Security Engineer
Adree
Posted on 24 Feb
Send me Jobs like this
Nationality
Any Nationality
Gender
Not Mentioned
Vacancy
1 Vacancy
Job Description
Roles & Responsibilities
Operationalize DevSecOps security controls across SDLC and CI/CD using Azure DevOps Server, ensuring enforceable security gates, vulnerability lifecycle management, and audit-ready evidence.
Key Responsibilities
- Configure and tune Fortify SAST/DAST, define thresholds and exception workflow.
- Automate the renewal and deployment of SSL/TLS certificates using tools like HashiCorp Vault and Cert-Manager in Kubernetes to prevent downtime and security risks.
- Integrate SBOM generation tools into the CI/CD pipeline to track component dependencies, license compliance, and vulnerabilities, providing visibility into the software supply chain.
- Implement image signing and verification using tools like Sigstore/Cosign to ensure code integrity, ensuring only verified, trusted container images are deployed.
- Define Quality Gates, vulnerability SLAs, triage process, remediation tracking and reporting dashboards.
- Integrate secrets management (HashiCorp Vault) and secure access patterns with SecurEnvoy MFA.
- Support compliance evidence: scan outputs, approvals, and release evidence packs.
- Partner with DevOps and QA on secure pipelines and test environment controls
Required Experience
5 8+ years AppSec/DevSecOps/security engineering experience. Government/regulatory sector experience is a plus. Strong OWASP, threat modeling, and vulnerability management exposure.
Technical Skills
Secure SDLC, CI/CD security gates, artifact trust, secrets management, container security concepts, and K8s security basics.
Soft Skills
Influence without authority, risk-based communication, pragmatic guidance, and calm escalation handling.
Core Skills / Tooling
Azure DevOps Server, Fortify (SAST/DAST), HashiCorp Vault, JFrog Artifactory, Sigstore (plus), OpenShift/Kubernetes awareness, and monitoring correlation (AppDynamics/BMC/Azure Monitoring).
Desired Candidate Profile
5 8+ years AppSec/DevSecOps/security engineering experience. Government/regulatory sector experience is a plus. Strong OWASP, threat modeling, and vulnerability management exposure.
Company Industry
- IT - Software Services
Department / Functional Area
- IT Software
Keywords
- Security Engineer
Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com
Similar Jobs
Security Specialist
Al Futtaim Private Company (LLC)
- 3 - 5 Years
- Dubai - United Arab Emirates (UAE)
Information Security Engineer
SUNDUS MANAGEMENT CONSULTANCY & STUDIES BUREAUL.L.C
- 3 - 6 Years
- Dubai - United Arab Emirates (UAE)
Information Security Officer
INTALEQ
- 8 - 15 Years
- Doha - Qatar
SOC L1 or SOC L2
CYBER GATE DEFENSE L.L.C.
- 2 - 7 Years
- Abu Dhabi - United Arab Emirates (UAE)
Security systems designer
Total Risk Protection Company
- 2 - 5 Years
- Riyadh - Saudi Arabia