Cyber Security DevOps Lead
Riyad Bank · Riyadh, Saudi Arabia
Apply & track with Apply EdgeJob purpose / role:To assist, review and validate in implementations of cybersecurity requirements across development activities in Business Technology.Areas of responsibility:Follows all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent mannerFollows the day-to-day operations related to own job to ensure continuity of workSupports projects or change initiatives through the preparation of technical plans and application of cybersecurity and DevOps design principles. Selects appropriate testing approach for automated testing of cybersecurity controls and countermeasures in the DevOps pipeline.Analyses and reports on test activities, results, issues and risks, for the cybersecurity initiatives within the DevOps pipeline.Plans the capture and management of configuration items and related information for cybersecurity controls and countermeasures within the DevOps pipeline.Develops, configures and maintains tools (including automation) to identify, track, log and maintain accurate, complete and current information for cybersecurity controls and countermeasures within the DevOps pipeline.Reports on the status of configuration management. Identifies problems and issues to recommend corrective actions, and report on progress cybersecurity initiatives within the DevOps pipeline.Assesses and analyses release components for input to release scheduling, maintains and administers tools and methods for cybersecurity software delivery, deployment and configuration of the DevOps pipeline.Conducts vulnerability and baseline configuration scanning, change related penetration and security testing activities such as initial information gathering and standard probing; and engagement with engineering/ product teams to resolve identified security vulnerabilitiesAssists in ensuring security is embedded as part of the agile deployment covering sprint planning, defining security user stories and test cases, participating in scrum cadence and sprint retrospectivesUse security testing and code scanning tools to conduct code reviewsPerform secure program testing, review, and/or assessment to identify potential flaws in codes and mitigate vulnerabilities. Address security implications in the software acceptance phase including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Apply coding and testing standards, apply security testing tools including "'fuzzing" static-analysis code scanning tools, and conduct code reviews.Contributes to the identification of opportunities for continuous improvement of processes and practices taking into account ‘international best practice’, improvement of business processes, cost reduction and productivity improvementAssists in the preparation of timely and accurate reports of Riyad Bank to meet company and department requirements, policies and standardsComplies with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environmentPerforms other related duties or assignments as directed within the confinement of the departmental roles and responsibilities.Qualifications & experience:Minimum Qualifications:Bachelor’s degree in Computer Science, Information Technology or equivalent. Minimum Experience:6-8 years of relevant experience in IT or Cyber Security (SOC, incident response, vulnerability management, penetration test, red teaming) Language:English: Advanced