Executive Manager - Squad Cyber Technical Lead
- غير محدد
نُشرت أول أمس
عن الوظيفة
We are seeking an Executive Manager – Squad Cyber Technical Lead to lead the delivery of a cybersecurity squad across four key workstreams: Application Security (AppSec), AI Governance, Continuous Security Validation, and Compliance & Evidence Management.
The role will ensure delivery is aligned with 2nd Line of Defense (2LoD) approved policies, defined SLAs, regulatory requirements, and CBUAE inspection-readiness. The successful candidate will provide technical leadership across DevSecOps, cloud security, and AI/LLM security within a highly regulated banking environment.
Key Responsibilities
- Lead and oversee delivery across AppSec, AI Governance, Continuous Security Validation, and Compliance Trail workstreams.
- Ensure adherence to approved security policies, controls, SLAs, and regulatory requirements.
- Own and manage the consolidated cybersecurity tooling ecosystem, including tools such as SonarQube, Snyk, ServiceNow IRM, Security Agent, Claude, Codex, OPA, Microsoft Defender for Cloud, and AWS Security Hub.
- Drive vendor consolidation, tooling integration, and security architecture across the technology landscape.
- Establish and maintain an end-to-end security evidence and attestation framework, including the DefectDojo Attestation Power BI reporting chain.
- Act as the 1st Line of Defense (1LoD) technical counterpart to 2LoD Risk/Compliance and the AI Centre of Excellence.
- Chair the Security Champions Guild and drive collaboration, knowledge sharing, and security adoption across engineering teams.
- Resolve cross-workstream priorities, dependencies, risks, and technical challenges.
- Prepare and present the monthly DevSecOps Governance Dashboard to 2LoD stakeholders.
- Ensure continuous regulatory and audit readiness, with a strong focus on CBUAE requirements and inspection preparedness.
- Drive implementation of security controls across cloud, application, AI/ML, and DevSecOps environments.
Required Experience & Expertise
- Strong experience in Cybersecurity Engineering and technical leadership, with proven expertise across:
- DevSecOps and Application Security
- Cloud Security across Azure and AWS
- AI/ML and LLM Security & Governance
- Security validation, compliance, and assurance
- Significant experience within banking or other highly regulated industries is essential.
- Hands-on experience implementing and operating security controls in a 3 Lines of Defense (3LoD) model, particularly within 1LoD.
- Proven ability to work effectively with 2LoD on security policies, risk, assurance, controls, and independent testing.
- Strong understanding and practical experience with applicable regulatory and security frameworks, including:
- CBUAE Decree-Law No. 6 of 2025
- CBUAE Enabling Technologies Guidelines
- CBUAE AI/ML Guidance Note
- NIST AI Risk Management Framework (AI RMF)
- ISO/IEC 42001
- Experience managing cybersecurity tooling, security integrations, evidence management, and governance reporting.
Mandatory Certifications
- CISSP – Mandatory
- One of the following:
- CCSP
- AWS Certified Security – Specialty
- Microsoft Azure Security Engineer Associate
- CISM or ISO/IEC 42001 Lead Implementer
- Certified DevSecOps Professional (CDP) or equivalent certification
Desirable Certifications
- SABSA
- GIAC GCSA
Skills: Cybersecurity Engineering , DevSecOps , Cloud Security