Company logo hidden

Software Security Initiative (SSI) Lead

Unlock employer Riyadh, Saudi Arabia Direct to Company Under an hour ago · 16 Sep 2026

Financial

  • Estimate: $60k - $120k*
  • Zero income tax location

Accessibility

  • Office Only
  • Apply from abroad
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional
  • Arabic: Preferred

Position

About the Role
We are looking for an experienced Software Security Initiative (SSI) Lead to establish and lead a centralized, measurable Application Security program. The SSI Lead will be responsible for defining the strategic direction of the Application Security program, strengthening DevSecOps maturity based on the outcomes of BSIMM, OWASP DSOMM, and OWASP DSOVS assessments, and establishing the governance, metrics, standards, and enablement programs required to drive sustainable adoption of secure software development practices across the organization. The role requires strong leadership, stakeholder management, and executive communication skills, with the ability to translate Application Security objectives into measurable initiatives and actionable roadmaps.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Responsibilities

  • Develop, maintain, and continuously improve a centralized Application Security Framework.
  • Define and monitor Key Performance Indicators (KPIs) and Key Goal Indicators (KGIs) across Application Security functions.
  • Review, update, and maintain Application Security policies, standards, and guidelines.
  • Design and establish a multi-year DevSecOps maturity roadmap, including initiatives, ownership, priorities, and timelines.
  • Design the Application Security Governance Framework and define a clear RACI matrix across Security, Development, and DevOps teams.
  • Review and validate DevSecOps maturity assessment results based on BSIMM 15, OWASP DSOMM, or equivalent frameworks.
  • Independently validate identified gaps, control duplication, and high-risk areas requiring executive management attention.
  • Establish metrics to measure program maturity, security control coverage, and developer adoption.
  • Review and align Application Security policies and standards with NCA, OWASP SAMM, and NIST SSDF.
  • Develop and recommend developer enablement, incentive, and recognition programs to encourage adherence to secure coding standards and Application Security objectives.
  • Design and deliver an Application Security Awareness Program targeting developers, testers, and product managers.
  • Conduct periodic reviews with senior management to communicate progress, challenges, risks, and next steps.
  • Provide strategic recommendations to continuously improve the organization's Application Security and DevSecOps capabilities.
  • Facilitate knowledge transfer to Security and DevOps teams to ensure sustainable ownership of the Application Security framework and roadmap.

Requirements & Qualifications

  • Minimum 6 years of professional experience in Application Security, including proven leadership experience.
  • Proven experience leading enterprise-level Application Security or DevSecOps programs.
  • Proven experience conducting, reviewing, or working with BSIMM and/or OWASP SAMM maturity assessments, or equivalent Application Security maturity frameworks.
  • Strong experience designing Application Security frameworks, governance models, RACI matrices, KPI/KGI structures, and awareness programs.
  • Proven ability to develop and execute multi-year Application Security and DevSecOps maturity roadmaps.
  • Strong stakeholder management skills with experience engaging and communicating with senior and executive management.
  • Strong practical experience in Secure Software Development and DevSecOps practices.
  • Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
  • Strong understanding of integrating security tools into the Software Development Life Cycle (SDLC), including:
    • SAST
    • SCA
    • DAST
    • Secrets Management
    • Infrastructure as Code (IaC) Scanning
  • Strong knowledge of Application Security and cybersecurity frameworks and standards, including:
    • OWASP SAMM
    • OWASP DSOMM
    • OWASP DSOVS
    • BSIMM
    • NIST SSDF
    • NCA Cybersecurity Guidelines
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
  • Strong written and verbal communication skills in English.
  • Arabic language proficiency is an advantage.

Preferred / Required Professional Certifications
Candidates must hold at least two (2) certifications or recognized training credentials from the following list:

  • GCSA – GIAC Cloud Security Automation (SANS)
  • GDSA – GIAC Defensible Security Architecture (SANS)
  • DevSecOps Foundation / Professional – DevOps Institute
  • CSSLP – Certified Secure Software Lifecycle Professional (ISC²)
  • GWEB – GIAC Web Application Defender (SANS)
  • OSWE – Offensive Security Web Expert
  • CKS – Certified Kubernetes Security Specialist
  • AZ-400 – Microsoft Azure DevOps Engineer Expert
  • AWS Certified DevOps Engineer – Professional
  • CISSP or CISM – strongly preferred for the SSI Lead role
  • Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP
  • Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDF

General Project Requirements

  • Candidates will be subject to security screening and background verification before being granted access to client environments.
  • Compliance with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) is required.
  • All client data must remain within the Kingdom of Saudi Arabia.
  • The successful candidate must comply with internal policies, secure coding standards, change management procedures, and applicable governance frameworks, including OWASP, BSIMM, NIST SSDF, and NCA.
Apply Direct

Jobs you might like   View all jobs

About IT Services and IT Consulting Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct