DevSecOps Engineer (Senior & Junior) – Application Security
Бюджет: -
HOURLY / FULL_TIME
⭐ 4.98 (96)
United Arab Emirates
cicd, docker, kubernetes, python, bash, microsoft-windows-powershell, owasp, devops
Summary
We are looking for experienced DevSecOps Engineers (1 Senior & 1 Junior) to support an enterprise-scale Application Security and DevSecOps initiative. The ideal candidates will have hands-on experience integrating security throughout the Software Development Lifecycle (SDLC), automating security testing, and implementing secure CI/CD pipelines.
Responsibilities:
* Design, implement, and maintain secure CI/CD pipelines.
* Integrate security controls throughout the Secure SDLC.
* Configure and manage SAST, DAST, SCA, and Secrets Scanning solutions.
* Perform application security assessments and vulnerability analysis.
* Support vulnerability remediation and secure coding practices.
* Conduct threat modeling and security architecture reviews.
* Implement Infrastructure as Code (IaC) security controls.
* Secure containerized and Kubernetes-based environments.
* Develop automation using Python, Bash, or PowerShell.
* Produce security reports, metrics, and technical documentation.
* Collaborate with development teams to improve application security maturity.
* Support implementation of security frameworks and governance processes.
Required Technical Skills:
- DevSecOps
* Secure Software Development Lifecycle (SSDLC)
* CI/CD Security
* Security Automation
* Infrastructure as Code (IaC)
* DevSecOps best practices
- Application Security
* SAST
* DAST
* Software Composition Analysis (SCA)
* Secret Detection
* Secure Code Review
* Vulnerability Management
* Threat Modeling
* API Security
* OWASP Top 10
- DevOps & Platforms
* GitLab CI/CD, Azure DevOps, CloudBees CI, or equivalent enterprise CI/CD platforms
* Git
* Docker
* Kubernetes
- Cloud
Experience with one or more:
* Microsoft Azure
* AWS
* Google Cloud Platform (GCP)
- Scripting
* Python
* Bash
* PowerShell
- Security Frameworks & Standards
Experience with one or more:
* OWASP SAMM
* BSIMM
* NIST Secure Software Development Framework (SSDF)
* Secure coding best practices
- Language
* **Arabic (Mandatory)**
* English (Professional working proficiency)
Experience
- Senior DevSecOps Engineer
* Minimum **7 years** of relevant DevSecOps / Application Security experience.
* Experience leading enterprise DevSecOps initiatives and mentoring engineering teams.
- Junior DevSecOps Engineer
* Up to **4 years** of relevant DevSecOps, DevOps, Software Engineering, or Application Security experience.
Mandatory Certifications (Senior Candidates):
- Senior candidates must hold at least one of the following certifications:
* GIAC Cloud Security Automation (GCSA)
* GIAC Defensible Security Architecture (GDSA)
* DevSecOps Foundation / Professional
* Certified Secure Software Lifecycle Professional (CSSLP)
* Certified Kubernetes Security Specialist (CKS)
* Microsoft Azure DevOps Engineer Expert (AZ-400)
* AWS Certified DevOps Engineer – Professional
- Preferred Qualifications (Junior Candidates):
One or more of the certifications above is preferred.
Preferred Qualifications:
* Candidates based in **Saudi Arabia** are strongly preferred.
* Experience implementing enterprise application security programs.
* Experience with secure coding training initiatives.
* Knowledge of enterprise security governance.
* Experience working in highly regulated environments.
* Strong communication and documentation skills.
* Be able to engage full time during regular work hours for 1 year
Відкрити на Upwork