📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

ديلويت تعلن عن وظيفة مستشار أول - مدير في أمن التطبيقات بالرياض

Senior Consultant - Manager| Cyber Operate | Application Security Specialist | KSA
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

شركة Deloitte تبحث عن Senior Consultant - Manager (أخصائي أمن التطبيقات) للعمل في الرياض، المملكة العربية السعودية.

المهام والمسؤوليات

  • تحديد معايير التطوير الآمن: تحديد دورة حياة تطوير البرمجيات الآمنة (Secure SDLC)، ومعايير البرمجة الآمنة، ومتطلبات أمن التطبيقات بما يتوافق مع NCA ECC وOWASP ASVS وNIST SSDF.
  • وضع متطلبات الأمان ومعايير القبول للتطبيقات المطورة داخليًا أو من جهات خارجية، بما في ذلك بنود العقود وفحوصات الإصدار.
  • بناء وصيانة سجل التطبيقات مع تصنيف المخاطر لكل تطبيق.
  • دمج الأمان في خط أنابيب CI/CD: تنفيذ وضبط أدوات SAST وDAST وSCA وفحص الأسرار (مثل Checkmarx وFortify وVeracode وSonarQube وSnyk وBurp Suite).
  • فرز نتائج الأدوات وإزالة الضوضاء وتقديم إرشادات واضحة للمطورين لإصلاح المشكلات دون تأخير الإصدارات.
  • مراجعة نشر الحاويات والبنية التحتية كرمز (IaC) والتطبيقات السحابية مع فرق DevOps.
  • إجراء تقييمات أمنية شاملة لتطبيقات الويب والجوال وواجهات API، بما في ذلك الاختبار اليدوي للمصادقة والتفويض ومنطق الأعمال.
  • إجراء مراجعات أمنية للكود المصدري للميزات والمكونات عالية الخطورة.
  • قيادة نمذجة التهديدات للتطبيقات الجديدة والتغييرات الكبرى بالتعاون مع المهندسين المعماريين وفرق التطوير.
  • مراجعة التطبيقات من جهات خارجية وتطبيقات SaaS قبل اعتمادها.
  • تتبع نقاط الضعف في التطبيقات حتى إغلاقها مع فرق التطوير والموردين، والتحقق من الإصلاحات قبل الإصدار.
  • رفع تقارير عن حالة المخاطر للتطبيقات والاتجاهات إلى الإدارة.
  • تدريب المطورين على البرمجة الآمنة وقوائم OWASP Top 10 وAPI Security Top 10، وبناء شبكة من أبطال الأمان في فرق التطوير.
  • تطوير القدرات القيادية: فهم قيم الشركة واستكشاف فرص التأثير، الالتزام بالتعلم والتطوير الذاتي، التمثيل كسفير للعلامة التجارية لجذب المواهب، تحمل المسؤولية الشخصية عن الأداء، تطوير مهارات التواصل وبناء العلاقات، فهم كيفية مساهمة العمل اليومي في أولويات الفريق والأعمال.

الشروط والمتطلبات

  • خبرة إجمالية من 4 إلى 8+ سنوات.
  • درجة البكالوريوس في علوم الحاسب أو هندسة البرمجيات أو مجال ذي صلة.
  • خلفية في تطوير البرمجيات بلغة واحدة على الأقل (مثل Java أو C#/.NET أو JavaScript/TypeScript أو Python) مع القدرة على قراءة ومراجعة الكود.
  • خبرة عملية في أدوات SAST وDAST وSCA في بيئات تطوير حقيقية.
  • معرفة قوية بقوائم OWASP Top 10 وAPI Security Top 10 وASVS.
  • خبرة في خطوط أنابيب CI/CD وممارسات DevSecOps.
  • يفضل: خبرة في أمن تطبيقات الجوال (OWASP MASVS/MASTG).
  • يفضل: خبرة في أمن الحاويات والتطبيقات السحابية (Kubernetes وDocker والبنية التحتية كرمز).
  • يفضل: خبرة في منصات الدفع أو منصات التفاعل مع العملاء (مع awareness بمعيار PCI DSS).
  • يفضل: خبرة في إدارة برنامج أبطال الأمان.
  • يفضل: إتقان اللغة العربية.
  • شهادة واحدة على الأقل من التالية مفضلة: CSSLP أو GWEB أو OSWE. كما تقدر الشهادات: GWAPT أو CASE أو eWPT أو Burp Suite Certified Practitioner.
  • الإلمام بالأطر والمعايير التالية: NCA ECC-2:2024، OWASP ASVS / SAMM / Top 10 / API Security Top 10، NIST SP 800-218 (SSDF)، ISO/IEC 27001:2022 (A.8.25-A.8.29)، PCI DSS v4.0 (awareness).
عرض النص الأصلي للإعلان
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.

Our Purpose

Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most-for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.

Our shared values guide the way we behave to make a positive, enduring impact:

During your tenure as a Senior Consultant - Manager, you will demonstrate and develop your capabilities in the following areas.

Set the secure development standard

  • Define the secure SDLC, secure coding standards and application security requirements, aligned with NCA ECC, OWASP ASVS and NIST SSDF
  • Set security requirements and acceptance criteria for in-house and vendor-built applications, including contract clauses and release checks
  • Build and maintain the application inventory, with a risk rating for each application

Embed security in the pipeline

  • Implement and tune SAST, DAST, SCA and secrets scanning in CI/CD pipelines (e.g. Checkmarx, Fortify, Veracode, SonarQube, Snyk, Burp Suite)
  • Triage tool findings, remove noise, and give developers clear, fix-ready guidance so security doesn't slow releases
  • Review container, infrastructure-as-code and cloud-native deployments with DevOps teams

Assess applications in depth

  • Run application security assessments of web, mobile and API applications, including manual testing of authentication, authorization and business logic
  • Perform secure code reviews of high-risk features and components
  • Lead threat modelling for new applications and major changes, working with architects and development teams
  • Review third-party and SaaS applications before they are adopted

Drive fixes and build skills

  • Track application vulnerabilities to closure with development teams and vendors; verify fixes before release
  • Report application risk posture and trends to management
  • Train developers on secure coding, OWASP Top 10 and API Security Top 10, and build a network of security champions in development teams

Leadership Capabilities

  • Builds own understanding of our purpose and values; explores opportunities for impact.
  • Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
  • Understands expectations and demonstrates personal accountability for keeping performance on track.
  • Actively focuses on developing effective communication and relationship-building skills.
  • Understands how their daily work contributes to the priorities of the team and the business. 

Qualifications

  • Years of experience: 4-8+ total years
  • Bachelor's in computer science, software engineering or a related field
  • Software development background in at least one language (e.g. Java, C#/.NET, JavaScript/TypeScript, Python), with the ability to read and review code
  • Hands-on experience with SAST, DAST and SCA tools in real development environments
  • Strong knowledge of OWASP Top 10, API Security Top 10 and ASVS
  • Experience with CI/CD pipelines and DevSecOps practices
  • Mobile application security experience (OWASP MASVS/MASTG) is preferred.
  • Cloud-native and container security (Kubernetes, Docker, infrastructure-as-code) is preferred.
  • Experience with payment or customer-facing platforms (PCI DSS awareness) is preferred.
  • Experience running a security champions programme is preferred.
  • Arabic Language is preferred.
  • At least one preferred: CSSLP, GWEB, OSWE. Also valued: GWAPT, CASE, eWPT, Burp Suite Certified Practitioner.
  • Frameworks & Standards: NCA ECC-2:2024
  • OWASP ASVS / SAMM / Top 10 / API Security Top 10
  • NIST SP 800-218 (SSDF)
  • ISO/IEC 27001:2022 (A.8.25-A.8.29)
  • PCI DSS v4.0 (awareness)
المصدر: LinkedIn - أُضيفت للموقع في 8 أكتوبر 2026
رقم الإعلان لدى المصدر: 4477401785