Posted
Ref: PP000-38770
Job description / Role
Full Time
Riyadh, Saudi Arabia
Any Nationality
Not Specified
Not Specified
Not Specified
IT - Software & Web Development
IT, Software & Internet Services
Description
Qiddiya Investment Company is looking for a highly-skilled and motivated Assistant Manager - Application Security to join our dynamic team. In this role, you will play a critical part in fortifying the security framework for our application development processes. You will work collaboratively with cross-functional teams to embed security best practices across all stages of the software development lifecycle (SDLC).
Your responsibilities will include conducting comprehensive security assessments, performing vulnerability analysis, and offering guidance on secure coding practices. You will influence the culture of security within our organization, ensuring that applications are developed with a strong security mindset.
Key Responsibilities
- Assist in strategizing and executing the application security roadmap aligned with organizational objectives.
- Conduct regular security assessments and penetration testing on applications and services.
- Provide actionable guidance for developers on remediating identified vulnerabilities.
- Participate in threat modeling and risk assessment activities.
- Facilitate training sessions and workshops to promote awareness of secure coding practices.
- Stay up-to-date with the latest security trends, vulnerabilities, and industry standards.
- Collaborate with DevOps teams to integrate security tools and practices into CI/CD pipelines.
- Document and report on security metrics and the status of remediation efforts.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology or related discipline.
- Minimum 4 years of professional experience in application security or software development roles.
- Expertise in application security frameworks and standards (e.g., OWASP Top Ten, NIST guidelines).
- Experience with security testing tools (SAST, DAST, IAST) and vulnerability management.
- Strong understanding of programming languages, secure coding practices, and software development methodologies.
- Excellent communication skills, capable of conveying complex security concepts to non-technical stakeholders.
- Relevant certifications (e.g., CISSP, CSSLP, CEH) are a plus.
Benefits
Comprehensive benefits package
|
Head of Cybersecurity
Big Fish Recruitment |
Jeddah | 12 Jan |
|
|
Head of Cyber & InfoSec - Security Rebuild (OT/IT)
Michael Page |
UAE | 7 Jan |
|
|
Cybersecurity Analyst
Charterhouse |
Abu Dhabi | 20 Oct |
|
|
Senior IT Security Engineer
Saudi Networkers Services |
Riyadh | 14 Dec |
|
|
Senior IT Security Engineer
Saudi Networkers Services |
Saudi Arabia | 14 Dec |
|