Senior Specialist - Asset Security Operations
Own the day-to-day security operations of business applications across Qiddiya's asset environments by managing application security controls, vulnerability remediation, secure configurations, access management, and patching. Act as the primary liaison with the Cybersecurity Team to coordinate penetration testing and code scanning activities, drive timely remediation of identified vulnerabilities, and ensure applications remain secure, compliant, and operational throughout their lifecycle
Key Responsibilities
- Manage WAF/API security policies, rule tuning, and virtual patching (Cloudflare).
- Track and drive remediation of application vulnerabilities identified through penetration testing and SAST/DAST, ensuring SLA compliance via ServiceNow.
- Coordinate application and service account access provisioning through BeyondTrust PAM.
- Manage application patching, secure configurations, and dependency updates.
- Maintain application security baselines, including WAF, access controls, secrets, and certificates for new application go-lives.
- Manage application secrets and certificate lifecycle.
- Coordinate with the Cybersecurity Team on penetration testing, code scanning, and remediation activities.
- Monitor application security compliance and produce regular security reports.
Requirements
- 2+ years of experience in cybersecurity, preferably in application or web security.
- Experience with WAF platforms, ITSM tools, and vulnerability remediation processes.
- Understanding of secure SDLC principles and the interpretation of penetration testing and SAST/DAST findings.
- Familiarity with application patching, access management, and security configuration best practices
As published by workable
First name, Last name, Email, Phone, Address, Highest Education Level, Gender, Please confirm your nationality, Do you, or any immediate family member or close personal associate, have any actual, potential, or perceived conflict of interest in relation to QIC, arising from personal relationships, financial interests, or external employment, business activities, or services, that could reasonably be perceived as influencing your independence, objectivity, or decision-making if employed by QIC?, Are you currently or have you ever worked directly for PIF or one of its affiliated companies?, Do you have any social media accounts such as Twitter, Facebook, LinkedIn, TikTok, YouTube or other platforms? If yes please share your usernames or links to you profiles:, Current Location, Date of Birth, Expected Salary, Current monthly salary, Nationality Field, Education, Experience, Summary, Resume, Years of relevant experience, Are you currently involved or working directly for Qiddiya either through a delivery partner or as a consultant?, By proceeding, I acknowledge that I have read the Privacy Notice https://qiddiya.com/en/careers/career-privacy-notice/ and consent to the use of my personal data provided in my job application for the purpose of conducting the recruitment process with Qiddiya Investment Company. I confirm that all information submitted as part of my job application is complete, accurate, and true to the best of my knowledge. I understand that providing false, misleading, or incomplete information at any stage of the application or profile creation process may result in the rejection of my application. I further acknowledge and agree that Qiddiya Investment Company may verify the information I have provided, either directly or through authorized third parties., I hereby confirm that I have never had any criminal conviction, an arrest or charge for which I am currently on or awaiting trial