إجراء اختبارات الاختراق عبر تطبيقات الويب وتطبيقات الهواتف وواجهات البرمجة (APIs).
تنفيذ مراجعات الشفرة الآمنة لتحديد الثغرات في كود التطبيق والسكربتات والتكوينات ومعالجتها.
تكوين وتحسين وإدارة نتائج أدوات فحص SAST وDAST وSCA وIaC وفحص الحاويات.
قيادة مبادرات DevSecOps، مع التركيز على أتمتة الأمن ضمن خطوط CI/CD.
تعزيز موقف الأمان لبنية Kubernetes، ووقت التشغيل للحاويات، والبنية التحتية الأساسية.
المساهمة في تصميم هندسة الأمن وإجراء مراجعات المخاطر للتطبيقات والبيئات السحابية والبنية التحتية.
قيادة نمذجة التهديدات وتقييمات المخاطر وإدارة الثغرات من النهاية إلى النهاية.
تعزيز الوعي الأمني من خلال إنشاء وتقديم جلسات تدريب وورش عمل لأفضل الممارسات.
التعاون مع فرق التطوير وDevOps والبنية التحتية لضمان التصميم والتسليم الآمن.
العمل كمستشار أمني موثوق، وتحويل المخاطر التقنية المعقدة إلى توصيات قابلة للتنفيذ لأصحاب المصلحة غير التقنيين.
المشاركة في الاستجابة للحوادث، وإجراء مراجعات ما بعد الحوادث، والتأكد من تطبيق الدروس المستفادة.
البقاء على اطلاع مستمر على التهديدات الناشئة، وطرق الهجوم الحديثة، والتقنيات الأمنية المبتكرة.
الملف المرغوب فيه للمرشح
من 7 إلى 12 عامًا من الخبرة المهنية في أدوار أمن المعلومات.
خبرة عملية مثبتة في اختبار الاختراق للويب والهواتف وواجهات API.
إتقان أدوات أمان التطبيق والبنية التحتية (SAST وDAST وSCA وIaC وفحص الحاويات).
فهم عميق لمبادئ DevSecOps، وأمن خطوط CI/CD، وأطر أتمتة الأمن.
معرفة قوية بممارسات أمان السحابة، خاصة ضمن AWS وAzure.
إلمام قوي بـ Kubernetes وDocker وأمن وقت تشغيل الحاويات ومبادئ تصميم البنية الآمنة.
مهارات برمجة قوية (مثلاً Python وBash) لبناء وت automatisation سير عمل الأمان.
تفكير تحليلي ومهارات حل المشكلات.
اتصالات ممتازة ومهارات إدارة أصحاب المصلحة، مع القدرة على توضيح المخاطر التقنية لجمهور غير تقني.
نهج تعاوني عالي عندما يعمل مع فرق التطوير وDevOps والمنتج والقيادة.
شغف بالتعلم المستمر والدفاع عن ثقافة الأمن على مستوى الشركة.
Conduct penetration testing across web applications, mobile applications, and APIs.
Execute secure code reviews to identify and remediate vulnerabilities in application code, scripts, and configurations.
Configure, optimize, and manage results from SAST, DAST, SCA, IaC, and container scanning tools.
Drive DevSecOps initiatives, emphasizing security automation within CI/CD pipelines.
Enhance the security posture of Kubernetes, container runtimes, and the underlying infrastructure.
Contribute to security architecture design and conduct risk reviews for applications, cloud environments, and infrastructure.
Lead threat modeling, risk assessments, and end-to-end vulnerability management.
Promote security awareness by establishing and delivering training sessions and best-practice workshops.
Partner with development, DevOps, and infrastructure teams to guarantee secure design and delivery.
Act as a trusted security advisor, translating complex technical risks into actionable recommendations for non-technical stakeholders.
Participate in incident response, conduct post-incident reviews, and ensure lessons learned are implemented.
Stay continuously updated on emerging threats, modern attack vectors, and innovative security technologies.
Desired Candidate Profile
7–12 years of professional experience in information security roles.
Proven hands-on expertise in web, mobile, and API penetration testing.
Proficiency with application and infrastructure security tooling (SAST, DAST, SCA, IaC, and container scanning).
Deep understanding of DevSecOps principles, CI/CD pipeline security, and security automation frameworks.
Strong knowledge of cloud security best practices, specifically within AWS and Azure.
Solid grasp of Kubernetes, Docker, container runtime security, and secure architecture design principles.
Proficient scripting skills (e.g., Python, Bash) to build and automate security workflows.
Strong analytical and problem-solving mindset.
Excellent communication and stakeholder management skills, with the ability to articulate technical risks clearly to non-technical audiences.
Highly collaborative approach when working with development, DevOps, product, and leadership teams.
Passion for continuous learning and championing a company-wide culture of security.
Tanqeeb.com هو محرك البحث عن الوظائف الأول فى الوطن العربى الذى يجمع لك الوظائف المناسبة من مختلف مواقع التوظيف الآخرى فى مكان واحد !