نحن نبحث عن مدير تنفيذي – قائد فريق الأمن السيبراني التقني لقيادة تقديم فريق الأمن السيبراني عبر أربعة مسارات عمل رئيسية: أمن التطبيقات (AppSec)، حوكمة الذكاء الاصطناعي، التحقق المستمر من الأمان، والامتثال وإدارة الدليل.
سيتأكد الدور من أن التنفيذ متوافق مع السياسات المعتمدة لـ الجبهة الثانية للدفاع (2LoD)، ومستويات الخدمة المحددة، والمتطلبات التنظيمية، وجاهزية فحص CBUAE. سيقدم المرشح الناجح القيادة الفنية عبر DevSecOps، أمان الحوسبة السحابية، وأمان الذكاء الاصطناعي/نماذج اللغة ضمن بيئة مصرفية منظمة للغاية.
المسؤوليات الأساسية
قيادة والإشراف على التسليم عبر مسارات العمل أمن التطبيقات، حوكمة AI، التحقق الأمني المستمر، ومسار الامتثال.
التأكد من الالتزام بسياسات الأمان المعتمدة، والضوابط، ومستويات الخدمة، والمتطلبات التنظيمية.
إدارة وتملك منظومة أدوات الأمن السيبراني المجمّعة، بما في ذلك أدوات مثل SonarQube، Snyk، ServiceNow IRM، Security Agent، Claude، Codex، OPA، Microsoft Defender for Cloud، وAWS Security Hub.
قيادة توحيد البائعين، تكامل الأدوات، وهندسة الأمن عبر مشهد التكنولوجيا.
إنشاء وصيانة إطار عمل أدلة وبيانات أمان ونزاهة من الطرف الأول إلى الطرف الأخير، بما في ذلك سلسلة الإبلاغ DefectDojo → Attestation → Power BI.
العمل كالنظير الفني لـ الجبهة الأولى للدفاع (1LoD) إلى مخاطر/امتثال الجبهة الثانية ومركز التميز في AI.
رئاسة نقابة أبطال الأمن وتعزيز التعاون وتبادل المعرفة وتبني الأمن عبر فرق الهندسة.
حل أولويات العمل عبر المسارات المختلفة، والتبعيات، والمخاطر، والتحديات التقنية.
إعداد وعرض لوحة حوكمة DevSecOps الشهرية لأصحاب المصلحة من 2LoD.
ضمان الاستعداد التنظيمي والتدقيق المستمر، مع تركيز قوي على متطلبات CBUAE وجهوزية الفحص.
قيادة تنفيذ ضوابط الأمن عبر بيئات السحابة والتطبيقات والذكاء الاصطناعي/تعلم الآلة وDevSecOps.
الملف المرغوب للمرشح
الخبرة والخبرة المطلوبة
خبرة قوية في هندسة الأمن السيبراني والقيادة التقنية، مع خبرة مثبتة عبر:
DevSecOps وأمن التطبيقات
أمن السحابة عبر Azure وAWS
الذكاء الاصطناعي/تعلم الآلة وأمان وحوكمة LLM
التحقق الأمني، الامتثال، والضمان
خبرة كبيرة في القطاع المصرفي أو صناعات عالية التنظيم أمر ضروري.
خبرة عملية في تنفيذ وتشغيل ضوابط الأمن في نموذج 3 خطوط دفاع (3LoD)، خاصة ضمن 1LoD.
قدرة مثبتة على العمل بفعالية مع 2LoD في سياسات الأمان، المخاطر، الضمان، الضوابط، والاختبارات المستقلة.
فهم قوي وخبرة عملية مع الأطر التنظيمية والأمنية المعمول بها، بما في ذلك:
مرسوم-القانون الإماراتي رقم 6 لسنة 2025 بشأن هيئة تنظيم الاتصالات
ـــدلالات التكنولوجيا الممكنة لـ CBUAE
CBUAE دليل توجيهي لــ AI/ML
إطار عمل إدارة مخاطر AI من NIST (AI RMF)
ISO/IEC 42001
خبرة في إدارة أدوات الأمن السيبراني، وتكامُل الأمان، وإدارة الأدلة وتقرير الحوكمة.
الاعتمادات المطلوبة
CISSP – إلزامي
أحد ما يلي:
CCSP
AWS Certified Security – Specialty
Microsoft Azure Security Engineer Associate
CISM أو ISO/IEC 42001 Lead Implementer
Certified DevSecOps Professional (CDP) أو ما يعادله من شهادة
الاعتمادات المرغوبة
SABSA
GIAC GCSA
المهارات
هندسة الأمن السيبراني
DevSecOps
أمن السحابة
We are seeking an Executive Manager – Squad Cyber Technical Lead to lead the delivery of a cybersecurity squad across four key workstreams: Application Security (AppSec), AI Governance, Continuous Security Validation, and Compliance & Evidence Management.
The role will ensure delivery is aligned with 2nd Line of Defense (2LoD) approved policies, defined SLAs, regulatory requirements, and CBUAE inspection-readiness. The successful candidate will provide technical leadership across DevSecOps, cloud security, and AI/LLM security within a highly regulated banking environment.
Key Responsibilities
Lead and oversee delivery across AppSec, AI Governance, Continuous Security Validation, and Compliance Trail workstreams.
Ensure adherence to approved security policies, controls, SLAs, and regulatory requirements.
Own and manage the consolidated cybersecurity tooling ecosystem, including tools such as SonarQube, Snyk, ServiceNow IRM, Security Agent, Claude, Codex, OPA, Microsoft Defender for Cloud, and AWS Security Hub.
Drive vendor consolidation, tooling integration, and security architecture across the technology landscape.
Establish and maintain an end-to-end security evidence and attestation framework, including the DefectDojo → Attestation → Power BI reporting chain.
Act as the 1st Line of Defense (1LoD) technical counterpart to 2LoD Risk/Compliance and the AI Centre of Excellence.
Chair the Security Champions Guild and drive collaboration, knowledge sharing, and security adoption across engineering teams.
Resolve cross-workstream priorities, dependencies, risks, and technical challenges.
Prepare and present the monthly DevSecOps Governance Dashboard to 2LoD stakeholders.
Ensure continuous regulatory and audit readiness, with a strong focus on CBUAE requirements and inspection preparedness.
Drive implementation of security controls across cloud, application, AI/ML, and DevSecOps environments.
Desired Candidate Profile
Required Experience & Expertise
Strong experience in Cybersecurity Engineering and technical leadership, with proven expertise across:
DevSecOps and Application Security
Cloud Security across Azure and AWS
AI/ML and LLM Security & Governance
Security validation, compliance, and assurance
Significant experience within banking or other highly regulated industries is essential.
Hands-on experience implementing and operating security controls in a 3 Lines of Defense (3LoD) model, particularly within 1LoD.
Proven ability to work effectively with 2LoD on security policies, risk, assurance, controls, and independent testing.
Strong understanding and practical experience with applicable regulatory and security frameworks, including:
CBUAE Decree-Law No. 6 of 2025
CBUAE Enabling Technologies Guidelines
CBUAE AI/ML Guidance Note
NIST AI Risk Management Framework (AI RMF)
Experience managing cybersecurity tooling, security integrations, evidence management, and governance reporting.
Mandatory Certifications
CISSP – Mandatory
One of the following:
CISM or ISO/IEC 42001 Lead Implementer
Certified DevSecOps Professional (CDP) or equivalent certification
Desirable Certifications
Skills
Cybersecurity Engineering
Cloud Security
Tanqeeb.com هو محرك البحث عن الوظائف الأول فى الوطن العربى الذى يجمع لك الوظائف المناسبة من مختلف مواقع التوظيف الآخرى فى مكان واحد !