Company logo hidden

Manager - Vulnerability Management

Unlock employer Riyadh, Saudi Arabia Posted: 26 May 2025

Financial

  • Estimate: $60k - $90k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Intermediate

Position

The role is responsible for embedding security into the software development lifecycle (SDLC) and ensuring the security of cloud-native and microservices-based applications, as well as managing and optimizing the Data Security Assessment Tool (D-SAT). This position involves proactively identifying, assessing, and mitigating security risks in applications while implementing industry-leading security practices to safeguard digital assets.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Responsibilities:

  • Implement Secure-by-Design and Zero Trust Architecture (ZTA) principles in agile and DevSecOps environments.
  • Conduct automated and manual threat modeling for API security, cloud-native applications, and AI models.
  • Lead the identification and classification of vulnerabilities, assess their risk levels, and collaborate with relevant stakeholders to prioritize remediation efforts.
  • Oversee the remediation process, ensuring timely resolution of high-priority vulnerabilities to minimize security risks to the organization.
  • Perform static (SAST), dynamic (DAST), interactive (IAST), and software composition analysis (SCA) to identify security flaws.
  • Assess and mitigate risks in AI/ML-based applications, including adversarial attacks and data poisoning threats.
  • Implement cloud security controls across Google Cloud and Oracle Cloud, ensuring compliance with relevant standards.
  • Integrate security testing tools into CI/CD pipelines.
  • Collaborate with red and blue teams to conduct penetration testing and incident response.
  • Develop and present regular reports on vulnerability management metrics, progress on remediation, and the overall security posture of the organization.
  • Ensure compliance with ISO 27001, PCI DSS, and Saudi Arabian Cybersecurity Standards.
  • Enforce, incorporate, and comply with all necessary controls and related information security policies, procedures, practices, training, reporting, and personal due diligence.

Qualifications:

  • Preferred Qualifications: A tertiary level qualification from a recognized institution in Computer Science, Information Security, or a related field.
  • Experience: 3 to 5 years of equivalent experience in information security or vulnerability management, with demonstrated competencies and experience.
  • Proven experience managing security tools like D-SAT, vulnerability scanners, or similar platforms.
  • Strong understanding of risk management frameworks and vulnerability assessment methodologies.

Technical Competencies:

  • Vulnerability scanning tools
  • Knowledge of security threats

Behavioral Competencies:

  • Communication
  • Problem-solving
  • Decision-making
  • Attention to detail

Work Conditions: On-site, Full-time
Location: Riyadh, Saudi Arabia
Language Requirements: Not specified.

Apply Direct

Jobs you might like   View all jobs

Ready to apply for this role?

Apply Direct