Cyber Security DevOps Lead

منذ أسبوع

Riyadh, Riyadh Region, المملكة العربية السعودية Riyad Bank دوام كامل
Job purpose / role: To assist, review and validate in implementations of cybersecurity requirements across development activities in Business Technology. Areas of responsibility:
• Follows all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner
• Follows the day-to-day operations related to own job to ensure continuity of work
• Supports projects or change initiatives through the preparation of technical plans and application of cybersecurity and DevOps design principles.
• Selects appropriate testing approach for automated testing of cybersecurity controls and countermeasures in the DevOps pipeline.
• Analyses and reports on test activities, results, issues and risks, for the cybersecurity initiatives within the DevOps pipeline.
• Plans the capture and management of configuration items and related information for cybersecurity controls and countermeasures within the DevOps pipeline.
• Develops, configures and maintains tools (including automation) to identify, track, log and maintain accurate, complete and current information for cybersecurity controls and countermeasures within the DevOps pipeline.
• Reports on the status of configuration management. Identifies problems and issues to recommend corrective actions, and report on progress cybersecurity initiatives within the DevOps pipeline.
• Assesses and analyses release components for input to release scheduling, maintains and administers tools and methods for cybersecurity software delivery, deployment and configuration of the DevOps pipeline.
• Conducts vulnerability and baseline configuration scanning, change related penetration and security testing activities such as initial information gathering and standard probing; and engagement with engineering/ product teams to resolve identified security vulnerabilities
• Assists in ensuring security is embedded as part of the agile deployment covering sprint planning, defining security user stories and test cases, participating in scrum cadence and sprint retrospectives
• Use security testing and code scanning tools to conduct code reviews
• Perform secure program testing, review, and/or assessment to identify potential flaws in codes and mitigate vulnerabilities.
• Address security implications in the software acceptance phase including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing.
• Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
• Apply coding and testing standards, apply security testing tools including "'fuzzing" static-analysis code scanning tools, and conduct code reviews.
• Contributes to the identification of opportunities for continuous improvement of processes and practices taking into account ‘international best practice’, improvement of business processes, cost reduction and productivity improvement
• Assists in the preparation of timely and accurate reports of Riyad Bank to meet company and department requirements, policies and standards
• Complies with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environment
• Performs other related duties or assignments as directed within the confinement of the departmental roles and responsibilities. Qualifications &

experience:
Minimum

Qualifications:
• Bachelor’s degree in Computer Science, Information Technology or equivalent. Minimum

Experience:
• 6-8 years of relevant experience in IT or Cyber Security (SOC, incident response, vulnerability management, penetration test, red teaming) Language: English: Advanced