JOIN THE TEAM  ·  Careers

Work That Actually Matters.

We are a small, focused team building the cybersecurity firm we wished existed when we were on the client side. Every person here has a direct impact on the businesses we protect. There is no bloated hierarchy and no work that disappears into a void.

Actively hiring for select roles
01 Who We Are

What We Believe In

We did not build Code Defence to be the biggest cybersecurity firm in the region. We built it to be the most trusted one. That ambition shapes everything about how we hire and how we work. We look for people who care more about the outcome than the appearance of the outcome.

Outcomes Over Activity

We measure success by whether the client's security is genuinely better, not by the number of documents produced or hours billed. A report that sits unread is not a deliverable. A closed vulnerability is.

Radical Honesty

We tell clients what they need to hear, not what they want to hear, and we expect the same standard internally. People who need to be right all the time do not thrive here.

Continuous Learning

The threat landscape and the regulations we work within change constantly. We invest in learning because stagnation is a security risk in our industry as much as anywhere else.

Client Respect

Our clients are mostly founders and operators trying to run a business who realised they need security help. We never make them feel unintelligent for not knowing what we know.

Practical Over Theoretical

Perfect security that never gets implemented helps nobody. We build programmes that work within real constraints and produce demonstrable improvement.

Regional Roots

We are a GCC firm, not a Western firm operating in the GCC. Understanding the regulatory environment and business culture specific to this region is the whole point.

02 How We Work

Life at Code Defence

We are a small team by choice. Small teams move faster, communicate better, and each individual has a more visible impact. We do not plan to become large just for the sake of it; growth happens when it serves clients better, not when it serves a headcount target. Most of our work is done remotely, with periodic visits to clients across the GCC when it adds genuine value.

Remote-first, working across the GCC

Most roles can be performed remotely with periodic client visits and occasional team gatherings in person.

Outcomes-focused, not hours-focused

We do not track hours worked. We track whether client programmes are running well and whether deliverables are high quality.

Competitive compensation

We pay at or above market rate for the GCC, reviewed annually and adjusted based on performance and market movement.

Learning and certification budget

Every team member gets an annual budget for certifications, courses, and conferences. We cover CISSP, CISM, CDPSE, CISA, CEH, and more. See what our team currently holds on our Certifications page.

Comprehensive health coverage

Full private health insurance for you and immediate family, standard from day one.

Flexible remote working

A home office allowance for equipment and connectivity, with travel and accommodation covered when we gather in person.

03 Open Roles

Current Openings

We hire selectively and deliberately. Every role we open is one where we genuinely need someone and believe the right person will thrive.

Security Consultant (vCISO Delivery)

Remote — GCCFull TimeMid to Senior

You will manage a portfolio of vCISO engagements across GCC SMEs, operating as the most senior security person in the room for your clients: developing and owning their security programmes, presenting to boards, and handling anything from a routine risk review to an incident response. Five or more years of security experience and deep familiarity with at least two GCC regulatory frameworks required.

Apply →

Data Privacy Consultant (vDPO Delivery)

Remote — GCCFull TimeMid Level

You will deliver vDPO services to a portfolio of clients across Saudi Arabia and the UAE, managing their PDPL and UAE FDPL compliance programmes end to end, from data mapping through breach readiness. Experience with data protection compliance in a regulated GCC sector preferred.

Apply →

Vulnerability Management Analyst (VMaaS)

Remote — GCCFull TimeMid Level

You will run continuous scanning and remediation tracking across a portfolio of client environments, prioritising findings by real-world exploitability and working directly with client teams to close them. Hands-on experience with vulnerability scanning tools and cloud security configuration required.

Apply →

Don't See Your Role?

Speculative Application

If you do not see a role that fits today but believe you belong here, reach out anyway. We hire selectively but we are always interested in meeting people who share how we think about this work.

Send a Speculative Application →

Think You'd Be a Good Fit?

Tell us a bit about yourself and what draws you to this work.