DevSecOps - Application Security

🏢 asiacell communications pjsc
📍 Saudi ArabiaFull-timeHybrid
📅 Posted: 3w ago🔄 Updated: 3w ago
CV%
✨ AI Summary
The DevSecOps - Application Security role is a Senior Expert position within the Cyber Security business unit, located in Sulaymaniyah, Iraq. The primary purpose of this role is to lead the implementation and continuous improvement of DevSecOps practices, embedding security into the Software Development Life Cycle (SDLC), CI/CD pipelines, cloud platforms, and infrastructure. This involves acting as a security partner for engineering and operations teams to drive secure delivery, manage vulnerabilities, conduct secure code reviews, ensure cloud and platform security, provide compliance support, perform security assessments, and deliver DevSecOps and MSSP services, ultimately reducing risk and enhancing operational resilience. Key responsibilities include designing and implementing CI/CD security controls (SAST, DAST, SCA, secret detection), building automations with Python, Bash, or Go, establishing secure platform guardrails, managing vulnerability workflows, enforcing secure configurations for cloud and containers, owning software supply chain security, implementing secrets management, enabling secure engineering standards, defining DevSecOps metrics, leading security tool management, and providing technical leadership. The role also involves coordinating with SOC/IR and infrastructure teams, conducting manual secure code reviews, managing security assessment and penetration testing activities, executing web application and API testing, performing mobile application security assessments, testing infrastructure as code, providing hardening and remediation recommendations, and supporting compliance and audit readiness. A BE in a relevant field and 7+ years of experience in DevOps/SRE/Platform Engineering and/or Application Security are required, with a minimum of 3 years in DevSecOps implementation at scale. Proficiency in programming and scripting languages, CI/CD tools, configuration management, cloud platforms, and IaC tools is essential, along with a mandatory DevSecOps certification and preferred certifications in offensive security and cloud/platform technologies.
Required Skills
Other
Security AssessmentSCASAST
Information Technology
GoRBACSLA Management
🎁 Benefits & Perks
Permanent Job
Requirements
A BE in computer science, cybersecurity, network engineering, security or related fields is required. The role demands 7+ years of experience in DevOps/SRE/Platform Engineering and/or Application Security, with at least 3+ years directly implementing DevSecOps controls at scale. Proficiency in Python, Bash, PowerShell, or Ruby for automation and scripting is essential, along with experience in CI/CD tools like GitHub, Jenkins, GitLab CI/CD, CircleCI, or Travis CI. Knowledge of configuration management tools like Ansible, Puppet, or Chef, and familiarity with cloud platforms such as AWS, Microsoft Azure, and Google Cloud Platform (GCP) are necessary. Proficiency in IaC tools like Terraform/Bicep or AWS CloudFormation is required. A DevSecOps certification is mandatory, with preferred certifications in offensive security and cloud/platform technologies.
Description
Job Details:Business Unit: Cyber SecurityJob Title: Development Security Operations Senior ExpertJob Location: Sulaymaniyah - IraqJob Purpose:Lead the implementation and continuous improvement of DevSecOps practices by embedding security controls, automated assurance, and secure-by-design principles across the SDLC, CI/CD pipelines, cloud platforms, and infrastructure. Act as the primary security partner for engineering and operations teams by driving secure delivery, vulnerability management, secure code review, cloud and platform security, compliance support, security assessments, DevSecOps and MSSP services requests while enabling measurable risk reduction and operational resilience.Key Accountabilities:DevSecOps Design, implement, and operate CI/CD security controls including: SAST, DAST, SCA, secret detection, license compliance, and artifact signing/attestation.Build automations and pipeline integrations using Python, Bash, or Go to strengthen security tooling, deployment workflows, and runtime controls.Build and maintain secure platform guardrails: hardened CI runners/agents, secure build environments, least-privilege service accounts, and segregation of duties for pipelines.Implement and manage vulnerability management workflows: triage processes, risk-based prioritization, remediation SLAs, false-positive handling, and verification/re-test automation.Establish and enforce secure configuration baselines for:Cloud (AWS/Azure/GCP): IAM least privilege, logging/monitoring, key management, network segmentation, storage security, and posture management.Containers/Kubernetes: image scanning, runtime policies, admission controls, RBAC, network policies, and cluster hardening.Infrastructure-as-Code: automated scanning and policy-as-code for Terraform/CloudFormation/ARM/Kubernetes manifests, with pull-request enforcement.Own software supply chain security initiatives: SBOM generation/management, dependency controls, secure package repositories, artifact integrity, and build provenance.Implement secrets management practices: centralized vaulting, automated rotation, elimination of hardcoded credentials, and CI/CD secret hygiene controls.Enable secure engineering standards: secure coding guidelines, secure design patterns, threat modeling facilitation, and secure architecture reviews for critical services.Define and track DevSecOps security metrics/KPIs (e.g., coverage, pipeline adoption, MTTR for critical vulns, deployment security gate pass rate, policy exceptions).Lead security tool onboarding and lifecycle management: evaluation, PoCs, licensing, configuration, tuning, integrations (SIEM/SOAR, ticketing, repos), and operations.Provide technical leadership and enablement: developer training, secure coding workshops, pipeline onboarding support, and playbooks/runbooks for secure delivery.Coordinate with SOC/IR and infrastructure teams to ensure: centralized logging for pipelines and platforms, incident-ready telemetry, and response procedures for supply chain events.Security Assessment & Testing OperationsConduct manual secure code reviews and vulnerability assessmentsManage the security assessment and penetration testing activities and project plans to ensure SDLC through Security-by-Design (SBD)Execute comprehensive web application and API testing for common security vulnerabilities as defined by OWASP including input validation vulnerabilities, broken access controls, session management vulnerabilities, cross-site scripting issues, SQL injection, and web server configuration issuesProvide security validation for corporate customers commercial projects (MSSP) relevant to network, application, and IT systems Vulnerability Assessment and Penetration TestingConduct mobile applications (iOS/Android) security assessment and penetration testingConduct OS and database security assessment and penetration testingConduct security testing for routing & switching, platforms, services, IP networks, and infrastructureConduct functional business logic security testing.Cloud and Container Security AssessmentDevelop and manage Infrastructure-as-Code using Helm, Terraform, and Ansible to automate deployment and configuration of hybrid Kubernetes clusters (on-prem and EKS), ensuring consistent and secure baselines.Implement and maintain Kubernetes and container security controls including RBAC least-privilege, secrets management, network policies, Pod Security Admission, runtime protection tools and integrations with AWS IAM/KMS.Assess cloud-native application security, including containerized applications, Kubernetes clusters, and serverless function securityEvaluate CI/CD pipeline security within cloud environments and assess integration of security testing toolsConduct container image security assessments, including vulnerability scanning, runtime protection, and orchestration platform configurationsTest Infrastructure as Code (IaC) security, including Terraform, and CloudFormation, for security misconfigurationsConsultation & RemediationProvide hardening recommendations and guidelines for technical teamsPropose remediation recommendations to business and technology owners for identified vulnerabilitiesProvide innovative security solutions and consultancy services to improve security posture, reduce risk, control security threats, decrease assets and data exposure, prevent data loss, and control access, while benefiting from extensive hands-on experience in secure solutions design, secure architectural development and probing, examination, audit, gap analysis, and forensic testing to meet internal and external security needsProvide support to the SOC team in investigating intrusion and hacking incidents.Mentor, and support junior security professionalsSupport compliance and audit readiness by producing evidence from pipelines, controls mapping (e.g., ISO 27001, NIST, PCI DSS), and secure SDLC documentation.Qualifications & Competencies:A BE in computer science, cybersecurity, network engineering, security or related fields7+ years of experience in DevOps/SRE/Platform Engineering and/or Application Security, with at least 3+ years directly implementing DevSecOps controls at scale.Programming and Scripting Languages: Proficiency in Python, Bash, PowerShell, or Ruby for automation and scripting.CI/CD Tools: Experience with continuous integration and continuous deployment tools such as GitHub,Jenkins, GitLab CI/CD, CircleCI, or Travis CI.Configuration Management: Knowledge of configuration management tools like Ansible, Puppet, or Chef.Cloud Platforms: Familiarity with cloud services such as AWS, Microsoft Azure, and Google Cloud Platform (GCP).Infrastructure as Code (IaC): Proficiency in IaC tools like Terraform/Bicep or AWS CloudFormation.Required DevSecOps certification, along with preferred certifications in offensive security and cloud/platform technologies.DevSecOps Certificates:DevSecOps Foundation (DevOps Institute) or equivalent DevSecOps certification.Terraform Associate (HashiCorp) and/or cloud DevOps certifications (AWS DevOps Engineer, Azure DevOps Engineer Expert).Cloud/Platform: AWS Certified Security – Speciality, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, and/or Kubernetes CKS/CKA.Offensive Security:OSCP/OSCP+, OSWA, OSWP, GWAPT, GPEN, GPPAT,eCCPT eWPTX, eWPT CCSP, CISA, CEH, LTP, ECSA, or equivalent
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00