مدير استشاري أول، العمليات السيبرانية
تفاصيل الوظيفة
Our shared values guide the way we behave to make a positive, enduring impact:
During your tenure as a Senior Consultant – Manager, you will demonstrate and develop your capabilities in the following areas.
Set the secure development standard
· Define the secure SDLC, secure coding standards and application security requirements, aligned with NCA ECC, OWASP ASVS and NIST SSDF
· Set security requirements and acceptance criteria for in-house and vendor-built applications, including contract clauses and release checks
· Build and maintain the application inventory, with a risk rating for each application
Embed security in the pipeline
· Implement and tune SAST, DAST, SCA and secrets scanning in CI/CD pipelines (e.g. Checkmarx, Fortify, Veracode, SonarQube, Snyk, Burp Suite)
· Triage tool findings, remove noise, and give developers clear, fix-ready guidance so security doesn't slow releases
· Review container, infrastructure-as-code and cloud-native deployments with DevOps teams
Assess applications in depth
· Run application security assessments of web, mobile and API applications, including manual testing of authentication, authorization and business logic
· Perform secure code reviews of high-risk features and components
· Lead threat modelling for new applications and major changes, working with architects and development teams
· Review third-party and SaaS applications before they are adopted
Drive fixes and build skills
· Track application vulnerabilities to closure with development teams and vendors; verify fixes before release
· Report application risk posture and trends to management
· Train developers on secure coding, OWASP Top 10 and API Security Top 10, and build a network of security champions in development teams
Leadership Capabilities:
Builds own understanding of our purpose and values; explores opportunities for impact.
Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
Understands expectations and demonstrates personal accountability for keeping performance on track.
Actively focuses on developing effective communication and relationship-building skills.
Understands how their daily work contributes to the priorities of the team and the business.
Qualifications:
Years of experience: 4-8+ total years
Bachelor's in computer science, software engineering or a related field
Software development background in at least one language (e.g. Java, C#/.NET, JavaScript/TypeScript, Python), with the ability to read and review code
Hands-on experience with SAST, DAST and SCA tools in real development environments
Strong knowledge of OWASP Top 10, API Security Top 10 and ASVS
Experience with CI/CD pipelines and DevSecOps practices
Mobile application security experience (OWASP MASVS/MASTG) is preferred.
Cloud-native and container security (Kubernetes, Docker, infrastructure-as-code) is preferred.
Experience with payment or customer-facing platforms (PCI DSS awareness) is preferred.
Experience running a security champions programme is preferred.
Arabic Language is preferred.
At least one preferred: CSSLP, GWEB, OSWE. Also valued: GWAPT, CASE, eWPT, Burp Suite Certified Practitioner.
Desired Candidate Profile
هذا الإعلان منشور على تنقيب السعودية ويُعرض هنا مع الإشارة إلى المصدر. لا نتقاضى أي رسوم من الباحثين عن عمل. إذا كان الإعلان مسيئًا أو احتياليًا، أبلغنا.