Riyad Bank
Riyadh, Saudi ArabiaPosted yesterday
Job purpose / role: To assist, review and validate in implementations of cybersecurity requirements across development activities in Business Technology. Areas of responsibility: • Follows all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner • Follows the day-to-day operations related to own job to ensure continuity of work • Supports projects or change initiatives through the preparation of technical plans and application of cybersecurity and DevOps design principles. • Selects appropriate testing approach for automated testing of cybersecurity controls and countermeasures in the DevOps pipeline. • Analyses and reports on test activities, results, issues and risks, for the cybersecurity initiatives within the DevOps pipeline. • Plans the capture and management of configuration items and related information for cybersecurity controls and countermeasures within the DevOps pipeline. • Develops, configures and maintains tools (including automation) to identify, track, log and maintain accurate, complete and current information for cybersecurity controls and countermeasures within the DevOps pipeline. • Reports on the status of configuration management. Identifies problems and issues to recommend corrective actions, and report on progress cybersecurity initiatives within the DevOps pipeline. • Assesses and analyses release components for input to release scheduling, maintains and administers tools and methods for cybersecurity software delivery, deployment and configuration of the DevOps pipeline. • Conducts vulnerability and baseline configuration scanning, change related penetration and security testing activities such as initial information gathering and standard probing; and engagement with engineering/ product teams to resolve identified security vulnerabilities • Assists in ensuring security is embedded as part of the agile deployment covering sprint planning, defining security user stories and test cases, participating in scrum cadence and sprint retrospectives • Use security testing and code scanning tools to conduct code reviews • Perform secure program testing, review, and/or assessment to identify potential flaws in codes and mitigate vulnerabilities. • Address security implications in the software acceptance phase including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing. • Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. • Apply coding and testing standards, apply security testing tools including "'fuzzing" static-analysis code scanning tools, and conduct code reviews. • Contributes to the identification of opportunities for continuous improvement of processes and practices taking into account ‘international best practice’, improvement of business processes, cost reduction and productivity improvement • Assists in the preparation of timely and accurate reports of Riyad Bank to meet company and department requirements, policies and standards • Complies with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environment • Performs other related duties or assignments as directed within the confinement of the departmental roles and responsibilities. Qualifications & experience: Minimum Qualifications: • Bachelor’s degree in Computer Science, Information Technology or equivalent. Minimum Experience: • 6-8 years of relevant experience in IT or Cyber Security (SOC, incident response, vulnerability management, penetration test, red teaming) Language: English: Advanced Show more Show less
Bachelor’s degree in Computer Science, Information Technology or equivalent. 6-8 years of relevant experience in IT or Cyber Security (SOC, incident response, vulnerability management, penetration test, red teaming). English: Advanced.
Follows all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner; Follows the day-to-day operations related to own job to ensure continuity of work; Supports projects or change initiatives through the preparation of technical plans and application of cybersecurity and DevOps design principles; Selects appropriate testing approach for automated testing of cybersecurity controls and countermeasures in the DevOps pipeline; Analyses and reports on test activities, results, issues and risks, for the cybersecurity initiatives within the DevOps pipeline; Plans the capture and management of configuration items and related information for cybersecurity controls and countermeasures within the DevOps pipeline; Develops, configures and maintains tools (including automation) to identify, track, log and maintain accurate, complete and current information for cybersecurity controls and countermeasures within the DevOps pipeline; Reports on the status of configuration management; Identifies problems and issues to recommend corrective actions, and report on progress cybersecurity initiatives within the DevOps pipeline; Assesses and analyses release components for input to release scheduling, maintains and administers tools and methods for cybersecurity software delivery, deployment and configuration of the DevOps pipeline; Conducts vulnerability and baseline configuration scanning, change related penetration and security testing activities such as initial information gathering and standard probing; engagement with engineering/ product teams to resolve identified security vulnerabilities; Assists in ensuring security is embedded as part of the agile deployment covering sprint planning, defining security user stories and test cases, participating in scrum cadence and sprint retrospectives; Use security testing and code scanning tools to conduct code reviews; Perform secure program testing, review, and/or assessment to identify potential flaws in codes and mitigate vulnerabilities; Address security implications in the software acceptance phase including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing; Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change; Apply coding and testing standards, apply security testing tools including fuzzing and static-analysis code scanning tools, and conduct code reviews; Contributes to opportunities for continuous improvement of processes and practices; Assists in the preparation of timely and accurate reports of Riyad Bank to meet company and department requirements, policies and standards; Complies with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environment.
Not sure you fit this role?
Upload your CV and see how you score against Riyad Bank and every other live job. It's free.
Get my free matchesAED 17,640 – 34,300 a monthest.
Security Integrations Senior Engineer
Riyad BankRiyadh, Saudi Arabia
AED 14,700 – 24,500/mo
Testing Team Leader
Riyad BankRiyadh, Saudi Arabia
AED 14,700 – 24,500/mo
Cyber Security Manager
中集天达物流系统工程有限公司Riyadh, Saudi Arabia
AED 17,640 – 29,400/mo
Senior Compliance Specialist
Confidential GovernmentRiyadh, Saudi Arabia
AED 17,640 – 31,360/mo