menajobs
  • For Employers
  • Companies
  • Resume Tools
  • ATS Checker
  • Offer Checker
  • Features
  • Pricing
  • FAQ
Post a Job
HireLoginGet Started — Free
Home/Jobs/Software Security Initiative (SSI) Lead
JODAYN logo
JODAYN

Software Security Initiative (SSI) Lead

🇸🇦 Riyadh, Saudi Arabia🏢 On-site
Application SecurityDevSecOpsBSIMMOWASP SAMMNIST SSDFGovernanceKPI

At a Glance

Category
💻 Technology
Level
Senior
Type
Full-time
WhatsAppLinkedInX

Before You Apply

  • Test your resume against JODAYN's ATS
  • Get AI-rewritten bullet points
  • Download Gulf-ready CV
Find Out Now

60 seconds. $5.88 one-time.

JODAYN logo
JODAYN

We are looking for an experienced Software Security Initiative (SSI) Lead to establish and lead a centralized, measurable Application Security program for the client.

The SSI Lead will be responsible for defining the strategic direction of the Application Security program, strengthening DevSecOps maturity based on the outcomes of BSIMM, OWASP DSOMM, and OWASP DSOVS assessments, and establishing the governance, metrics, standards, and enablement programs required to drive sustainable adoption of secure software development practices across the organization.

The role requires strong leadership, stakeholder management, and executive communication skills, with the ability to translate Application Security objectives into measurable initiatives and actionable roadmaps.

  • Develop, maintain, and continuously improve the client's centralized Application Security Framework.
  • Define and monitor Key Performance Indicators (KPIs) and Key Goal Indicators (KGIs) across Application Security functions.
  • Review, update, and maintain Application Security policies, standards, and guidelines.
  • Design and establish a multi-year DevSecOps maturity roadmap, including initiatives, ownership, priorities, and timelines.
  • Design the Application Security Governance Framework and define a clear RACI matrix across Security, Development, and DevOps teams.
  • Review and validate DevSecOps maturity assessment results based on BSIMM 15, OWASP DSOMM, or equivalent frameworks.
  • Independently validate identified gaps, control duplication, and high-risk areas requiring executive management attention.
  • Establish metrics to measure program maturity, security control coverage, and developer adoption.
  • Review and align Application Security policies and standards with NCA, OWASP SAMM, and NIST SSDF.
  • Develop and recommend developer enablement, incentive, and recognition programs to encourage adherence to secure coding standards and Application Security objectives.
  • Design and deliver an Application Security Awareness Program targeting developers, testers, and product managers.
  • Conduct periodic reviews with the client's senior management to communicate progress, challenges, risks, and next steps.
  • Provide strategic recommendations to continuously improve the organization's Application Security and DevSecOps capabilities.
  • Facilitate knowledge transfer to Security and DevOps teams to ensure sustainable ownership of the Application Security framework and roadmap.Requirements & Qualifications
  • Minimum 6 years of professional experience in Application Security, including proven leadership experience.
  • Proven experience leading enterprise-level Application Security or DevSecOps programs.
  • Proven experience conducting, reviewing, or working with BSIMM and/or OWASP SAMM maturity assessments, or equivalent Application Security maturity frameworks.
  • Strong experience designing Application Security frameworks, governance models, RACI matrices, KPI/KGI structures, and awareness programs.
  • Proven ability to develop and execute multi-year Application Security and DevSecOps maturity roadmaps.
  • Strong stakeholder management skills with experience engaging and communicating with senior and executive management.
  • Strong practical experience in Secure Software Development and DevSecOps practices.
  • Proven experience working with CI/CD platforms such as GitLab, Azure DevOps, and/or CloudBees.
  • Strong understanding of integrating security tools into the Software Development Life Cycle (SDLC), including:
  • SAST
  • SCA
  • DAST
  • Secrets Management
  • Infrastructure as Code (IaC) Scanning
  • Strong knowledge of Application Security and cybersecurity frameworks and standards, including:
  • OWASP SAMM
  • OWASP DSOMM
  • OWASP DSOVS
  • BSIMM
  • NIST SSDF
  • NCA Cybersecurity Guidelines
  • Proficiency in automation and scripting using Python, Bash, and/or PowerShell.
  • Strong written and verbal communication skills in English.
  • Arabic language proficiency is an advantage.Preferred / Required Professional Certifications

Candidates must hold at least two (2) certifications or recognized training credentials from the following list:

  • GCSA – GIAC Cloud Security Automation (SANS)
  • GDSA – GIAC Defensible Security Architecture (SANS)
  • DevSecOps Foundation / Professional – DevOps Institute
  • CSSLP – Certified Secure Software Lifecycle Professional (ISC²)
  • GWEB – GIAC Web Application Defender (SANS)
  • OSWE – Offensive Security Web Expert
  • CKS – Certified Kubernetes Security Specialist
  • AZ-400 – Microsoft Azure DevOps Engineer Expert
  • AWS Certified DevOps Engineer – Professional
  • CISSP or CISM – strongly preferred for the SSI Lead role
  • Recognized Secure Coding training from organizations such as SANS, Secure Code Warrior, or OWASP
  • Formal training in BSIMM, OWASP SAMM, OWASP DSOMM, OWASP DSOVS, or NIST SSDFStrong preference will be given to candidates with formal training in BSIMM, OWASP SAMM, or NIST SSDF.

General Project Requirements

  • Candidates will be subject to security screening and background verification before being granted access to client environments.
  • Compliance with the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) is required.
  • All client data must remain within the Kingdom of Saudi Arabia.
  • The successful candidate must comply with the client's internal policies, secure coding standards, change management procedures, and applicable governance frameworks, including OWASP, BSIMM, NIST SSDF, and NCA.

Requirements

  • •Minimum 6 years of professional experience in Application Security
  • •Proven leadership experience in enterprise-level Application Security or DevSecOps programs
  • •Experience conducting or reviewing BSIMM and/or OWASP SAMM maturity assessments
  • •Experience designing Application Security frameworks, governance models, and RACI matrices
  • •Experience designing KPI/KGI structures and awareness programs
  • •Strong stakeholder management and executive communication skills

Responsibilities

  • •Define strategic direction for the Application Security program
  • •Strengthen DevSecOps maturity based on BSIMM, OWASP DSOMM, and OWASP DSOVS assessments
  • •Develop and maintain a centralized Application Security Framework
  • •Define and monitor KPIs and KGIs across Application Security functions
  • •Review and update Application Security policies, standards, and guidelines
  • •Design a multi-year DevSecOps maturity roadmap with clear ownership and timelines
  • •Design the Application Security Governance Framework and RACI matrix
  • •Develop developer enablement, incentive, and recognition programs

Related Jobs4 similar jobs

VAM Systems logo
Java Developer  
VAM Systems · 🇧🇭 Manama
Awtad logo
Legal Advisor
Awtad · 🇸🇦 Riyadh
Al-Watania Information Systems logo
ServiceNow Technical Lead
Al-Watania Information Systems · 🇸🇦 Riyadh
InnovationTeam logo
Quality Assurance Engineer
InnovationTeam · 🇸🇦 Riyadh

Browse Similar

Technology jobs in RiyadhJobs in RiyadhJobs in Saudi ArabiaTechnology jobsJobs at JODAYN
Back to all jobs
Before You Apply
  • Test your resume against JODAYN's ATS
  • Get AI-rewritten bullet points
  • Download Gulf-ready CV
Find Out Now

60 seconds. $5.88 one-time.

GCC Info
Company
JODAYN logo
JODAYN
Visit WebsiteView all jobs
Share
WhatsAppLinkedInX
menajobs

AI-powered GCC job board with resume optimization tools.

Serving:

UAESaudi ArabiaQatarKuwaitBahrainOman

Product

  • For Employers
  • Resume Tools
  • Pricing
  • ATS Checker
  • Offer Evaluator
  • All Tools

Resources

  • Resume Examples
  • Resume Templates
  • Resume Summaries
  • Resume Mistakes
  • Cover Letters
  • Achievement Examples
  • ATS Resume Guide
  • Fresher Resumes

Career Guides

  • CV Format Guides
  • Skills Guides
  • Salary Guides
  • ATS Keywords
  • Job Descriptions
  • Career Paths
  • Interview Questions
  • Career Change
  • GCC Salary Report

Country Guides

  • Jobs by Country
  • Visa Guides
  • Cost of Living
  • Expat Guides
  • Work Culture

Company

  • About
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Shipping & Delivery
  • Sitemap

Browse by Country

  • Jobs in UAE
  • Jobs in Saudi Arabia
  • Jobs in Qatar
  • Jobs in Kuwait
  • Jobs in Bahrain
  • Jobs in Oman

Browse by City

  • Jobs in Dubai
  • Jobs in Abu Dhabi
  • Jobs in Sharjah
  • Jobs in Riyadh
  • Jobs in Jeddah
  • Jobs in Doha
  • Jobs in Kuwait City
  • Jobs in Manama

Browse by Category

  • Technology Jobs
  • Healthcare Jobs
  • Finance Jobs
  • Construction Jobs
  • Oil & Gas Jobs
  • Marketing Jobs
  • Hospitality Jobs
  • Education Jobs

Browse by Nationality

  • UAE Jobs for Indians
  • UAE Jobs for Filipinos
  • Saudi Jobs for Indians
  • Saudi Jobs for Pakistanis
  • Qatar Jobs for Nepalis
  • Qatar Jobs for Filipinos
  • Kuwait Jobs for Egyptians
  • Bahrain Jobs for Indians
  • Oman Jobs for Bangladeshis
  • UAE Jobs for Pakistanis

Popular Searches

  • Tech Jobs in Dubai
  • Healthcare Jobs in Dubai
  • Finance Jobs in Dubai
  • Engineering Jobs in Dubai
  • Marketing Jobs in Dubai
  • Oil & Gas Jobs in Dubai
  • Tech Jobs in Riyadh
  • Healthcare Jobs in Riyadh
  • Finance Jobs in Riyadh
  • Engineering Jobs in Riyadh
  • Marketing Jobs in Riyadh
  • Oil & Gas Jobs in Riyadh
  • Tech Jobs in Abu Dhabi
  • Healthcare Jobs in Abu Dhabi
  • Finance Jobs in Abu Dhabi
  • Engineering Jobs in Abu Dhabi
  • Marketing Jobs in Abu Dhabi
  • Oil & Gas Jobs in Abu Dhabi
  • Tech Jobs in Doha
  • Healthcare Jobs in Doha
  • Finance Jobs in Doha
  • Engineering Jobs in Doha
  • Marketing Jobs in Doha
  • Oil & Gas Jobs in Doha
  • Tech Jobs in Kuwait City
  • Healthcare Jobs in Kuwait City
  • Finance Jobs in Kuwait City
  • Engineering Jobs in Kuwait City
  • Marketing Jobs in Kuwait City
  • Oil & Gas Jobs in Kuwait City

As featured on

Featured on Better LaunchFeatured on neeed.directoryFeatured on Aura++ViesearchList on SimilarlabsLaunched onTiny Startupstinystartups.comFeatured on Findly.toolsFeatured on LaunchVerified on DANG!Featured on FoundrList
Featured on Better LaunchFeatured on neeed.directoryFeatured on Aura++ViesearchList on SimilarlabsLaunched onTiny Startupstinystartups.comFeatured on Findly.toolsFeatured on LaunchVerified on DANG!Featured on FoundrList
Featured on Better LaunchFeatured on neeed.directoryFeatured on Aura++ViesearchList on SimilarlabsLaunched onTiny Startupstinystartups.comFeatured on Findly.toolsFeatured on LaunchVerified on DANG!Featured on FoundrList
Featured on Better LaunchFeatured on neeed.directoryFeatured on Aura++ViesearchList on SimilarlabsLaunched onTiny Startupstinystartups.comFeatured on Findly.toolsFeatured on LaunchVerified on DANG!Featured on FoundrList

© 2026 MenaJobs. All rights reserved.

HireLoginGet Started — Free