Back

Head of Security

Information Technology and ServicesTechnology

About the role

Role Purpose

As Head of Security at Salla, you are the most senior security authority at Salla. You set the strategy, build the team, and own the controls that keep our platform, our people, and our merchants safe. You translate risk into business language for the executive team and the Board, and you make security a competitive advantage rather than a constraint. You will lead end to end across every security domain and represent Salla's security posture to auditors, regulators, partners, and customers.

Please not that we are looking for Saudi Nationals only for this role.

Key Responsibilities

Security Strategy & Leadership

  • Own and evolve the enterprise security strategy, roadmap, and operating model across cloud, network, endpoint, physical, and GRC, aligned to Salla's growth and public-listing readiness.
  • Act as the organization's principal security advisor; brief the executive team and the Board on cyber risk posture, investment priorities, and regulatory exposure.
  • Define and steward the security budget, headcount plan, and tooling portfolio; drive measurable return on security investment.
  • Establish security KPIs, OKRs, and a metrics-driven reporting cadence for leadership and audit committees.

Cloud Security

  • Lead cloud security across the platform, including landing-zone hardening, network segmentation, secrets management, and workload protection (AWS strongly preferred).
  • Govern Infrastructure-as-Code security, container and Kubernetes security (image scanning, admission control, runtime protection), and CI/CD pipeline integrity.
  • Drive Cloud Security Posture Management, workload protection, and continuous compliance against recognized cloud control frameworks and CIS benchmarks.
  • Partner with SRE and Platform Engineering to embed secure-by-default guardrails that protect velocity rather than slow it.

Network Security

  • Own network security architecture, including edge protection, DDoS mitigation, web application firewall, segmentation, and zero-trust network access.
  • Govern the CDN…
View all