adree logoadree logo

Security Engineer

adreeRiyadh, Riyadh Province, Saudi Arabia
On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Experience Level

Mid to Senior

Qualifications

Required Experience5 to 8+ years of experience in Application Security, DevSecOps, or security engineering. Experience in government or regulatory sectors is an asset. Strong familiarity with OWASP standards, threat modeling, and vulnerability management is essential. Technical SkillsProficiency in secure SDLC practices, CI/CD security gates, artifact trust, secrets management, container security concepts, and foundational knowledge of Kubernetes security. Soft SkillsAbility to influence without authority, engage in risk-based communication, provide pragmatic guidance, and handle escalations calmly.

About the job

As a Security Engineer, you will play a pivotal role in embedding DevSecOps security protocols throughout the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) processes using Azure DevOps Server. You will ensure robust security measures are in place, effectively manage vulnerabilities, and maintain audit-ready documentation.

Key Responsibilities

  • Configure and optimize Fortify SAST/DAST tools, setting appropriate thresholds and managing exception workflows.
  • Automate the renewal and deployment of SSL/TLS certificates utilizing tools such as HashiCorp Vault and Cert-Manager in Kubernetes, mitigating downtime and security vulnerabilities.
  • Integrate Software Bill of Materials (SBOM) generation tools into the CI/CD pipeline to oversee component dependencies, license compliance, and vulnerabilities, ensuring transparency within the software supply chain.
  • Implement image signing and verification protocols using tools like Sigstore/Cosign to guarantee code integrity, confirming that only verified and trusted container images are deployed.
  • Establish Quality Gates, define vulnerability SLAs, and create triage processes along with remediation tracking and reporting dashboards.
  • Incorporate secrets management practices using HashiCorp Vault and secure access methods with SecurEnvoy MFA.
  • Provide support for compliance documentation, including scan outputs, approvals, and release evidence packs.
  • Collaborate closely with DevOps and QA teams to establish secure pipeline and test environment controls.

About adree

adree is a forward-thinking company dedicated to enhancing security practices in software development. We strive for excellence by integrating innovative security solutions that empower our teams and enhance our clients' confidence.

Similar jobs

Browse all companies, explore by city & role, or SEO search pages. View directory listings: all jobs, search results, location & role pages.

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.