Security Engineer, Specialist

Apply Now ↗

About this role

Adree is seeking a Security Engineer to support our product development and engineering initiatives by leveraging deep application security and analytical expertise to articulate the value of secure, compliant digital solutions. In this role, you will work closely with stakeholders to understand technical requirements and business goals, and clearly demonstrate how enforceable security gates and robust vulnerability lifecycle management can address their needs.

You will be responsible for bridging the gap between security compliance and rapid delivery execution, collaborating across teams to operationalize automated security controls throughout the SDLC. By blending secrets management, automated scanning pipelines, and artifact trust mechanisms, you will ensure our digital products are highly secure, resilient, and fully audit-ready.

Key Responsibilities:

  • Engage with clients and stakeholders to gather security requirements and understand their digital transformation and compliance goals
  • Deliver impactful presentations, security dashboards, and reporting frameworks showcasing vulnerability triage, remediation tracking, and pipeline safety metrics
  • Support the engineering and DevOps teams in configuring and tuning Fortify SAST/DAST, establishing clear thresholds, and governing exception workflows
  • Provide technical insights and application security expertise throughout the product lifecycle to automate SSL/TLS certificate renewals using HashiCorp Vault and Cert-Manager in Kubernetes
  • Collaborate with cross-functional teams (including DevOps and QA) to build secure pipelines, manage test environment controls, and enforce software supply chain visibility via SBOM integration
  • Stay current with industry trends, OWASP frameworks, container security concepts, and threat modeling to position solution security effectively
  • Conduct workshops and technical triage sessions internally and with clients to define Quality Gates, vulnerability SLAs, and secure secrets management patterns with SecurEnvoy MFA
  • Participate in Agile development processes and release alignments, producing required compliance evidence, scan outputs, approvals, and comprehensive release evidence packs

Education

  • Bachelor’s degree in Computer Science, Cyber Security, Software Engineering, or a related technical field.

Experience

  • 4+ years of professional experience in Application Security (AppSec), DevSecOps, or Security Engineering.
  • Proven experience operationalizing enforceable security gates within CI/CD pipelines, preferably using Azure DevOps Server.
  • Demonstrated experience with threat modeling, vulnerability management, and operating within government or highly regulated enterprise sectors is a strong plus.

Skills & Competencies (Technical & Analytical + Soft)

  • Deep proficiency in Secure SDLC principles, OWASP Top 10, container security concepts, and Kubernetes/OpenShift security basics.
  • Strong hands-on experience implementing image signing/verification (Sigstore/Cosign) and artifacts lifecycle security via JFrog Artifactory.
  • Analytical skills to correlate security logs and monitoring alerts with enterprise platforms like AppDynamics, BMC, or Azure Monitoring.
  • Excellent soft skills with an ability to influence without authority, deliver pragmatic risk-based guidance, and handle security escalations calmly.
  • Strong collaboration, structured reporting, and cross-functional engineering alignment.

Experience (summary)

  • Operationalization of automated DevSecOps security gates across CI/CD pipelines
  • Vulnerability lifecycle management including triage, SLA tracking, and remediation
  • Automated software supply chain security (SBOM generation & container image signing)
  • Secrets management integration and automated infrastructure certificate management
  • Application security scanning optimization across SAST and DAST frameworks
  • Regulatory compliance evidence gathering and release package auditing

Skills & Competencies (summary)

  • Azure DevOps Server & JFrog Artifactory secure workflow management
  • Fortify SAST/DAST tuning & exception workflow design
  • HashiCorp Vault secrets management & Cert-Manager infrastructure
  • Container & cluster security principles (Kubernetes / Red Hat OpenShift)
  • Multi-factor authentication access patterns (SecurEnvoy MFA)
  • Stakeholder relationship management & security governance
  • Prioritization, risk-based communication, and teamwork
  • Travel for client-facing activities

Job location: HQ

Frequently Asked Questions

Is the salary disclosed for the Security Engineer, Specialist position at c2u9om5Mwb3BDEiNVB4tZh?
The salary for this Security Engineer, Specialist role at c2u9om5Mwb3BDEiNVB4tZh is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Security Engineer, Specialist position at c2u9om5Mwb3BDEiNVB4tZh located?
This Security Engineer, Specialist role at c2u9om5Mwb3BDEiNVB4tZh is based in Riyadh, Riyadh Province, Saudi Arabia. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Which team or department does the Security Engineer, Specialist at c2u9om5Mwb3BDEiNVB4tZh belong to?
This Security Engineer, Specialist position is part of the KSA Office department at c2u9om5Mwb3BDEiNVB4tZh. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Security Engineer, Specialist position at c2u9om5Mwb3BDEiNVB4tZh?
Click the "Apply Now" button on this page. You will be redirected to c2u9om5Mwb3BDEiNVB4tZh's official application portal hosted on workable where you can submit your application directly.
When was the Security Engineer, Specialist job at c2u9om5Mwb3BDEiNVB4tZh posted?
This Security Engineer, Specialist position at c2u9om5Mwb3BDEiNVB4tZh was posted on Feb 23, 2026. Apply as soon as possible — early applications are often reviewed first.
Security Engineer, Specialist
c2u9om5Mwb3BDEiNVB4tZh
Apply for this role ↗

You'll be redirected to c2u9om5Mwb3BDEiNVB4tZh's official application page on workable.