Location
Riyadh
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
About the Role
As a Senior Consultant - Manager, you will have the opportunity to demonstrate and develop your capabilities in several critical areas related to secure software development. Your responsibilities will include defining security standards, integrating security practices into development pipelines, assessing applications, driving vulnerability fixes, and enhancing team skills in application security. You will work collaboratively with various teams to ensure high standards of application security and risk management.
Key Responsibilities
-
Set the Secure Development Standard
- Define the secure Software Development Life Cycle (SDLC), secure coding standards, and application security requirements in alignment with NCA ECC, OWASP ASVS, and NIST SSDF.
- Set security requirements and acceptance criteria for in-house and vendor-built applications, including relevant contract clauses and release checks.
- Build and maintain the application inventory, assigning a risk rating for each application.
-
Embed Security in the Pipeline
- Implement and optimize SAST, DAST, SCA, and secrets scanning tools in CI/CD pipelines (e.g. Checkmarx, Fortify, Veracode, SonarQube, Snyk, Burp Suite).
- Triage tool findings, eliminating noise, and providing developers with clear, actionable guidance to ensure security does not hinder release schedules.
- Review container, infrastructure-as-code, and cloud-native deployments in collaboration with DevOps teams.
-
Assess Applications in Depth
- Conduct application security assessments for web, mobile, and API applications, including manual testing for authentication, authorization, and business logic vulnerabilities.
- Perform secure code reviews on high-risk features and components.
- Lead threat modeling sessions for new applications and significant updates, working closely with architects and development teams.
- Evaluate third-party and SaaS applications prior to adoption.
-
Drive Fixes and Build Skills
- Track application vulnerabilities to closure in partnership with development teams and vendors, verifying fixes before release.
- Report on the application risk posture and trends to management.
- Provide training to developers on secure coding practices, OWASP Top 10, and API Security Top 10, while building a network of security champions within development teams.
Leadership Capabilities
- Develop an understanding of the organization's purpose and values, actively seeking opportunities to make a meaningful impact.
- Commit to personal learning and development while acting as a brand ambassador to attract top talent.
- Demonstrate awareness of expectations and personal accountability for maintaining performance standards.
- Focus on enhancing effective communication and relationship-building skills.
- Recognize how daily work aligns with the team’s and organization's priorities.
Qualifications
- 4-8+ years of total professional experience.
- Bachelor’s degree in computer science, software engineering, or a related field.
- Background in software development with proficiency in at least one programming language (e.g., Java, C#/.NET, JavaScript/TypeScript, Python); capable of reading and reviewing code.
- Hands-on experience with SAST, DAST, and SCA tools in development environments.
- Comprehensive understanding of OWASP Top 10, API Security Top 10, and ASVS.
- Familiarity with CI/CD pipelines and DevSecOps practices.
- Preferred experience in mobile application security (OWASP MASVS/MASTG).
- Preferred knowledge in cloud-native and container security (Kubernetes, Docker, infrastructure-as-code).
- Experience with payment or customer-facing platforms (awareness of PCI DSS) is preferred.
- Preferred experience running a security champions program.
- Proficiency in Arabic is preferred.
- At least one of the following certifications preferred: CSSLP, GWEB, OSWE; valued certifications include GWAPT, CASE, eWPT, Burp Suite Certified Practitioner.
- Familiarity with frameworks and standards such as NCA ECC-2:2024, OWASP ASVS, SAMM, Top 10, API Security Top 10, NIST SP 800-218 (SSDF), ISO/IEC 27001:2022 (A.8.25–A.8.29), and PCI DSS v4.0 (awareness).