About the job
Who We Are
At Foodics, we are revolutionizing the restaurant management landscape as a prominent ecosystem and payment technology provider. Established in 2014 and headquartered in Riyadh, we have expanded our presence across five countries, including the UAE, Egypt, Jordan, and Kuwait. With a customer base that spans over 35 countries globally, our cutting-edge products have processed more than 6 billion orders, making Foodics one of the fastest-growing SaaS companies to originate from the MENA region. Our recent funding round raised $170 million, marking the largest SaaS funding initiative in MENA, which enhances our capacity to innovate and serve business owners effectively.
The Role at a Glance
We are on the lookout for a Senior Cloud Security Engineer with approximately 3 years of experience to bolster our daily cloud security operations and internal infrastructure management.
This position is crucial for monitoring, operational support, incident response, and ensuring secure configurations across Foodics' cloud platforms and services.
As a vital part of the Cloud Security Operations team, you will contribute to safeguarding our systems, addressing alerts, supporting internal teams, and ensuring our infrastructure remains compliant, secure, and resilient.
Your Responsibilities
- Promote the adoption of zero-trust, least privilege, and defense-in-depth security principles.
- Establish secure baseline configurations for compute, storage, databases, and serverless environments.
- Engage proactively in threat landscape monitoring using diverse threat intelligence and OSINT tools.
- Collaborate closely with the Cybersecurity team for attack surface management, vulnerability assessments, and executing patch management protocols.
- Continuously assess and mitigate identity risks using PAM and IAM platforms.
- Regularly review security logs from SIEM, WAF, and CloudTrail while collaborating with our outsourced MDR vendor for incident management and reporting.
- Oversee WAF, DDoS protection, and secure ingress/egress controls.
- Work in conjunction with Application Security and QA teams to analyze code-level security issues using SAST/DAST tools and follow up on remediation plans.
- Manage cloud KMS, key lifecycle, and secrets management solutions.
- Partner with Cloud Engineers and SRE teams to define and enforce cloud guardrails through native policies and controls.
- Develop and maintain cloud security reference architectures, design patterns, and document incident response playbooks.
- Assist in audits and security assessments including ISO27001, NCA ECC, SAMA CSF, PCI-DSS, SOC 2, and GDPR.
What We Are Seeking
- Extensive expertise in IAM, network security, and cloud security.
