Job purpose / role:
To assist, review and validate in implementations of cybersecurity requirements across development activities in Business Technology.
Areas of responsibility:
- Follows all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner
- Follows the day-to-day operations related to own job to ensure continuity of work
- Supports projects or change initiatives through the preparation of technical plans and application of cybersecurity and DevOps design principles.
- Selects appropriate testing approach for automated testing of cybersecurity controls and countermeasures in the DevOps pipeline.
- Analyses and reports on test activities, results, issues and risks, for the cybersecurity initiatives within the DevOps pipeline.
- Plans the capture and management of configuration items and related information for cybersecurity controls and countermeasures within the DevOps pipeline.
- Develops, configures and maintains tools (including automation) to identify, track, log and maintain accurate, complete and current information for cybersecurity controls and countermeasures within the DevOps pipeline.
- Reports on the status of configuration management. Identifies problems and issues to recommend corrective actions, and report on progress cybersecurity initiatives within the DevOps pipeline.
- Assesses and analyses release components for input to release scheduling, maintains and administers tools and methods for cybersecurity software delivery, deployment and configuration of the DevOps pipeline.
- Conducts vulnerability and baseline configuration scanning, change related penetration and security testing activities such as initial information gathering and standard probing; and engagement with engineering/ product teams to resolve identified security vulnerabilities
- Assists in ensuring security is embedded as part of the agile deployment covering sprint planning, defining security user stories and test cases, participating in scrum cadence and sprint retrospectives
- Use security testing and code scanning tools to conduct code reviews
- Perform secure program testing, review, and/or assessment to identify potential flaws in codes and mitigate vulnerabilities.
- Address security implications in the software acceptance phase including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing.
- Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
- Apply coding and testing standards, apply security testing tools including "'fuzzing" static-analysis code scanning tools, and conduct code reviews.
- Contributes to the identification of opportunities for continuous improvement of processes and practices taking into account ‘international best practice’, improvement of business processes, cost reduction and productivity improvement
- Assists in the preparation of timely and accurate reports of Riyad Bank to meet company and department requirements, policies and standards
- Complies with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environment
- Performs other related duties or assignments as directed within the confinement of the departmental roles and responsibilities.
Qualifications & experience:
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Information Technology or equivalent.
Minimum Experience:
- 6-8 years of relevant experience in IT or Cyber Security (SOC, incident response, vulnerability management, penetration test, red teaming)
Language:
English: Advanced