Cyber Security DevOps Senior Specialist
by Riyad Bank in Banking & Financial Services
The Cyber Security DevOps Senior Specialist role at Riyad Bank in Riyadh, Saudi Arabia focuses on integrating cybersecurity requirements into DevOps and software development pipelines within Business Technology environments. The role is responsible for supporting cybersecurity projects and change initiatives by applying cybersecurity and DevOps design principles, ensuring security is embedded across agile development processes including sprint planning, user story definition, testing, deployment, and sprint retrospectives. The position involves selecting appropriate automated testing approaches for cybersecurity controls and countermeasures within CI/CD pipelines, conducting vulnerability assessments, baseline configuration scanning, and security testing activities including penetration testing, fuzzing, static code analysis, and secure code reviews. The role requires developing, configuring, and maintaining DevOps security tools to track cybersecurity controls, configuration items, and ensure accurate and continuous security monitoring of development environments. It includes assessing release components for deployment scheduling, managing secure software delivery tools, and ensuring secure configuration management across DevOps pipelines. The specialist is responsible for identifying vulnerabilities in applications, analyzing risks, performing threat assessments, and coordinating with engineering teams to remediate security issues. The role also includes applying cybersecurity principles such as defense-in-depth, authentication, authorization, access control, encryption, intrusion detection, intrusion prevention, and network security architecture design. It requires strong understanding of OSI model, network protocols, Windows and Unix systems, packet-level analysis, and cyberattack stages. The position involves continuous monitoring of cybersecurity threats, assessing emerging technologies for exploitation risks, and ensuring compliance with IT security principles and enterprise cybersecurity architecture standards. The specialist contributes to continuous improvement of cybersecurity processes, reporting security findings, maintaining documentation, and supporting incident response activities within the banking cybersecurity environment while ensuring alignment with regulatory and organizational security policies.