وظائف افراد امن في الإمارات
١٤١١٦ وظائف شاغرة
We are looking for a Security Specialist to implement, manage, and support enterprise endpoint and email security solutions. The role focuses on threat detection, security monitoring, incident investigation, policy management, and operational support of security platforms. The successful candidate will work closely with security operations teams to investigate threats, improve security controls, and maintain effective protection against phishing, malware, ransomware, and advanced cyber threats.<br>Key Responsibilities Configure, manage, and support endpoint and email security platforms including Microsoft Defender for Endpoint, Proofpoint Email Security, Trend Micro solutions, and Microsoft Exchange Online Protection. Investigate security alerts related to phishing attacks, malware infections, ransomware activity, endpoint compromise, and email-based threats. Perform security policy configuration, tuning, optimisation, and improvements to enhance threat detection capabilities. Conduct threat analysis, incident investigation, containment, and remediation activities. Work with SOC teams to support security escalations, threat investigations, and incident response processes. Monitor security platforms and ensure security controls are properly configured and maintained. Support security assessments, audits, compliance activities, and operational documentation.<br>Required Skills & Experience5–6 years of experience in cybersecurity operations, endpoint security, or email security. Hands-on experience with endpoint and email security solutions such as Microsoft Defender for Endpoint, Proofpoint Email Security, Trend Micro Security Solutions, or Microsoft Exchange Online Protection. Strong understanding of endpoint protection, email security, phishing analysis, malware investigation, and security incident response. Experience managing security policies, investigating alerts, and performing threat remediation. Knowledge of email security protocols including SPF, DKIM, and DMARC. Experience integrating security tools with SIEM/SOC platforms. Relevant vendor certifications such as Microsoft security certifications, Proofpoint certifications, or Trend Micro certifications.<br>Preferred Skills Experience with Microsoft 365 security ecosystem. Knowledge of threat hunting techniques and security investigation processes. Experience supporting enterprise security operations. Strong analytical, troubleshooting, and documentation skills.
We are looking for a Security Specialist to implement, manage, and support enterprise endpoint and email security solutions. The role focuses on threat detection, security monitoring, incident investigation, policy management, and operational support of security platforms. The successful candidate will work closely with security operations teams to investigate threats, improve security controls, and maintain effective protection against phishing, malware, ransomware, and advanced cyber threats.<br>Key Responsibilities Configure, manage, and support endpoint and email security platforms including Microsoft Defender for Endpoint, Proofpoint Email Security, Trend Micro solutions, and Microsoft Exchange Online Protection. Investigate security alerts related to phishing attacks, malware infections, ransomware activity, endpoint compromise, and email-based threats. Perform security policy configuration, tuning, optimisation, and improvements to enhance threat detection capabilities. Conduct threat analysis, incident investigation, containment, and remediation activities. Work with SOC teams to support security escalations, threat investigations, and incident response processes. Monitor security platforms and ensure security controls are properly configured and maintained. Support security assessments, audits, compliance activities, and operational documentation.<br>Required Skills & Experience5–6 years of experience in cybersecurity operations, endpoint security, or email security. Hands-on experience with endpoint and email security solutions such as Microsoft Defender for Endpoint, Proofpoint Email Security, Trend Micro Security Solutions, or Microsoft Exchange Online Protection. Strong understanding of endpoint protection, email security, phishing analysis, malware investigation, and security incident response. Experience managing security policies, investigating alerts, and performing threat remediation. Knowledge of email security protocols including SPF, DKIM, and DMARC. Experience integrating security tools with SIEM/SOC platforms. Relevant vendor certifications such as Microsoft security certifications, Proofpoint certifications, or Trend Micro certifications.<br>Preferred Skills Experience with Microsoft 365 security ecosystem. Knowledge of threat hunting techniques and security investigation processes. Experience supporting enterprise security operations. Strong analytical, troubleshooting, and documentation skills.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<strong>Senior Security Engineer</strong>
<strong>Role Overview</strong>
<p>We are seeking an experienced <strong>Senior Security Engineer</strong> to strengthen and evolve enterprise security practices across application, infrastructure, and cloud environments within a highly regulated financial services environment.</p><br><br>
<p>This role will be responsible for driving secure-by-design principles across the software development lifecycle, implementing DevSecOps best practices, conducting security assessments, and enhancing the organization's overall security posture. The successful candidate will work closely with Development, DevOps, Infrastructure, Architecture, and Product teams to ensure security controls are embedded throughout the technology landscape.</p><br><br>
<p>The ideal candidate will possess deep technical expertise across application security, cloud security, penetration testing, threat modelling, and security architecture, combined with strong stakeholder management and communication skills.</p><br><br>
<strong>Key Responsibilities</strong>
<ul>
<li>Conduct web, mobile, and API penetration testing and vulnerability assessments. </li><li>Perform secure code reviews and identify application and infrastructure security weaknesses. </li><li>Manage and optimize security tooling including: <ul>
<li>SAST </li><li>DAST </li><li>SCA </li><li>Infrastructure as Code (IaC) Security </li><li>Container Security Solutions </li></ul>
</li><li>Drive DevSecOps initiatives and integrate security controls into CI/CD pipelines. </li><li>Perform threat modelling, security risk assessments, and architecture reviews. </li><li>Design and review secure solutions across cloud, container, Kubernetes, and enterprise platforms. </li><li>Lead vulnerability management activities, including remediation planning and tracking. </li><li>Support security incident investigations, root cause analysis, and remediation efforts. </li><li>Deliver security awareness sessions and secure coding training to engineering teams. </li><li>Collaborate with development, DevOps, infrastructure, and product teams to ensure secure implementation of solutions. </li><li>Support continuous improvement of security standards, processes, and governance frameworks. </li><li>Participate in security reviews and compliance initiatives across enterprise projects.
</li></ul>
<strong>Required Skills & Qualifications</strong>
<ul>
<li>8–15 years of experience in Information Security, Cyber Security, or Security Engineering roles. </li><li>Strong hands-on expertise in: <ul>
<li>Application Security </li><li>Infrastructure Security </li><li>Cloud Security </li><li>Security Architecture </li></ul>
</li><li>Deep experience performing: <ul>
<li>Web Application Penetration Testing </li><li>API Security Testing </li><li>Mobile Security Testing </li><li>Vulnerability Assessments </li></ul>
</li><li>Strong understanding of: <ul>
<li>OWASP Top 10 </li><li>OWASP API Security Top 10 </li><li>Secure Development Practices </li></ul>
</li><li>Experience implementing and managing DevSecOps programmes. </li><li>Strong expertise with CI/CD security integration and security automation. </li><li>Experience conducting: <ul>
<li>Threat Modelling </li><li>Risk Assessments </li><li>Security Architecture Reviews </li><li>Secure Design Assessments </li></ul>
</li><li>Hands-on experience securing: <ul>
<li>Kubernetes Environments </li><li>Docker Containers </li><li>Microservices Architectures </li><li>Cloud-Native Applications </li></ul>
</li><li>Strong knowledge of: <ul>
<li>AWS Security </li><li>Azure Security </li><li>Identity & Access Management </li><li>Secrets Management </li><li>Network Security </li></ul>
</li><li>Experience supporting security incident response and remediation activities. </li><li>Strong stakeholder management, presentation, and communication skills. </li><li>Experience with scripting and automation using: <ul>
<li>Python </li><li>Bash </li><li>PowerShell </li></ul>
</li></ul>
<strong>Preferred Skills & Experience</strong>
<ul>
<li>Banking or Financial Services industry experience. </li><li>Strong understanding of PCI-DSS compliance requirements. </li><li>Experience working with governance and compliance frameworks including: <ul>
<li>ISO 27001 </li><li>SOC 2 </li><li>NIST </li><li>CIS </li></ul>
</li><li>Familiarity with GDPR and privacy regulations. </li><li>Experience establishing or supporting Security Champion programmes. </li><li>Exposure to Security Operations and Incident Response functions. </li><li>Relevant security certifications such as: <ul>
<li>CISSP </li><li>CSSLP </li><li>OSCP </li><li>CEH </li><li>AWS Security Specialty </li><li>Azure Security Engineer Associate </li></ul>
</li></ul>
<strong>Halian Group</strong>
<p>With over 28 years of experience, we have come to understand that innovation is the only way to provide agile, practical solutions that transform businesses and careers. Our resourcing and smart services help you to realise tomorrow's potential. Discover the amazing things possible when you bring the right people and the right technologies together.</p><br><br>
<p>At Halian, we recognise that diversity, equity, and inclusion (DEI) are essential to building high-performing teams for our clients. We are committed to connecting organisations with top talent from all backgrounds, ensuring that every individual feels valued, respected, and empowered to contribute their unique perspectives.</p><br><br>
<p>We encourage applications from all qualified candidates, regardless of race, gender, disability, or any other characteristic that makes them unique.</p><br><br>
<p><strong>#LI-CC1</strong></p><br><br>
<br><br> </div>
???? Security Architect with SAP RISE | SAP experience (MUST HAVE)<br><br>???? Contract: 12 months, renewable contract<br>???? Shape the future of security within one of the Middle East's largest digital transformation programmes. We're partnering with one of the Middle East's leading luxury retail groups to appoint an experienced Security Architect who will play a pivotal role in designing and embedding enterprise security across a large-scale SAP Transformation Programme. This is a high-impact opportunity to influence security strategy, architecture, governance, and secure-by-design principles across a complex enterprise environment.<br>What We're Looking For (Must-Haves)✅ 8+ years' experience in Security Architecture or Enterprise Security Architecture✅ MUST HAVE SAP experience (SAP S/4HANA and SAP RISE are essential)✅ Solid understanding of ISO 27001 Controls, Security Governance and Risk Management✅ Experience designing security architecture for large-scale ERP or Digital Transformation ✅ Knowledge of IAM, PAM, GRC, Cloud Security and Enterprise Security Frameworks✅ Excellent stakeholder engagement skills, with the ability to influence technical and business teams<br>What You'll Be Doing???? Design & own enterprise security architecture across a major SAP transformation programme???? Define security standards, frameworks and architectural best practices???? Embed Security by Design across SAP solutions and programme delivery???? Lead architecture reviews, security assessments and risk mitigation initiatives???? Ensure compliance with ISO 27001 controls and enterprise security standards???? Partner with Information Security, Enterprise Architecture, SAP Delivery Teams, PMO and senior business stakeholders<br>Why Join?✨ Join one of the largest luxury retail organisations in the Middle East✨ Work on a flagship enterprise SAP transformation with high executive visibility✨ Influence the security strategy of a business investing heavily in technology and innovation✨ Collaborate with senior leaders and highly skilled technology teams on business-critical initiatives✨ Long-term programme with exciting career growth and exposure to cutting-edge enterprise technologies<br>???? Location: Dubai, UAE (Hybrid)???? Contract: 12 months, renewable contract If you're passionate about Enterprise Security Architecture, SAP Security, and delivering security across complex transformation programmes, I'd love to hear from you.<br>#Security Architect #Cyber Security #Information Security #SAPSecurity #SAPRISE #S4HANA #SAP #Enterprise Architecture #Cyber Security Jobs #ISO27001 #IAM #PAM #Cloud Security #GRC #Dubai Jobs #UAEJobs #Tech Jobs #Digital Transformation #Hiring Now
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><b>Job Description:</b></p><p><b> </b></p><p>The AI, Data Governance & Privacy Officer is responsible for establishing and operating the enterprise-wide governance framework for data, artificial intelligence, privacy, and responsible digital innovation.</p><p> </p><p>The role serves as the second-line governance authority for AI and data, ensuring that the organisation maximises the value of data and AI while maintaining compliance with regulatory requirements, ethical standards, privacy obligations, and enterprise risk management principles.</p><p> </p><p>The officer will lead the development of data governance and AI governance frameworks, oversee privacy compliance programmes, drive trustworthy AI adoption, and act as the organisational subject matter expert on data protection, AI risk management, and information governance.</p><p> </p><p>This role is particularly critical as the organisation expands the use of Agentic AI, Generative AI, advanced analytics, machine learning, intelligent automation, and enterprise data platforms across underwriting, claims, finance, reinsurance, customer service, and corporate operations.</p><p> </p><p><b>What you will do</b></p><p> </p><p><b>1. Enterprise AI Governance</b></p><p> </p><ul><li>Establish and maintain the enterprise AI Governance Framework.</li></ul><p> </p><ul><li>Define policies, standards, controls, and operating procedures for AI usage.</li></ul><p> </p><ul><li>Create governance models for:</li></ul><p> </p><ul><li>Agentic AI</li><li>Generative AI</li><li>Machine Learning</li><li>Advanced Analytics</li><li>Intelligent Automation</li></ul><p> </p><ul><li>Chair the AI Governance Committee.</li></ul><p> </p><ul><li>Define AI approval and risk assessment processes.</li></ul><p> </p><ul><li>Ensure AI initiatives align with:</li></ul><p> </p><ul><li>Regulatory requirements</li><li>Ethical AI principles</li><li>Security policies</li><li>Business objectives</li></ul><p> </p><ul><li>Implement AI lifecycle governance across development, deployment, monitoring, and retirement.</li></ul><p> </p><ul><li>Develop controls for:</li><li>Explainability</li><li>Fairness</li><li>Bias management</li><li>Human oversight</li><li>Model monitoring</li><li>Prompt governance</li><li>Auditability</li></ul><p> </p><p> </p><p><b>2. Data Governance & Information Management</b></p><p> </p><ul><li>Develop and operate the enterprise data governance framework.</li></ul><p> </p><ul><li>Establish data ownership and stewardship models.</li></ul><p> </p><ul><li>Define enterprise standards for:</li></ul><p> </p><ul><li>Data quality</li><li>Metadata management</li><li>Master data management</li><li>Data lineage</li><li>Data retention</li><li>Data classification</li></ul><p> </p><ul><li>Lead enterprise data cataloguing and inventory programmes.</li></ul><p> </p><ul><li>Implement data governance tooling and controls.</li></ul><p> </p><ul><li>Develop governance measures for structured and unstructured data.</li></ul><p> </p><ul><li>Drive data quality improvement initiatives across business functions.</li></ul><p> </p><ul><li>Establish governance for enterprise data platforms, analytics environments, GenAI platforms, and data lakes.</li></ul><p> </p><p> </p><p><b>3. Privacy & Data Protection</b></p><p> </p><ul><li>Act as Data Protection Officer (where required by regulation).</li></ul><p> </p><ul><li>Lead compliance with:</li></ul><p> </p><ul><li>UAE PDPL</li><li>DIFC Data Protection Law</li><li>GDPR</li><li>Other applicable regional privacy regulations</li></ul><p> </p><ul><li>Define and maintain enterprise privacy frameworks.</li></ul><p> </p><ul><li>Conduct and oversee:</li></ul><p> </p><ul><li>Data Protection Impact Assessments (DPIAs)</li><li>Privacy Risk Assessments</li><li>Third-party Privacy Reviews</li></ul><p> </p><ul><li>Establish Privacy by Design practices across business and technology initiatives.</li></ul><p> </p><ul><li>Manage:</li></ul><p> </p><ul><li>Data Subject Rights Requests</li><li>Consent management processes</li><li>Cross-border transfer assessments</li><li>Breach response governance</li></ul><p> </p><p><b>4. AI Risk & Model Governance</b></p><p> </p><ul><li>Define model governance standards.</li></ul><p> </p><ul><li>Establish model risk management processes.</li></ul><p> </p><ul><li>Classify AI systems based on risk and criticality.</li></ul><p> </p><ul><li>Develop controls for:</li></ul><p> </p><ul><li>Model validation</li><li>Performance monitoring</li><li>Drift detection</li><li>Explainability</li><li>Human-in-the-loop oversight</li></ul><p> </p><ul><li>Maintain an enterprise AI model inventory.</li></ul><p> </p><ul><li>Conduct periodic AI risk assessments.</li></ul><p> </p><ul><li>Ensure regulatory readiness for emerging AI regulations.</li></ul><p> </p><p><b>5. Regulatory Compliance & Audit</b></p><p> </p><ul><li>Monitor evolving AI, privacy, and data regulations globally.</li></ul><p> </p><ul><li>Translate regulatory requirements into governance controls.</li></ul><p> </p><ul><li>Coordinate regulatory responses and examinations.</li></ul><p> </p><ul><li>Support Internal Audit, Risk, Compliance, and External Audit activities.</li></ul><p> </p><ul><li>Maintain evidence repositories for governance and compliance activities.</li></ul><p> </p><ul><li>Lead remediation of governance and privacy findings.</li></ul><p> </p><p><b>6. Vendor, Third-Party & Cloud Governance</b></p><p> </p><ul><li>Define governance requirements for AI vendors and data processors.</li></ul><p> </p><ul><li>Review:</li></ul><p> </p><ul><li>SaaS contracts</li><li>AI solution providers</li><li>Data sharing arrangements</li><li>Third-party processing agreements</li></ul><p> </p><ul><li>Assess external AI platforms for privacy, security, compliance, and ethical risk.</li></ul><p> </p><ul><li>Establish governance controls for third-party LLMs and foundation model providers.</li></ul><p> </p><p><b>7. Governance Awareness & Culture</b></p><p> </p><ul><li>Develop enterprise-wide training programmes on:</li></ul><p> </p><ul><li>Responsible AI</li><li>Data governance</li><li>Data protection</li><li>Information handling</li></ul><p> </p><ul><li>Build a culture of responsible innovation.</li></ul><p> </p><ul><li>Conduct executive awareness sessions and governance workshops.</li></ul><p> </p><ul><li>Develop reporting dashboards and governance KPIs.</li></ul><p><br></p> </div><h2 class="h5">Skills</h2>
<div data-jb-field="skills"><p><b>Required Skills to be successful </b></p><p> </p><p><b>Education</b></p><p> </p><ul><li>Bachelor's Degree in Computer Science, Information Systems, Data Science, Cybersecurity, Law, or related field.</li></ul><p> </p><ul><li>Master's Degree preferred.</li></ul><p> </p><p><b>Experience</b></p><p> </p><ul><li>10+ years of experience in data governance, privacy, risk, information management, or technology governance.</li></ul><p> </p><ul><li>Minimum 5 years leading enterprise governance initiatives.</li></ul><p> </p><ul><li>Experience within insurance, financial services, banking, or regulated industries preferred.</li></ul><p> </p><ul><li>Practical experience governing:</li></ul><p> </p><ul><li>AI/ML platforms</li><li>Generative AI</li><li>Cloud platforms</li><li>Enterprise data environments</li></ul><p><br></p></div>
معلومات إضافية<br><br>رقم الوظيفة 26107264<br><br>فئة الوظيفة: الوقاية من الخسائر والأمن<br><br>الموقع: شارع حمدان بن محمد (الشارع الخامس)، أبوظبي، الإمارات العربية المتحدة، الإمارات العربية المتحدة،عرض على الخريطة<br><br>الجدول: دوام كامل<br><br>موجود عن بُعد؟ لا<br><br>نوع الوظيفة: غير إداري<br><br>مرحبا بكم في العائلة<br><br>نرحب بك كعضو في عائلة ماريوت الدولية المتنوعة. سواء كنت تسافر داخل المدينة نفسها أم إلى أقصى بقاع العالم، نحن ندرك أنه من المهم أن يشعر كل عميل بأنّه مرحب به وبأكبر قدر ممكن من الأمان. طابعك الحامي واهتمامك بالتفاصيل يساهمان بشكل كامل في نجاحك. سيقدَّر عملك بقدر شخصيتك، وستحصل على الدعم في جميع الجهود التي تبذلها.<br><br>التأثير الذي ستحدثه<br><br>عينك اليقظة وحدسك الحامي يتجاوزان المهارات الأساسية لدى الأشخاص. بفضلك، يمكن لعملائنا أن يتنقلوا بكل سلام. تفانيك في الأمن يمنح العملاء نفس الشعور بالأمان الذي يجده في منازلهم.<br><br>المهام التي ستقوم بها<br><br>دوريات عبر جميع أقسام المنشأة ومساعدة العملاء في الوصول إلى غرفهم فحص شاشات المراقبة وإجراء فحوصات يومية للمخاطر المادية الاستجابة للحوادث ومساعدة العملاء والموظفين في حالات الطوارئ تهدئة حالات النزاع ومرافقة أشخاص خارج المنشأة عند اللزوم إجراء التحقيقات وجمع أدلة والقيام بمقابلات مع المعنيين تعبئة تقارير الدَور المناسبة والحفاظ على سرية جميع المستندات المتعلقة بحماية الممتلكات والأشخاص<br><br>المزايا التي تستحقها<br><br>ستحصل على مزايا في مكان العمل وخارجه:<br><br>زملاء بروح الفريق<br>إمكانات التعلم والتطوير<br>إدارة تشجّع<br>برامج الرفاهية<br>خصومات على غرف الفنادق، وبضائع المتجر، والمواد الغذائية والمشروبات<br>برامج التقدير<br><br>المؤهلات التي نبحث عنها<br><br>مهارات اتصال ممتازة<br>قدرة مثبتة على الظهور بموقف مريح في المواقف المجهدة<br>القدرة على العمل كفريق<br>الاهتمام بالتفاصيل<br>قدرة جيدة على الحكم والحفاظ على موقف مهني<br><br>هذا المنصب يتطلب الالتزام بمعايير ضمان الجودة. قد يكون من اللازم الوقوف أو الجلوس أو المشي لفترات طويلة. نقل، رفع، حمل، دفع، سحب ووضع أشياء بوزن يصل إلى 50 رطلاً (23 كجم) دون مساعدة والمساعدة في نقل أشياء أزيد من 75 رطلاً (34 كجم). الدخول والبحث عن معلومات مرتبطة بالعمل باستخدام الحواسيب وأنظمة نقاط البيع. أداء مهام أخرى معقولة، بناءً على طلب المشرفين.<br><br>أنت مرحب بك هنا<br><br>أولويتنا الأساسية هي ترحيبك كما نرحب بعملائنا. نريدك أن تشعر بالراحة وأنت تكون نفسك وأن تعلم أنك مهم بالنسبة لنا. سيكون لدورك تأثير على عملائنا، وبالتالي ستقدَّر وتُبرز.<br><br>المؤهلات الموصى بها<br><br>المستوى التعليمي: شهادة الثانوية العامة أو ما يعادلها<br><br>الخبرة العملية ذات الصلة: لا توجد خبرة عمل ذات صلة<br><br>الخبرة الإشرافية: لا توجد خبرة إشرافية<br><br>رخصة أو شهادة: لا شيء<br><br>في Marriott International، نلتزم بتعزيز المساواة في فرص العمل واستقبال كل شخص بكرامة وتقديم فرص متساوية للجميع. لقد أنشأنا بيئة تُقدَّر وتحتفل بخصوصيات موظفينا. قوتنا الكبرى تكمن في التنوع الثقافي والمهارات والخبرات لدى موظفينا. نحن حريصون على منع أي تمييز مبني على معايير محمية، بما في ذلك الإعاقة ووضع المحارب القديم وأي جانب آخر مغطى بموجب القانون المعمول به.<br><br>في Courtyard، شغفنا هو تلبية احتياجات المسافرين في جميع أنحاء العالم. ومن هذه الرؤية وُلد الفندق الأول المصمم خصيصاً للمسافرين بغرض العمل، وهذا هو السبب في أن تجربة Courtyard اليوم تمنح جميع عملائنا، بغض النظر عن هدف السفر، مفاتيح الازدهار. نحن نبحث عن أشخاص فاعلين، يحفزهم شغف تقديم تجربة خدمة عملاء تتجاوز التوقعات، ويستمتعون بأن يكونوا جزءاً من فريق صغير لكن طموح، ويحبون أكثر من أي شيء تعلم طريقة التحسن المستمر... مع المتعة. <br><br>بانضمامك إلى Courtyard، ستنضم إلى محفظة علامات Marriott International. انضم إلى شركة تمنحك إمكانية بذل أفضل ما لديك، وإيجاد معنى في حياتك المهنية، وأن تكون جزءاً من فريق دولي استثنائي وتصبح أفضل نسخة من نفسك.
The Senior Specialist – Information Security is responsible for supporting the development, implementation, and continuous improvement of the organization’s information security framework. The role ensures the protection of information assets, systems, and data against cybersecurity threats while maintaining compliance with applicable government regulations, security standards, and organizational policies.<br>Key Responsibilities:Develop, implement, and maintain information security policies, procedures, standards, and guidelines. Monitor the organization’s information security posture and identify potential vulnerabilities, threats, and security risks. Conduct information security risk assessments and recommend appropriate mitigation and control measures. Ensure compliance with applicable UAE government cybersecurity requirements, regulatory frameworks, and recognized international standards. Support the implementation and monitoring of security controls across systems, applications, networks, and information assets. Coordinate vulnerability assessments, penetration testing, security audits, and remediation activities. Monitor security incidents and alerts, support incident investigation, and coordinate appropriate response and recovery actions. Develop and maintain the Information Security Incident Response Plan and contribute to business continuity and disaster recovery activities. Conduct security reviews for new systems, technologies, applications, and third-party solutions before implementation. Assess information security risks associated with vendors and third-party service providers. Work closely with IT and relevant departments to ensure security requirements are incorporated into technology projects and operations. Support data protection, access control, identity and access management, and information classification initiatives. Develop information security awareness programs and conduct awareness sessions for employees. Prepare information security reports, dashboards, risk registers, and performance indicators for management. Monitor emerging cybersecurity threats, technologies, and regulatory developments and recommend improvements to the organization’s security practices. Support internal and external audits and ensure timely closure of information security findings.<br>Qualifications & Experience:Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field. Master’s degree in a relevant field is an advantage. Minimum 6 years of relevant experience in information security, cybersecurity, IT security, or a related field. Experience within government, education, academic, or other regulated sectors is preferred.
Responsibilities:Provide L3 engineering and deep troubleshooting support for complex security infrastructure issues, incidents, and escalations. Design, configure, harden, review, and optimize enterprise security solutions and security policies. Support security architecture reviews, solution design, technology upgrades, migrations, and implementation activities. Perform root-cause analysis and resolution of complex security and connectivity issues across multiple security platforms. Provide technical support for Disaster Recovery (DR) exercises, resilience testing, failover, and recovery activities. Review existing security configurations and policies and recommend improvements based on security best practices and operational requirements. Work closely with infrastructure, network, application, SOC, and other technical teams to resolve security-related issues. Manage incidents, service requests, problems, and changes in accordance with established ITSM processes.<br>Key Technology Areas:Strong hands-on experience across several of the following technologies is required:Firewalls: Checkpoint and/or Palo Alto Secure Web Gateway / Proxy: Proxy solutions and Zscaler Web Application Firewall: F5 WAFNetwork Security: IPS/IDS and DDoS protection Security Network Design and Architecture Endpoint Security: Trellix / McAfee, EDR and DLPIdentity & Access Security: MFA, VPN and token-based authentication solutions ITSM / Incident, Problem and Change Management
An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.<br>Key Responsibilities Web Application & API Security Testing Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services. Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security. Assess applications against recognized security frameworks and industry best practices. File & Document Security Assessment Evaluate security controls governing file uploads, downloads, storage, and processing workflows. Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure. Access Control & Authorization Review Validate role-based and attribute-based access controls across multiple user types and permission levels. Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access. Assess segregation and isolation controls within shared application environments. Identity & Authentication Security Review authentication and authorization mechanisms, including OAuth 2.0, Open ID Connect (OIDC), SAML, and JWT implementations. Test token validation, session handling, replay protection, and identity federation controls. Identify weaknesses in identity lifecycle management and access governance. Business Logic Security Analysis Assess critical user journeys and application workflows for logic flaws and abuse cases. Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls. Evaluate protections against fraud, abuse, and unauthorized transaction manipulation. Security Advisory & Remediation Support Produce clear, risk-based security assessment reports with prioritized remediation recommendations. Collaborate with stakeholders to validate fixes and perform security re-testing. Support secure development practices throughout the software delivery lifecycle.<br>Required Skills & Experience Security Assessment Expertise Minimum 5 years of hands-on experience conducting web application and API penetration testing. Strong understanding of modern attack techniques and security testing methodologies. Security Frameworks & Methodologies Expert knowledge of:OWASP Top 10OWASP API Security Top 10OWASP Web Security Testing Guide (WSTG) Threat modeling and risk-based assessment approaches Security Tools Advanced proficiency with:Burp Suite Professional Postman Web application and API testing tools Identity & Access Management Security Proven experience identifying and exploiting weaknesses in:OAuth 2.0Open ID Connect (OIDC) JWTSAML 2.0Secure File Handling Strong understanding of secure file processing, archive parsing, storage isolation, and content validation. Experience assessing file management controls and secure object storage implementations.<br>Preferred Qualifications Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions. Familiarity with security automation and vulnerability assessment tools such as:Nuclei Semgrep OWASP ZAPKnowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP). Understanding of secure architecture principles for internet-facing applications and distributed environments.<br>Preferred Certifications Offensive Security OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) Port Swigger BSCP (Burp Suite Certified Practitioner) Other relevant application security, penetration testing, or cloud security certifications are advantageous. Senior Web App Security Engineer in Abu Dhabi, United Arab Emirates
An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.<br>Key Responsibilities Web Application & API Security Testing Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services. Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security. Assess applications against recognized security frameworks and industry best practices. File & Document Security Assessment Evaluate security controls governing file uploads, downloads, storage, and processing workflows. Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure. Access Control & Authorization Review Validate role-based and attribute-based access controls across multiple user types and permission levels. Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access. Assess segregation and isolation controls within shared application environments. Identity & Authentication Security Review authentication and authorization mechanisms, including OAuth 2.0, Open ID Connect (OIDC), SAML, and JWT implementations. Test token validation, session handling, replay protection, and identity federation controls. Identify weaknesses in identity lifecycle management and access governance. Business Logic Security Analysis Assess critical user journeys and application workflows for logic flaws and abuse cases. Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls. Evaluate protections against fraud, abuse, and unauthorized transaction manipulation. Security Advisory & Remediation Support Produce clear, risk-based security assessment reports with prioritized remediation recommendations. Collaborate with stakeholders to validate fixes and perform security re-testing. Support secure development practices throughout the software delivery lifecycle.<br>Required Skills & Experience Security Assessment Expertise Minimum 5 years of hands-on experience conducting web application and API penetration testing. Strong understanding of modern attack techniques and security testing methodologies. Security Frameworks & Methodologies Expert knowledge of:OWASP Top 10OWASP API Security Top 10OWASP Web Security Testing Guide (WSTG) Threat modeling and risk-based assessment approaches Security Tools Advanced proficiency with:Burp Suite Professional Postman Web application and API testing tools Identity & Access Management Security Proven experience identifying and exploiting weaknesses in:OAuth 2.0Open ID Connect (OIDC) JWTSAML 2.0Secure File Handling Strong understanding of secure file processing, archive parsing, storage isolation, and content validation. Experience assessing file management controls and secure object storage implementations.<br>Preferred Qualifications Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions. Familiarity with security automation and vulnerability assessment tools such as:Nuclei Semgrep OWASP ZAPKnowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP). Understanding of secure architecture principles for internet-facing applications and distributed environments.<br>Preferred Certifications Offensive Security OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) Port Swigger BSCP (Burp Suite Certified Practitioner) Other relevant application security, penetration testing, or cloud security certifications are advantageous. Senior Web App Security Engineer in Abu Dhabi, United Arab Emirates
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<br>Company Description<br><br><p>Established in 2000 in Turkey, Rixos pioneers the ‘ALL Inclusive, ALL Exclusive’ concept, inviting guests to discover a world of possibilities, with luxurious stays, inclusive of culinary delights from around the globe, live entertainment, daily sports, and fitness activities, sensorial spa and wellness journeys and fun-filled kids and teens activities. Each Rixos property presents a unique experience inspired by local culture, global influences, and our Turkish heritage, all within a setting of unparalleled luxury.</p><br><br>Job Description<br><br><ul><li><strong>Main Duties and Responsibilities</strong></li><li>Develop, implement, and maintain safety policies and procedures in compliance with local, national, and international regulations.</li><li>Conduct regular safety inspections, risk assessments, and audits to identify potential hazards and ensure a safe working environment.</li><li>Lead safety training sessions for employees, promoting awareness and adherence to safety practices and protocols.</li><li>Investigate accidents, incidents, and near-misses, preparing detailed reports with recommendations for corrective actions.</li><li>Collaborate with management to develop and execute safety improvement plans and initiatives.</li><li>Maintain accurate records of safety-related incidents, training, inspections, and corrective actions.</li><li>Ensure the availability and proper use of personal protective equipment (PPE) and other safety gear.</li><li>Act as the point of contact for all safety-related matters, providing guidance and support to employees at all levels, and offering honest feedback at all times.</li><li>Promote and develop teamwork.</li><li>Praise team members in public and discuss individual problems privately.</li><li>Ensure high standards of cleanliness in the pool.</li><li>Ensure consistency within pool surroundings with regard to general health and safety of guests and staff through regular cleaning and maintenance of equipment and facilities.</li><li>Utilize all communication tools available to disseminate information in a timely manner.</li><li>Conduct daily follow-ups to ensure standards of quality and service are maintained.</li><li>Support and follow through with the implementation of new ideas.</li><li>Utilize every interaction with team members as an opportunity to coach and improve performance.</li><li>Challenge and review existing procedures and practices to drive continuous improvement.</li><li>Ensure guests are always provided with an enjoyable, well-informed, and memorable experience.</li><li>Provide courteous, efficient, and professional service at all times.</li><li>Seek excellence and support continuous daily improvement.</li><li>Build and maintain excellent relationships with the team and all other hotel colleagues.</li><li>Ensure punctuality and maintain excellent grooming and hygiene standards.</li><li>Attend daily operational briefings with direct reports and supervisors.</li><li>Thoroughly familiarize oneself with the hotel’s emergency procedures and remain in a state of preparedness for any emergency situations.</li><li>Be familiar with all related company documentation, especially relevant Quality Standards for the field of responsibility.</li><li>Perform other duties as assigned by management.</li></ul><br>Qualifications<br><br><ul><li>Minimum of 2 years’ experience in a similar Safety Officer or HSE role, preferably within the luxury hospitality industry.</li><li>Bachelor’s degree in occupational health & safety or a related field (preferred).</li><li>Strong knowledge of health, safety, and risk management regulations, standards, and best practices.</li><li>Experience in conducting safety inspections, risk assessments, audits, and incident investigations.</li><li>Ability to prepare clear safety reports, corrective action plans, and compliance documentation.</li><li>Knowledge of PPE requirements, emergency response procedures, and safety training delivery.</li><li>Good communication skills in English, with the ability to train, guide, and support employees at all levels.</li><li>Strong attention to detail, problem-solving skills, and a proactive approach to workplace safety.</li><li>Ability to work independently and collaboratively in a dynamic hotel environment.</li></ul><br>Additional Information<br><br><p><strong>Our commitment to Diversity & Inclusion:</strong><br>We are an inclusive company and our ambition is to attract, recruit and promote diverse talent.</p><br> </div>
Job Overview:<br>The HR Officer – Operations & Employee Lifecycle Administration serves as the primary point of contact for employees, managers, and external service providers regarding employee benefits, health insurance administration, and offboarding processes. The role is responsible for ensuring the accurate, timely, and compliant delivery of employee benefits throughout the employee lifecycle, while managing end-to-end separation processes and maintaining a positive employee experience. The position will oversee the administration of medical insurance programs, including employee enrollment, additions, deletions, claims coordination, policy compliance, and vendor management. In addition, the role will manage employee exits, ensuring smooth and timely completion of clearance procedures, final settlements, exit interviews, asset recovery, documentation, and statutory compliance. A strong understanding of company policies, compensation and benefits practices, labor regulations, and HR operational procedures is essential. The role requires proactive stakeholder management, high attention to detail, excellent customer service, and the ability to ensure all employee benefit and offboarding activities are delivered within established service levels and organizational standards across all ABHCG entities.<br>Key Responsibilities:<br>Health Insurance & Benefits Administration Manage end-to-end medical insurance operations, including employee and dependent enrollment, amendments, deletions, and policy updates. Liaise with insurance providers, brokers, and third-party administrators (TPAs) to ensure seamless service delivery. Support employees with insurance-related inquiries, claims processing, coverage clarification, and benefit utilization. Ensure accurate and timely maintenance of employee benefits records within HR systems. Monitor insurance costs, policy utilization, renewals, and reconciliation activities. Communicate benefit programs, policy enhancements, and eligibility requirements to employees. Ensure compliance with company policies and insurance contractual obligations.<br>Employee Offboarding Administration Manage the complete employee separation process through digital off boarding process, including resignation, termination, retirement, and end-of-contract cases. Coordinate employee clearance with relevant stakeholders, including Finance, IT, Administration, Security, and Business functions. Process and track final settlement documentation within defined timelines. Conduct and document exit interviews and provide trend analysis reports to HR management. Ensure recovery of company assets and timely deactivation of employee access. Issue employment certificates, experience letters, and separation documentation. Maintain accurate offboarding records and ensure compliance with labor laws and company policies.<br>HR Operations & Service Delivery Maintain accurate employee records and HR databases. Respond to employee queries related to benefits, insurance, and separation processes within agreed service levels. Prepare periodic reports, dashboards, and analytics related to benefits administration and employee separations. Support internal and external audits by providing accurate documentation and records. Identify opportunities for process improvement and automation within HR operations.<br>Qualification & Experience:<br>Bachelor’s degree in human resources, Business Administration, Management, or a related discipline. Minimum 5 years of progressive experience in Health Insurance and Employee Benefits Administration within a large, complex, and matrixed organization. Demonstrated experience managing end-to-end health insurance operations, including employee enrollment, policy administration, vendor coordination, claims support, and benefits compliance. Proficient in HRMS/HRIS systems and employee data management. Strong working knowledge of Microsoft Office (Word, Excel, Power Point), Power BI, and Power Automate. Good understanding of UAE labor laws, HR policies, and compliance requirements. Strong organizational, planning, and prioritization skills with the ability to manage multiple tasks and deadlines. Ability to handle confidential information with discretion and exercise sound judgment in decision-making. Effective communication, stakeholder management, and problem-solving skills.
An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.<br><br>Key Responsibilities<br><br>Web Application & API Security Testing<br><br>Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services. Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security. Assess applications against recognized security frameworks and industry best practices. <br><br>File & Document Security Assessment<br><br>Evaluate security controls governing file uploads, downloads, storage, and processing workflows. Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure. <br><br>Access Control & Authorization Review<br><br>Validate role-based and attribute-based access controls across multiple user types and permission levels. Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access. Assess segregation and isolation controls within shared application environments. <br><br>Identity & Authentication Security<br><br>Review authentication and authorization mechanisms, including OAuth 2.0, Open ID Connect (OIDC), SAML, and JWT implementations. Test token validation, session handling, replay protection, and identity federation controls. Identify weaknesses in identity lifecycle management and access governance. <br><br>Business Logic Security Analysis<br><br>Assess critical user journeys and application workflows for logic flaws and abuse cases. Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls. Evaluate protections against fraud, abuse, and unauthorized transaction manipulation. <br><br>Security Advisory & Remediation Support<br><br>Produce clear, risk-based security assessment reports with prioritized remediation recommendations. Collaborate with stakeholders to validate fixes and perform security re-testing. Support secure development practices throughout the software delivery lifecycle. <br><br>Required Skills & Experience<br><br>Security Assessment Expertise<br><br>Minimum 5 years of hands-on experience conducting web application and API penetration testing. Strong understanding of modern attack techniques and security testing methodologies. <br><br>Security Frameworks & Methodologies <br><br>Expert knowledge of:OWASP Top 10 OWASP API Security Top 10 OWASP Web Security Testing Guide (WSTG) Threat modeling and risk-based assessment approaches <br>Security Tools <br><br>Advanced proficiency with:Burp Suite Professional Postman Web application and API testing tools <br>Identity & Access Management Security <br><br>Proven experience identifying and exploiting weaknesses in:OAuth 2.0 Open ID Connect (OIDC) JWT SAML 2.0 <br>Secure File Handling<br><br>Strong understanding of secure file processing, archive parsing, storage isolation, and content validation. Experience assessing file management controls and secure object storage implementations. <br><br>Preferred Qualifications <br><br>Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions. Familiarity with security automation and vulnerability assessment tools such as:Nuclei Semgrep OWASP ZAP Knowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP). Understanding of secure architecture principles for internet-facing applications and distributed environments. <br><br>Preferred Certifications <br><br>Offensive Security OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) Port Swigger BSCP (Burp Suite Certified Practitioner) Other relevant application security, penetration testing, or cloud security certifications are advantageous. <br><br>Senior Web App Security Engineer in Abu Dhabi, United Arab Emirates
<h2 class="h5">وصف الوظيفة</h2>
<div class="t-break" data-jb-field="description">
<p><strong> المسؤوليات والنتائج الرئيسية</strong># إنشاء قاعدة بيانات تتبع لجميع ملفات المكتب، الإيصالات، والفواتير، والمدفوعات المستلمة.# الحفاظ على ملفات موظفي القسم في القسم بالتنسيق مع مدير الموارد البشرية# تنسيق أنشطة المدراء والتأكد من أن الأعمال الكتابية وصورة المكتب أنيقة أمام الزوار.# أداء مسؤوليات أخرى مرتبطة بالمنصب حسب الاقتضاء# المسؤول عن الطلب المبكر والطباعة لجميع لوازم المكاتب المطبوعة مسبقاً من ورقة الرأس، طوابع البريد، بطاقات الأعمال، الأظرف المعاد استخدامها، وما إلى ذلك.# دعم الأعمال الكتابية وفقاً لطلب المدير/عبء عمل القسم.# تنسيق أي معدات مكتبية أو أعمال صيانة أخرى مع موردي الصيانة المعنيين# توليد تقارير أو سجلات موظفين مختلفة حسبما يراه ضرورياً# مساعدة المدير في جميع صلاحياته الإدارية والقيام بالواجبات الإدارية كما هو مكلف بما يتفق مع معايير وإجراءات وحدة الأعمال الاستراتيجية (SBU)# مسؤول عن توفير معدات المكاتب المطلوبة وصيانة اللوازم المكتبية والمساعدة في التوثيق والمراسلة مع الأقسام الأخرى في SBU فيما يخص قضايا الإدارة.# مسؤول عن تطبيق سياسات الإجازة السنوية والمرضية وإعداد إشعارات عودتهم وإبلاغ قسم الموارد البشرية بالإجراء اللازم.# ضمان التشغيل اليومي الفعال لمتطلبات مدير المكتب الإداري.# الإبلاغ عن أي تغييرات في قضايا شؤون الموظفين وتدوين النصوص عند الحاجة، وحضور اجتماعات الفريق الداخلية حسب الحاجة.# إعداد والتأكد من استكمال جميع الإجراءات عند إنهاء عمل موظف أو استقالته مثل إجراءات التخليص والإلغاء.# مسؤول عن إعداد الشهادات الخبرة اللازمة وغيرها من الوثائق حسب ما يراه المديرون والموظفون ضرورياً.</p><br> <p><strong>التعليم</strong># بكالوريوس/ دبلوم عالي في إدارة الأعمال أو العلاقات العامة من جامعة معترف بها.</p><br> </div>
We are looking for an experienced Network Security Lead to design, implement, and govern enterprise network security solutions across hybrid environments. The role requires strong technical expertise in firewall architecture, VPN technologies, network segmentation, and security operations. The successful candidate will lead network security initiatives, ensure secure network connectivity, and provide technical guidance for enterprise security platforms.<br>Key Responsibilities Lead network security architecture, design, implementation, and operational governance activities. Manage and maintain enterprise firewall platforms including Fortinet, Palo Alto Networks, and Cisco ASA. Design and support secure VPN solutions including SSL VPN and IPSec VPN environments. Define and enforce firewall security standards, policies, and rule management processes. Perform firewall rule reviews, optimisation, segmentation improvements, and security configuration assessments. Support security incident investigation, troubleshooting, root cause analysis, and remediation activities. Manage firewall upgrades, migrations, lifecycle activities, and vendor coordination. Provide technical leadership and guidance to network and security operations teams. Ensure network security controls align with security policies, compliance requirements, and industry best practices.<br>Required Skills & Experience10–12 years of experience in enterprise network security. Strong hands-on experience with firewall technologies including Fortinet Forti Gate, Forti Manager, Forti Analyzer, Palo Alto Networks PAN-OS, Panorama, and Cisco ASA. Strong understanding of firewall policies, NAT, routing, VPN technologies, and network segmentation. Experience designing and managing SSL VPN and IPSec VPN solutions. Experience with high availability (HA), clustering, and disaster recovery configurations. Strong knowledge of IDS/IPS, URL filtering, malware protection, and network security monitoring. Experience handling complex security incidents and technical escalations. Relevant vendor certifications such as Fortinet certifications, PCNSA/PCNSE, or CCIE Security.<br>Preferred Skills Experience with cloud network security solutions across Azure, AWS, or GCP. Knowledge of automation tools such as Python or Ansible. Familiarity with security frameworks including ISO 27001, NIST, SOC 2, and PCI-DSS. Strong leadership, communication, and stakeholder management skills.
Minimum 10-15 years overall experience in IT starting with the hands-on engineering positions5 years’ experience doing practical design or architecture within the specialization (solutions, infrastructure, network, security, etc.) Act as a technical focal point for complex network and security design/solution Act as a technical SME during the product/solution evalution and implementation for network & security tools Must have experience around Enterprise Security Architecture Security, Security Strategy and Compliance Consulting Experience creating and audit of security best practices and implementation of security principles across the organization , to meet business goals along with customer and regulatory requirements,Understanding of compliance regulatory requirements like ISO,PCI DSS, NESA etc.,Must have experience around design of security controls and product best fit analysis to ensure end to end security covering different areas of security architecture : Layered Security Zoning Integration aspects API Security Endpoint Security Data Security Compliance and regulations Threat Intelligence Threat Exposure & Incident Management aspects Must Possess strong presentation , written and verbal communication skills Industry Security Certifications like CCIE,CISSP, CISA, CISM, CSRIC, TOGAF,SABSA etc., are preferred Good Understanding & Must have experience in implementing Cloud Security Controls Good Understanding of Cloud Platforms like Azure, Oracle, Google,AWS etc.,Good Understanding of Dockers, Containers and Kubernetes Good Understanding of SDN technologies like ACI. Good Understanding of REST, SOAP Protocols, Web services etc.,Good Understanding of Symmetric and Asymmetric Cryptography algorithms. Hands on Experience on Multi-vendor firewalls and other security technologies ( Firewalls, Web Proxy, Email Gate, Endpoint Security etc..) Knowledge and experience in requirements traceability throughout the design phase, including functional and non-functional requirements Ability and experience in translating functional and non-functional requirements into solution/feature/component design and service architecture Understands how the business structures and functions in FAB relate to the nature of the service Can create a high-level and low-level design (functional and non-functional) of a single or a small collection of components or a small end-to-end service Conducts / participates in code reviews, identifies bug root causes, and finds a workable solution Participates in Communities Proactively addresses issues discovered in the software components, infrastructure and scripts in the various environments
About The Role<br><br>What you will be doing:<br><br>Work directly with product teams in building a security by design and by default mindset by defining a structured approach to security in line with the Application Security Program mandates<br><br>Develop design patterns, and code guidelines that meet business security and system requirements in line with the risk assessments, policies, and procedures<br><br>Be a thought leader and help the wider organization drive security solutions implementation in-alignment with other stakeholders<br><br>Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary<br><br>Lead Dev Sec Ops implementation through technology, process and human upskilling including SAST, DAST, SCA, and penetration test results in collaboration with the developers.<br><br>Review current software security control measures and implement security enhancements for multiple cloud-based products<br><br>Participate in vulnerability investigations and become an extended arm to the Security Operation team<br><br>What You Have<br><br>Master’s degree in computer science or cyber security, a related field or equivalent demonstrated experience and knowledge<br><br>Minimum 7+ years of experience in engineering or software development or related fields.<br><br>Minimum 5 years hands-on product security role either as an architect, penetration tester or security engineer in cloud and application<br><br>Strong working knowledge of<br><br>software technologies such as C/C++, Java, . Net, python, etc.<br><br>Experience analyzing, using SAST, DAST, SCA and penetration tests.<br><br>Azure cloud<br><br>IOT and Operating system hardening using DISA STIGS and CIS benchmark<br><br>Experience ins secure software development or at least knowledge in secure coding practices and application security test report interpretation for various coding languages and multiple cloud services<br><br>Strong knowledge of secure software development lifecycle and practices including Agile methodologies for software development<br><br>Understanding of security by design principles and architecture level security concepts<br><br>Sound understanding and experience in implementing security public key Infrastructure (PKI)),<br><br>Experience implementing OWASP Top10 application security guidelines in cloud-based web applications<br><br>Experienced in generating, defining, and reviewing penetration test results through knowledge of standard methodologies and tools including environmental configuration definition, security analysis, threat modeling, and system security audits<br><br>Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities<br><br>Exposure to international privacy requirements & cross-industry trends<br><br>Requirements<br><br>We are looking for a Principal Product Security Engineer whom his primary responsibility will be to for design, build, test and implementing secure SDLC across the product development lifecycle.<br><br>This role requires deep knowledge of building product security program from scratch which includes writing SOP, SWI, designing training for developers and gaining the trust of the product teams through hands-on engagement. A deep understanding of web-based secure code principles, and IOT security is a pre-requisite. Candidates should have experience in FDA and EU MDR submission process.<br><br>About The Company<br><br>At AMD, we are dedicated to safeguarding our client against cyber threats. We recognize the distinct requirements and vulnerabilities of each enterprise, which is why we offer tailor-made solutions to shield your data and assets effectively.<br><br>Our collaborative approach involves working closely with clients to devise a holistic cybersecurity strategy that harmonizes with their specific business objectives.
About The Role<br><br>Development experience in C#, C++ or Java preferred but not required<br><br>Embedded system, firmware and IoT security preferred but not required<br><br>Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE) or Offensive Security Web Expert (OSWE) certification preferred but not required.<br><br>Cloud Security Experience Preferred<br><br>Travel up to 10% domestic and international<br><br>Requirements<br><br>The Product Security Engineer is responsible for creating and implementing cutting-edge security solutions and infrastructures that will ensure our client products are secure and resilient.<br><br>This role provides the opportunity to work cross-functionally with a variety of stakeholders including product development teams and contribute to product security deliverables and activities<br><br>Support developers of our business units in their SDLC and provide guidance regarding mitigations to emerging threats and remediation planning.<br><br>Participate in building security champions within product and R&D teams and to help mature their secure development lifecycle practices.<br><br>Collaborate effectively with cross functional teams including, R&D Quality, Manufacturing and Regulatory to achieve security risk reduction.<br><br>Develop security training and deliver to internal development teams and other stakeholders.<br><br>Evaluation of new security tools and technologies and build internal tools as needed.<br><br>Perform security tools integration such as Static Code Analysis (SAST), Software Composition Analysis (SCA) and Dynamic Application Security Testing (DAST) tools.<br><br>Other duties and responsibilities as required to support the changing security needs of the organization.<br><br>Have knowledge of industry standards and frameworks such as OWASP, NIST, SANS, MITRE ATT&CK, etc.<br><br>Strong interpersonal and communication skills<br><br>Strong technical writing and presentation skills<br><br>About The Company<br><br>At AMD, we are dedicated to safeguarding our client against cyber threats. We recognize the distinct requirements and vulnerabilities of each enterprise, which is why we offer tailor-made solutions to shield your data and assets effectively.<br><br>Our collaborative approach involves working closely with clients to devise a holistic cybersecurity strategy that harmonizes with their specific business objectives.
The Senior Manager of Governance is responsible for developing the information security and cybersecurity strategy and plan. This role aims to protect DET’s Information assets from risks, threats, and attacks by establishing robust security policies and aligning them with local and federal mandates, such as those from the Dubai Cyber Security Strategy and the Dubai Electronic Security Center.<br>The responsibilities include managing policy implementation, managing risk assessments, delivering training programs, and ensuring compliance across all technology platforms. Conducting investigations on information security policy breaches and recommending solutions. Coordinating with regulatory bodies and stakeholders to maintain and report on DET’s security posture, ensuring a secure operational environment.<br>Core Functional Responsibilities Develop the DET Group’s information security and cybersecurity strategy and plan in order to mitigate risks, attacks, and threats on the data assets of the DET Group. Design and manage new programs, projects, initiatives, and enhancement and implementation roadmap to strengthen the DET security. Manage the Information Security governance process including Policy and Standards across the DET. Ensure the alignment of the DET Group’s information security and cybersecurity strategy with local and federal strategies, such as the Dubai Cyber Security Strategy, and other requirements set by DESC. Additionally, maintain compliance with the ISO 27001:2022 standard to uphold international best practices in information security management alongside the ISR. Develop and implement of information security and cybersecurity policies, procedures, and standards for the DET Group, ensuring alignment with the ISR as well as leading practices and trends. Manage the provision of awareness and training sessions and program to all employees, leaders, strategic partners, etc. on information security and cyber security policies, to mitigate potential policy breaches. Conduct thorough and ongoing audits to ensure all employees, leaders, and strategic partners strictly adhere to DET's information security and cybersecurity policies. This includes verifying system access compliance, facilitating cybersecurity training, assessing risks, and maintaining detailed audit trails for continuous improvement and accountability. Provide support as needed, to manage any exceptions or deviations from information security and cybersecurity policies. Manage the implementation of information and cybersecurity risk assessments on DET Group, in order to gain intelligence on information security and cyber threats and risks DET is vulnerable to, based on its operations and its IT infrastructure components including applications, cloud, cryptography, and infrastructure, and accordingly recommend risk mitigation measures. Manage investigations on information security policy breaches conducted internally or through external parties, ensure policy breaches are being accurately reported, and accordingly identify solutions to policy breaches. Develop reports pertaining to information security and cybersecurity risk assessments results, as well as incidents related to information security. Ensure reports are being circulated to relevant stakeholders, and manage the delivery of presentations to the Director General as well as the Information Security Committee, as needed. Provide guidance and advice to end users, when needed, regarding potential threats and key considerations for the safe usage of systems and exchange of information. Provide guidance and subject matter expertise when it comes to the enhancement of information security controls, in coordination with the Technology team as well as IT vendors.
About UsAI71 is an applied research team dedicated to creating helpful and responsible AI agents for knowledge workers. Working closely with our industry partners, our cross-functional teams of AI experts build products grounded in the cutting edge research of our colleagues from the Technology Innovation Institute (TII). We are seeking a highly experienced and strategic Security Architect to define and lead the security architecture of our AI and data platform. In this role, you will be responsible for designing secure-by-design systems across AI workloads, data pipelines, and cloud-native infrastructure, ensuring the confidentiality, integrity, and availability of our platform at scale. You will collaborate closely with engineering, platform, and AI teams to embed security into every layer of system design, development, and deployment, while establishing standards and best practices aligned with enterprise and high-security environments.<br><br>Key Responsibilities Security Architecture and Design<br><br> Define and evolve the end-to-end security architecture for AI systems, data platforms, and cloud-native infrastructure. Establish and enforce Zero Trust principles, including identity-first security, m TLS, and fine-grained access control (RBAC/ABAC). Design secure patterns for distributed systems, event-driven architectures, and multi-tenant environments. Platform and Infrastructure Security Define security standards for Kubernetes-based platforms, including workload isolation, network policies, and runtime protection. Establish container and software supply chain security practices (e.g., image scanning, SBOM, signing, and provenance). Design secure deployment architectures for both cloud and restricted/air-gapped environments. AI and Data Security Define and implement security controls for LLM-based applications, RAG pipelines, and data platforms. Establish safeguards against AI-specific threats such as data poisoning, model extraction, and data leakage. Dev Sec Ops and Governance Embed security into Git Ops and CI/CD workflows, including policy-as-code and automated enforcement. Define and maintain secure SDLC practices aligned with ISO 27001 and internal governance frameworks. Lead threat modeling, architecture reviews, and security validations. Observability and Threat Detection Define requirements for security observability, including audit logging and anomaly detection. Ensure integration of security signals into observability platforms (e.g., Open Telemetry). Leadership and Collaboration Act as a security advisor to engineering and AI teams. Review system designs and enforce security standards. Mentor engineers and promote a strong culture of security awareness. Qualifications<br><br>Required Skills and Experience<br><br> Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field. 7+ years of experience in security engineering, architecture, or related roles. Experience designing security for distributed systems and cloud-native platforms. Strong understanding of Zero Trust, IAM, cryptography, and secure communication. Experience with Dev Sec Ops practices and secure CI/CD pipelines. Preferred Skills Experience securing AI/ML systems or data platforms. Familiarity with streaming technologies (e.g., Kafka, NATS). Experience in regulated or high-security environments. Certifications such as CISSP or CSSLP. Proficiency in Python or Bash for automation. Why Join Us? Work on cutting-edge AI technologies with a focus on security and ethics. Shape the security architecture of a next-generation AI platform. Collaborate with a diverse and talented team. Competitive salary, equity options, and benefits. Opportunities for growth and leadership.