وظيفة مهندس DevSecOps أول لدى Darb Pay بمدينة الرياض
تفاصيل الوظيفة
Darb Pay، شركة تقنية مالية مرخصة من البنك المركزي السعودي، تبحث عن Senior DevSecOps Engineer للعمل في الرياض. ستعمل على تعزيز البنية التحتية السحابية وتأمينها، مع التركيز على البنية كرمز، وأمان خطوط CI/CD، وبناء قدرات الكشف في بيئة منظمة.
المهام والمسؤوليات
- تصميم وبناء وتأمين البنية التحتية على GCP (GKE، VPC networking، IAM، Cloud Armor WAF).
- إدارة البنية كرمز باستخدام Terraform: وحدات قابلة لإعادة الاستخدام، الحالة عن بُعد، كشف الانجراف، وحراس السياسات كرمز.
- بناء وتأمين خطوط CI/CD في GitHub Actions: سير عمل بأقل صلاحية (OIDC / Workload Identity Federation)، إدارة الأسرار، وأمان سلسلة التوريد.
- تشغيل وتحسين Splunk SIEM: إدخال السجلات، هندسة الكشف، ضبط التنبيهات، ولوحات المعلومات.
- قيادة تعزيز الأمان عبر الحزمة: هوية العمل، إدارة الأسرار، تجزئة الشبكة، قواعد WAF، وسياسات أمان Kubernetes.
- دعم الامتثال لإطار SAMA CSF: تنفيذ الضوابط، جمع الأدلة، والجاهزية للتدقيق.
- المشاركة في الاستجابة للحوادث: الفرز، الاحتواء، تحليل السبب الجذري، ومراجعات ما بعد الحادث بدون لوم.
- دفع الرصد والموثوقية: مؤشرات مستوى الخدمة (SLOs)، التنبيهات، وتخطيط السعة لأعباء العمل الإنتاجية.
الشروط والمتطلبات
- خبرة 5+ سنوات في أدوار DevOps أو DevSecOps أو SRE أو هندسة المنصات.
- خبرة عملية عميقة مع GCP (GKE، IAM، VPC، Cloud Armor، Cloud Logging and Monitoring).
- خبرة إنتاجية في Terraform: تصميم الوحدات، إدارة الحالة، وضغط CI-driven plan/apply.
- مهارات قوية في GitHub Actions، بما في ذلك أمان خطوط الأنابيب وإدارة الـ runners.
- كفاءة عملية في Splunk (SPL، التنبيهات، بناء أو ضبط الكشوفات).
- أساسيات Kubernetes متينة: RBAC، سياسات الشبكة، تعزيز أعباء العمل.
- القدرة على كتابة سكربتات في Bash و/أو Python.
- خبرة في بيئات منظمة أو عالية الامتثال (التقنية المالية، البنوك، أو ما شابه).
- تواصل كتابي واضح: أدلة التشغيل، مراجعات ما بعد الحادث، ووثائق التدقيق.
المهارات المطلوبة
- شهادات مثل GCP Professional Cloud Security Engineer أو CKA/CKS أو HashiCorp Terraform Associate (مفضلة).
- خبرة مباشرة مع SAMA CSF أو PCI DSS أو أطر مشابهة (مفضلة).
- خلفية في هندسة الكشف (قواعد Sigma، MITRE ATT&CK mapping) (مفضلة).
- خبرة في شبكات الثقة الصفرية (مفضلة).
- اطلاع على البنية التحتية للمدفوعات أو كشف الاحتيال (مفضلة).
عرض النص الأصلي للإعلان
About DarbPay
DarbPay is a SAMA-regulated fintech in Saudi Arabia, building secure, compliant payments infrastructure . Security isn't a checkbox for us - it's the foundation of everything we ship.
About the Role
We're hiring a Senior DevSecOps Engineer to own and harden our cloud infrastructure. You'll work at the intersection of platform engineering, security operations, and compliance - writing infrastructure as code, securing CI/CD pipelines, and building the detection capabilities that keep a regulated payments platform safe.
This is a hands-on senior role. You'll ship Terraform, tune Splunk detections, respond to incidents.
What You'll Do
• Design, build, and secure GCP infrastructure - GKE, VPC networking, IAM, and Cloud Armor WAF
• Own infrastructure as code with Terraform: reusable modules, remote state, drift detection, and policy-as-code guardrails
• Build and harden CI/CD pipelines in GitHub Actions - least-privilege workflows (OIDC / Workload Identity Federation), secrets management, and supply chain security
• Operate and improve our Splunk SIEM: log onboarding, detection engineering, alert tuning, and dashboarding
• Lead hardening across the stack - workload identity, secret management, network segmentation, WAF rules, and Kubernetes security policies
• Support SAMA CSF compliance: control implementation, evidence collection, and audit readiness
• Participate in incident response - triage, containment, root cause analysis, and blameless post-mortems
• Drive observability and reliability: SLOs, alerting, and capacity planning for production workloads
What We're Looking For
• 5+ years in DevOps, DevSecOps, SRE, or platform engineering roles
• Deep hands-on GCP experience - GKE, IAM, VPC, Cloud Armor, Cloud Logging and Monitoring
• Production Terraform experience: module design, state management, CI-driven plan/apply workflows
• Strong GitHub Actions skills, including pipeline security and runner management
• Working proficiency with Splunk - SPL, alerting, and building or tuning detections
• Solid Kubernetes fundamentals: RBAC, network policies, workload hardening
• Scripting ability in Bash and/or Python
• Experience in regulated or high-compliance environments (fintech, banking, or similar)
• Clear written communication - runbooks, post-mortems, and audit documentation
Nice to Have
• Certifications such as GCP Professional Cloud Security Engineer, CKA/CKS, or HashiCorp Terraform Associate
• Direct experience with SAMA CSF, PCI DSS, or comparable frameworks
• Detection engineering background (Sigma rules, MITRE ATT&CK mapping)
• Zero-trust networking experience
• Exposure to payments infrastructure or fraud/abuse detection
Our Stack
GCP • Terraform • GitHub Actions • Splunk • Kubernetes
Hiring Process
1. Shortlisting - we review your application and experience
2. Technical Assessment - a practical, scenario-based assessment
3. Technical Interview - a deep-dive with the engineering team on architecture, security, and how you think
We keep the process tight and respect your time. This is part-time, leading to full-time based on performance.