وصف الوظيفة
سترسم الاتجاه التقني للأمان عبر منصة DigitalZone، من أمان التطبيقات والسحابة إلى تدفقات الدفع والهوية في جوهر العمل.
هذا أغلى منصب أمان فردي مساهم: أنت تملك أصعب المشكلات، وتقوم بالعمل الفعلي، وترفع المستوى لكامل فريق الهندسة.
يمكنك قراءة الشفرة، بناء الأدوات، وإصلاح المشكلة، وليس مجرد حفظها.
ما ستفعله: تصميم وتطوير دورة حياة تطوير البرمجيات الآمنة SDLC، لدعم المهندسين في الأولويات ومعالجة النتائج: أمان التطبيقات: استغلال الأتمتة الحتمية والمساعدة بالـ LLM لتحديد ومعالجة الثغرات في الشفرة المطورة ضمن DigitalZone.
أمان سلسلة التوريد: تصميم وتنفيذ حلول لتخفيف مخاطر الاعتماديات الطرف الثالث القابلة للثغرات والمخترقة.
بما في ذلك التحقق من تكامل الميزة والإصدار.
أمان البنية التحتية والسحابة: دمج حلول قابلة للتوسع لتحديد وتصحيح الثغرات عبر عملية توصيل الحاويات والبنية التحتية السحابية، بما في ذلك الفحص، والتوقيع، والتحكم في الدخول، وأمان وقت التشغيل.
تشغيل إدارة الثغرات والتنسيق لاختبارات الاختراق، وتحديد وتتبع مقاييس الثغرات الرئيسية.
تحديد أنماط آمنة بالتصميم ومعايير النجاح للمصادقة والتفويض، وشبكات السحابة، وإدارة الأسرار، وIAM.
العمل كحلقة وصل رئيسية بين العملاء وبائعي الأمن، قيادة التوافق في نتائج الأمان، أولويات المعالجة، قرارات قبول المخاطر، ونتائج الأمن الاستراتيجية.
تأثير فوري وكبير على عمل عالي النمو حزم تعويض في أعلى السوق العمل بجانب أفضل المواهب الإقليمية، مع أعضاء فريق من Talabat وCareem وEtisalat وغيرهم
ما ستقدمه: أكثر من 8 سنوات في هندسة البرمجيات أو الأمن مع عمق عملي في أمان التطبيقات، أمان السحابة/البنية التحتية، والكشف والاستجابة.
سجل قوي في نمذجة التهديدات وتأمين الأنظمة التي تتعامل مع المدفوعات أو البيانات المالية الحساسة وPII.
أسس هندسية قوية: الطلاقة في أمان AWS، أنماط المصادقة والتفويض الحديثة، وبواحد على الأقل من لغاتنا الأساسية.
معرفة عملية بالأطر ذات الصلة (PCI DSS، ISO 27001، OWASP، SOC 2) وكيفية تشغيلها دون عرقلة التسليم.
تطبيق الحكم في مخاطر المقايضات والتواصل الواضح والعملي مع المهندسين والقيادة.
Job description
You will set the technical direction for security across DigitalZone's platform, from application and cloud security to the payment and identity flows at the core of the business.
This is the most senior individual-contributor security role: you own the hardest problems, do the hands-on work, and raise the bar for the whole engineering org.
You can read the code, build the tooling, and fix the issue, not just file it.
What you'll do: Design and mature the secure SDLC, to support engineers in prioritising and remediating findings: Application Security: Leverage deterministic and LLM assisted automation to identify and remediate vulnerabilities across code developed within DigitalZone.
Supply Chain Security: Design and implement solutions to mitigate the risks of vulnerable and compromised 3rd party dependencies.
Including, the verification of feature and release integrity.
Infrastructure & Cloud Security: Integrate scalable solutions to identify and patch vulnerabilities across the container and cloud infrastructure delivery process, including scanning, signing, admission control and runtime security.
Run vulnerability management and coordinate penetration tests, and defining and tracking key vulnerability metrics.
Define secure-by-design patterns and success criteria for authentication and authorization, cloud networking, secrets management, and IAM.
Act as the primary liaison between customers and security vendors, driving alignment on security findings, remediation priorities, risk acceptance decisions, and strategic security outcomes.
Immediate, large-scale impact on a high-growth business Top-of-the-market compensation packages Work alongside top regional talent, with team members from Talabat, Careem, Etisalat, and more What you'll bring 8+ years in software or security engineering with deep hands-on depth across application security, cloud/infra security, and detection and response.
Strong track record threat modeling and securing systems that handle payments or sensitive financial and PII data.
Strong engineering fundamentals: fluency in AWS security, modern authentication and authorisation patterns, and at least one of our core languages.
Working knowledge of relevant frameworks (PCI DSS, ISO 27001, OWASP, SOC 2) and how to operationalize them without slowing delivery.
Apply judgment on risk tradeoffs and direct, clear and practical communication with engineers and leadership.