أبلاي إيدج ابدأ البحث عن عمل

Director of Cyber Security

Ruyat Technologies · Sulaymaniyah, Sulaymaniyah Governorate, Iraq

قدّم وتابع مع أبلاي إيدج
We are hiring in the capacity of Director Of CybersecurityAbout the PositionAs Cybersecurity Director, you'll own security end to end network and perimeter, infrastructure, applications, and the pipelines that build and ship them. From firewalls and network segmentation through SIEM/EDR monitoring, all the way to source code, APIs, CI/CD, and cloud-native environments, you're the person accountable for how we detect, prevent, and respond to security risk across the business.Basically, you make sure security is built directly into all our software and systems from the start. Instead of just writing policies, you'll work hands-on with our tech teams to make secure practices the standard way we operate.You'll report to technical leadership, with a direct line to executive leadership when significant security risks require their attention. We've got some foundational security stuff in place already, but some needs to be built out.You don't need to tick every box below, if most of it fits and you're excited about the role, apply anywayRequirements8+ years in cybersecurity, at least 3 in a leadership role5+ years hands on with CI/CD platforms (Jenkins, GitHub Actions, GitLab CI or similar) and pipeline security3+ years securing containers and Kubernetes environmentsStrong background in SAST, DAST, SCA/dependency scanning, API security testing and secure code reviewExperience rolling out secure development practices across engineering teams, not just writing policy docsHands on experience with SIEM and EDR platforms, deployment, tuning, alert triage, and incident responseExperience securing apps that deal with sensitive data, complex authorization, and high value/high volume transactionsSolid understanding of transaction security, authorization, transaction integrity, fraud resistant design, replay protectionWorking knowledge of IaC security (Terraform, CloudFormation or similar) and secret managementFamiliar with OWASP Top 10, ISO 27001, and other relevant standardsExperience leading vulnerability management and penetration testing programs across network and application layersCan explain a technical risk clearly to both engineers and executivesBachelor's in Computer Science, Info Security or related, or equivalent experiencePreferredCertifications like CISSP, CISM, OSCP, GIAC, or similarExperience with cloud security posture management (CSPM) and cloud-native security toolsExperience with high scale, API driven apps with complex authorization/transaction flowsBackground in a regulated or otherwise security sensitive industryExperience integrating AI tooling into security or dev workflowsResponsibilitiesOwn the cybersecurity strategy, roadmap, budget and day to day prioritiesManage firewall policy, network segmentation, and secure remote accessOwn SIEM and EDR, deployment, monitoring, alert tuning, and incident responseDeploy and tune WAF for our web applications and APIsSet secure coding standards and security gates across the SDLC, and actually enforce themRun threat modeling, code reviews, SAST/DAST, and vulnerability managementSit down with engineers directly to figure out what to fix first and howImprove how we handle auth, secrets, encryption and data protection across the boardOwn CI/CD pipeline security, build integrity, release security, protected branches, access controlsGet security into developer workflows without slowing everyone downSet standards for source control, build systems, artifact repos and deployment pipelinesSupply chain security is a big one, SBOMs, dependency governance, artifact provenance, all of itBuild out and mature our container security practices and set security standards for Kubernetes environmentsOwn scanning and governance for infrastructure as code and keep secrets management practices solid across dev and deploymentGenerally push secure by default thinking across our cloud native stackLead incident response when something breaks at the app or supply chain levelRun risk assessments regularly across apps, APIs, pipelines and the third party stuff we rely onWork with Compliance on the technical side of things, they own the regulatory piece, we make the systems actually meet itReport on where we stand, posture, open risks, program maturity, to both technical and executive leadershipBuild and mature the cybersecurity program as we grow, this role starts fairly hands onHire and mentor cybersecurity security engineers and other security specialists over timeTrack metrics that actually show risk going down, not just activityKeep an eye on new security tech, automation opportunities, and where AI fits into security workAll qualified applicants are kindly asked to submit their resume to hr@ruyat.tech