمتة والبرمجة باستخدام Python وBash و/أو PowerShell
  • مهارات تواصل كتابية وشفوية قوية باللغة الإنجليزية
  • إجادة اللغة العربية ميزة إضافية
  • يجب أن يحمل المرشح شهادتين معتمدتين على الأقل من القائمة التالية: GCSA، GDSA، DevSecOps Foundation/Professional (DevOps Institute)، CSSLP، GWEB، OSWE، CKS، AZ-400، AWS Certified DevOps Engineer - Professional، CISSP، CISM، أو تدريب معتمد في البرمجة الآمنة من جهات مثل SANS أو Secure Code Warrior أو OWASP، أو تدريب رسمي في BSIMM أو OWASP SAMM أو OWASP DSOMM أو OWASP DSOVS أو NIST SSDF

المهارات المطلوبة

  • إتقان أتمتة المهام والأمان باستخدام أدوات البرمجة النصية (Python, Bash, PowerShell)
  • معرفة جيدة بأطر الأمان والمقاييس مثل OWASP SAMM وOWASP DSOMM وOWASP DSOVS وBSIMM وNIST SSDF وNCA
  • فهم متقدم لتكامل أدوات الأمان في خطوط CI/CD وإدارة الثغرات
  • مهارات قيادية وتوجيهية للفرق
  • مهارات اتصال فعالة باللغة الإنجليزية (والعربية ميزة)
عرض النص الأصلي للإعلان
Job Description

We are looking for a Senior DevSecOps Engineer to serve as the primary technical reference for the project and lead initiatives to enhance DevSecOps maturity across the organization.

The successful candidate will be responsible for integrating security practices and tools into CI/CD pipelines, managing vulnerability remediation processes, establishing secure software development practices, and providing technical guidance and mentorship to security, development, and DevSecOps teams.

Requirements

  • Lead initiatives to improve and enhance DevSecOps maturity across the organization
  • Conduct DevSecOps and Application Security maturity assessments against recognized frameworks and standards, including BSIMM 15, OWASP DSOMM, and OWASP DSOVS
  • Assess control coverage, pipeline maturity, security practices, control duplication, and high-risk areas, and identify gaps and improvement opportunities
  • Design, review, and coordinate the integration of security controls into CI/CD pipelines, including:
    • SAST
    • SCA
    • DAST
    • IAST
    • Secrets Management
    • Infrastructure as Code (IaC) Scanning
  • Establish and govern vulnerability triage, prioritization, tracking, and remediation processes, including defined SLAs
  • Lead the implementation, configuration, and optimization of application, API, and secure development security tools
  • Develop and maintain technical standards, documentation, security guidelines, templates, checklists, and operational runbooks
  • Lead knowledge transfer activities and provide technical guidance to client teams
  • Provide technical mentorship and guidance to DevSecOps, cybersecurity, and software development teams
  • Monitor and report on Application Security KPIs, metrics, and DevSecOps maturity indicators
  • Support the alignment of security policies and standards with global best practices and applicable local regulatory requirements
  • Promote secure software development practices throughout the Software Development Life Cycle (SDLC)

Requirements & Qualifications

  • Minimum 7 years of relevant professional experience, including experience in Senior and/or Lead-level roles
  • Proven experience leading Threat Modeling, secure design reviews, and end-to-end implementation of security tools
  • Proven experience conducting DevSecOps and/or Application Security maturity assessments using frameworks such as BSIMM and/or OWASP DSOMM, including evidence collection, assessment, gap analysis, and reporting
  • Experience defining, tracking, and reporting Application Security KPIs, metrics, and maturity indicators
  • Experience developing, updating, and aligning security policies and technical standards with international best practices and local compliance requirements, including NCA requirements
  • Strong practical experience in Secure Software Development and DevSecOps practices
  • Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees
  • Strong understanding of integrating security tools into the SDLC, including SAST, SCA, DAST, IAST, Secrets Management, and IaC Scanning
  • Good knowledge of security frameworks and standards, including:
    • OWASP SAMM
    • OWASP DSOMM
    • OWASP DSOVS
    • BSIMM
    • NIST SSDF
    • NCA Cybersecurity Guidelines
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell
  • Strong written and verbal communication skills in English
  • Arabic language proficiency is an advantage

Preferred / Required Professional Certifications

Candidates must hold at least two (2) certifications or recognized training credentials from the following list:

  • GCSA - GIAC Cloud Security Automation (SANS)
  • GDSA - GIAC Defensible Security Architecture (SANS)
  • DevSecOps Foundation / Professional - DevOps Institute
  • CSSLP - Certified Secure Software Lifecycle Professional (ISC²)
  • GWEB - GIAC Web Application Defender (SANS)
  • OSWE - Offensive Security Web Expert
  • CKS - Certified Kubernetes Security Specialist
  • AZ-400 - Microsoft Azure DevOps Engineer Expert
  • AWS Certified DevOps Engineer - Professional
  • CISSP or CISM
  • Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP
  • Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDF
المصدر: LinkedIn - أُضيفت للموقع في 16 سبتمبر 2026
رقم الإعلان لدى المصدر: 4467977460