Security Engineer

Adree

Posted on 24 Feb

Experience

5 - 8 Years

Job Location

Riyadh - Saudi Arabia

Education

Bachelor of Science(Computers)

Nationality

Any Nationality

Gender

Not Mentioned

Vacancy

1 Vacancy

Job Description

Roles & Responsibilities

Operationalize DevSecOps security controls across SDLC and CI/CD using Azure DevOps Server, ensuring enforceable security gates, vulnerability lifecycle management, and audit-ready evidence.

Key Responsibilities

  • Configure and tune Fortify SAST/DAST, define thresholds and exception workflow.
  • Automate the renewal and deployment of SSL/TLS certificates using tools like HashiCorp Vault and Cert-Manager in Kubernetes to prevent downtime and security risks.
  • Integrate SBOM generation tools into the CI/CD pipeline to track component dependencies, license compliance, and vulnerabilities, providing visibility into the software supply chain.
  • Implement image signing and verification using tools like Sigstore/Cosign to ensure code integrity, ensuring only verified, trusted container images are deployed.
  • Define Quality Gates, vulnerability SLAs, triage process, remediation tracking and reporting dashboards.
  • Integrate secrets management (HashiCorp Vault) and secure access patterns with SecurEnvoy MFA.
  • Support compliance evidence: scan outputs, approvals, and release evidence packs.
  • Partner with DevOps and QA on secure pipelines and test environment controls

Required Experience

5 8+ years AppSec/DevSecOps/security engineering experience. Government/regulatory sector experience is a plus. Strong OWASP, threat modeling, and vulnerability management exposure.

Technical Skills

Secure SDLC, CI/CD security gates, artifact trust, secrets management, container security concepts, and K8s security basics.

Soft Skills

Influence without authority, risk-based communication, pragmatic guidance, and calm escalation handling.

Core Skills / Tooling

Azure DevOps Server, Fortify (SAST/DAST), HashiCorp Vault, JFrog Artifactory, Sigstore (plus), OpenShift/Kubernetes awareness, and monitoring correlation (AppDynamics/BMC/Azure Monitoring).

Desired Candidate Profile

5 8+ years AppSec/DevSecOps/security engineering experience. Government/regulatory sector experience is a plus. Strong OWASP, threat modeling, and vulnerability management exposure.

Company Industry

Department / Functional Area

Keywords

  • Security Engineer

Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com

Similar Jobs

Security Specialist

Information Security Officer

SOC L1 or SOC L2

View All