📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

بنك الرياض يعلن عن وظيفة Cyber Security DevOps Lead في الرياض

Cyber Security DevOps Lead
🏢 بنك الرياض (Riyad Bank)
🕒 نُشرت: (منذ 11 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

يسعى بنك الرياض إلى توظيف قائد عمليات الأمن السيبراني و DevOps (Cyber Security DevOps Lead) في الرياض، للمساعدة في مراجعة والتحقق من تطبيق متطلبات الأمن السيبراني عبر الأنشطة التطويرية في قطاع تقنية الأعمال.

نبذة عن الوظيفة

المساعدة والمراجعة والتحقق من تطبيق متطلبات الأمن السيبراني عبر الأنشطة التطويرية في قطاع تقنية الأعمال.

المهام والمسؤوليات

  • اتباع جميع السياسات والإجراءات والمعايير التشغيلية ذات الصلة لضمان تنفيذ العمل بطريقة مضبوطة ومتسقة.
  • إدارة العمليات اليومية المرتبطة بالوظيفة لضمان استمرارية العمل.
  • دعم المشاريع أو مبادرات التغيير من خلال إعداد الخطط الفنية وتطبيق مبادئ تصميم الأمن السيبراني و DevOps.
  • اختيار نهج الاختبار المناسب للاختبار الآلي لضوابط وإجراءات الأمن السيبراني في خط أنابيب DevOps.
  • تحليل الإبلاغ عن أنشطة الاختبار ونتائجه والمشكلات والمخاطر المتعلقة بمبادرات الأمن السيبراني ضمن خط أنابيب DevOps.
  • تخطيط إدارة عناصر التكوين والمعلومات ذات الصلة لضوابط وإجراءات الأمن السيبراني ضمن خط أنابيب DevOps.
  • تطوير وتكوين وصيانة الأدوات (بما في ذلك الأتمتة) لتحديد وتتبع وتسجيل والحفاظ على معلومات دقيقة وكاملة وحديثة لضوابط الأمن السيبراني ضمن خط أنابيب DevOps.
  • الإبلاغ عن حالة إدارة التكوين، وتحديد المشكلات والتوصية بإجراءات تصحيحية، والإبلاغ عن تقدم مبادرات الأمن السيبراني ضمن خط أنابيب DevOps.
  • تقييم وتحليل مكونات الإصدار للمساهمة في جدولة الإصدارات، وصيانة وإدارة أدوات وطرق تسليم ونشر وتكوين برمجيات الأمن السيبراني لخط أنابيب DevOps.
  • إجراء مسح للثغرات ومسح التكوين الأساسي، وأنشطة اختبار الاختراق والأمن ذات الصلة بالتغيير (مثل جمع المعلومات الأولية والاستقصاء المعياري) والتواصل مع فرق الهندسة/المنتجات لحل الثغرات الأمنية المحددة.
  • المساعدة في ضمان دمج الأمن كجزء من النشر المرن (Agile) بما يغطي تخطيط السبرنت (Sprint)، وتحديد قصص المستخدمين الأمنية وحالات الاختبار، والمشاركة في إيقاع سكرام ومراجعة السبرنت.
  • استخدام أدوات اختبار الأمن وفحص الكود لإجراء مراجعات الكود.
  • إجراء اختبار آمن للبرامج ومراجعتها وتقييمها لتحديد العيوب المحتملة في الأكواد وتخفيف الثغرات.
  • معالجة الآثار الأمنية في مرحلة قبول البرمجيات بما في ذلك معايير الإنجاز، وقبول المخاطر والتوثيق، والمعايير المشتركة، وطرق الاختبار المستقل.
  • إجراء تحليل المخاطر (مثل التهديدات والثغرات واحتمالية الحدوث) عند حدوث تغيير كبير في أي تطبيق أو نظام.
  • تطبيق معايير الترميز والاختبار، واستخدام أدوات اختبار الأمان بما في ذلك أدوات "Fuzzing" وفحص الكود الثابت (Static-analysis)، وإجراء مراجعات الكود.
  • المساهمة في تحديد فرص التحسين المستمر للعمليات والممارسات مع مراعاة أفضل الممارسات العالمية، وتحسين العمليات التجارية، وخفض التكاليف، وزيادة الإنتاجية.
  • المساعدة في إعداد تقارير دقيقة وفي الوقت المناسب لبنك الرياض لتلبية متطلبات الشركة والإدارات والسياسات والمعايير.
  • الامتثال لجميع سياسات وإجراءات وضوابط السلامة والجودة والبيئة ذات الصلة لضمان بيئة عمل صحية وآمنة.
  • أداء المهام الأخرى ذات الصلة أو المكلف بها ضمن نطاق المسؤوليات الإدارية.

الشروط والمتطلبات

درجة البكالوريوس في علوم الحاسب، تقنية المعلومات أو ما يعادلها. خبرة لا تقل عن 6-8 سنوات في مجال تقنية المعلومات أو الأمن السيبراني (مركز عمليات الأمن، الاستجابة للحوادث، إدارة الثغرات، اختبار الاختراق، الفريق الأحمر). إجادة متقدمة للغة الإنجليزية.

عرض النص الأصلي للإعلان

Job purpose / role:

To assist, review and validate in implementations of cybersecurity requirements across development activities in Business Technology.

Areas of responsibility:

  • Follows all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner
  • Follows the day-to-day operations related to own job to ensure continuity of work
  • Supports projects or change initiatives through the preparation of technical plans and application of cybersecurity and DevOps design principles.
  • Selects appropriate testing approach for automated testing of cybersecurity controls and countermeasures in the DevOps pipeline.
  • Analyses and reports on test activities, results, issues and risks, for the cybersecurity initiatives within the DevOps pipeline.
  • Plans the capture and management of configuration items and related information for cybersecurity controls and countermeasures within the DevOps pipeline.
  • Develops, configures and maintains tools (including automation) to identify, track, log and maintain accurate, complete and current information for cybersecurity controls and countermeasures within the DevOps pipeline.
  • Reports on the status of configuration management. Identifies problems and issues to recommend corrective actions, and report on progress cybersecurity initiatives within the DevOps pipeline.
  • Assesses and analyses release components for input to release scheduling, maintains and administers tools and methods for cybersecurity software delivery, deployment and configuration of the DevOps pipeline.
  • Conducts vulnerability and baseline configuration scanning, change related penetration and security testing activities such as initial information gathering and standard probing; and engagement with engineering/ product teams to resolve identified security vulnerabilities
  • Assists in ensuring security is embedded as part of the agile deployment covering sprint planning, defining security user stories and test cases, participating in scrum cadence and sprint retrospectives
  • Use security testing and code scanning tools to conduct code reviews
  • Perform secure program testing, review, and/or assessment to identify potential flaws in codes and mitigate vulnerabilities.
  • Address security implications in the software acceptance phase including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing.
  • Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
  • Apply coding and testing standards, apply security testing tools including "'fuzzing" static-analysis code scanning tools, and conduct code reviews.
  • Contributes to the identification of opportunities for continuous improvement of processes and practices taking into account ‘international best practice’, improvement of business processes, cost reduction and productivity improvement
  • Assists in the preparation of timely and accurate reports of Riyad Bank to meet company and department requirements, policies and standards
  • Complies with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environment
  • Performs other related duties or assignments as directed within the confinement of the departmental roles and responsibilities.


Qualifications & experience:

Minimum Qualifications:

  • Bachelor’s degree in Computer Science, Information Technology or equivalent.

Minimum Experience:

  • 6-8 years of relevant experience in IT or Cyber Security (SOC, incident response, vulnerability management, penetration test, red teaming)

Language:

English: Advanced

المصدر: LinkedIn - أُضيفت للموقع في 28 سبتمبر 2026
رقم الإعلان لدى المصدر: 4470834593