Cyber Technical Lead
Role Overview
We are seeking an experienced
Cyber Technical Lead to lead a strategic cybersecurity transformation initiative within a highly regulated banking environment.
This role will be responsible for operating and governing a multi-disciplinary cyber security squad delivering
Application Security, AI Governance, Continuous Security Validation, and Compliance Assurance services. The successful candidate will act as the primary First Line of Defense (1LoD) technology leader, ensuring security controls are embedded across the software delivery lifecycle while maintaining alignment with regulatory requirements, enterprise security policies, and operational risk frameworks.
The ideal candidate will have extensive expertise in
DevSecOps, Cloud Security, AI Security, Cyber Governance, Secure Software Delivery, and Banking Regulatory Compliance, with a proven record of leading cross-functional security teams within large-scale regulated organizations.
Key Responsibilities
- Lead and manage a cyber security squad across four strategic workstreams:
- Application Security (AppSec)
- AI Governance
- Continuous Security Validation
- Compliance & Audit Trail Management
- Ensure delivery aligns with approved security policies, regulatory requirements, and agreed service level agreements (SLAs).
- Own and govern the enterprise security tooling ecosystem, driving optimization, integration, and vendor consolidation strategies.
- Define and oversee integration architecture across security platforms and engineering toolchains.
- Establish and manage evidence management processes supporting audit, attestation, and regulatory reporting requirements.
- Act as the primary 1LoD counterpart to Risk, Compliance, Internal Audit, and AI Centre of Excellence teams.
- Lead and facilitate Security Champions programs across engineering teams.
- Drive DevSecOps adoption and secure-by-design principles across software delivery environments.
- Present monthly cybersecurity governance metrics, risk posture assessments, and executive reporting dashboards.
- Govern vulnerability management, remediation tracking, and security posture improvement initiatives.
- Collaborate with cloud, infrastructure, application, and platform teams to enhance cyber resilience.
- Ensure readiness for internal reviews, audits, and regulatory inspections.
- Support implementation of AI governance, AI risk management, and emerging technology security controls.
- Drive continuous improvement initiatives across cyber operations, automation, and security engineering practices.
Required Skills & Qualifications - 12+ years of experience in Cybersecurity Engineering, Security Architecture, DevSecOps, or Cloud Security leadership roles.
- Proven experience leading large-scale security engineering and governance initiatives within banking or highly regulated industries.
- Strong expertise in:
- DevSecOps
- Cloud Security
- AI Security
- Application Security
- Security Governance
- Risk & Compliance
- Demonstrated experience operating within a Three Lines of Defense (3LoD) model.
- Expertise in designing and implementing security controls across Azure and AWS environments.
- Hands-on experience managing enterprise security tooling and integrated security platforms.
- Strong knowledge of secure software development lifecycle (SSDLC) practices.
- Experience implementing AI governance and AI risk management frameworks.
- Familiarity with regulatory and compliance requirements within financial services environments.
- Excellent stakeholder management and executive communication skills.
- Proven experience leading multidisciplinary cybersecurity teams and security transformation programs.
Certifications (Mandatory & Preferred)
Mandatory
Preferred
- CCSP
- AWS Certified Security – Specialty
- Azure Security Engineer Associate
- CISM
- ISO/IEC 42001 Lead Implementer
- Certified DevSecOps Professional (CDP) or equivalent
Highly Desirable
Preferred Skills & Experience
- Banking and financial services industry experience.
- Exposure to AI/ML governance and security frameworks.
- Experience implementing cloud-native security architectures.
- Familiarity with security metrics, executive dashboards, and governance reporting.
- Experience leading regulatory remediation and cyber transformation initiatives.
- Deep understanding of vulnerability management and compliance automation.
- Proven track record of driving security culture and engineering enablement programs.
Halian Group
With over 28 years of experience, we have come to understand that innovation is the only way to provide agile, practical solutions that transform businesses and careers. Our resourcing and smart services help you to realise tomorrow's potential. Discover the amazing things possible when you bring the right people and the right technologies together.
At Halian, we recognise that diversity, equity, and inclusion (DEI) are essential to building high-performing teams for our clients. We are committed to connecting organisations with top talent from all backgrounds, ensuring that every individual feels valued, respected, and empowered to contribute their unique perspectives.
We encourage applications from all qualified candidates, regardless of race, gender, disability, or any other characteristic that makes them unique.
Cyber Technical Lead in Abu Dhabi, United Arab Emirates
قائد تقني للأمن السيبراني
نظرة عامة على الدور الوظيفي
نحن نبحث عن
قائد تقني للأمن السيبراني ذي خبرة لقيادة مبادرة استراتيجية للتحول في مجال الأمن السيبراني ضمن بيئة مصرفية يخضع عملها لتنظيم صارم.
سيكون هذا الدور مسؤولاً عن تشغيل وإدارة فريق أمن سيبراني متعدد التخصصات يقدم خدمات
أمن التطبيقات، وحوكمة الذكاء الاصطناعي، والتحقق المستمر من الأمن، وضمان الامتثال. وسيعمل المرشح الناجح كقائد تقني رئيسي لخط الدفاع الأول (1LoD)، مما يضمن دمج ضوابط الأمن عبر دورة حياة تسليم البرمجيات مع الحفاظ على التوافق مع المتطلبات التنظيمية، وسياسات الأمن الخاصة بالمؤسسة، وأطر المخاطر التشغيلية.
وسيمتلك المرشح المثالي خبرة واسعة في
DevSecOps، وأمن السحابة، وأمن الذكاء الاصطناعي، والحوكمة السيبرانية، والتسليم الآمن للبرمجيات، والامتثال التنظيمي المصرفي، مع سجل مثبت في قيادة فرق أمنية متعددة الوظائف داخل مؤسسات كبرى تخضع للتنظيم.
المسؤوليات الرئيسية
- قيادة وإدارة فريق للأمن السيبراني عبر أربعة مسارات عمل استراتيجية:
- أمن التطبيقات (AppSec)
- حوكمة الذكاء الاصطناعي
- التحقق المستمر من الأمن
- الامتثال وإدارة مسار التدقيق
- ضمان توافق التسليم مع سياسات الأمن المعتمدة، والمتطلبات التنظيمية، واتفاقيات مستوى الخدمة (SLAs) المتفق عليها.
- امتلاك وإدارة منظومة أدوات الأمن للمؤسسة، وقيادة استراتيجيات التحسين والدمج وتوحيد الموردين.
- تحديد والإشراف على بنية التكامل عبر منصات الأمن وسلاسل أدوات الهندسة.
- إنشاء وإدارة عمليات إدارة الأدلة التي تدعم متطلبات التدقيق والإقرار والتقارير التنظيمية.
- العمل كنظير رئيسي لخط الدفاع الأول (1LoD) مع فرق المخاطر، والامتثال، والتدقيق الداخلي، ومركز تميز الذكاء الاصطناعي.
- قيادة وتسهيل برامج رواد الأمن (Security Champions) عبر الفرق الهندسية.
- تعزيز تبني DevSecOps ومبادئ الأمن بالتصميم عبر بيئات تسليم البرمجيات.
- تقديم مقاييس حوكمة الأمن السيبراني الشهرية، وتقييمات وضع المخاطر، ولوحات تقارير الإدارة التنفيذية.
- إدارة معالجة الثغرات الأمنية، ومتابعة التصحيح، ومبادرات تحسين الوضع الأمني.
- التعاون مع فرق السحابة والبنية التحتية والتطبيقات والمنصات لتعزيز المرونة السيبرانية.
- ضمان الجاهزية للمراجعات الداخلية، والتدقيق، والتفتيش التنظيمي.
- دعم تنفيذ حوكمة الذكاء الاصطناعي، وإدارة مخاطر الذكاء الاصطناعي، وضوابط أمن التقنيات الناشئة.
- قيادة مبادرات التحسين المستمر عبر العمليات السيبرانية، والأتمتة، وممارسات هندسة الأمن.
المهارات والمؤهلات المطلوبة - خبرة لا تقل عن 12 عاماً في أدوار قيادية في هندسة الأمن السيبراني، أو بنية الأمن، أو DevSecOps، أو أمن السحابة.
- خبرة مثبتة في قيادة مبادرات هندسة وحوكمة الأمن واسعة النطاق في القطاع المصرفي أو القطاعات الخاضعة لتنظيم صارم.
- خبرة قوية في:
- DevSecOps
- أمن السحابة
- أمن الذكاء الاصطناعي
- أمن التطبيقات
- حوكمة الأمن
- المخاطر والامتثال
- خبرة مثبتة في العمل ضمن نموذج خطوط الدفاع الثلاثة (3LoD).
- خبرة في تصميم وتطبيق ضوابط الأمن عبر بيئات Azure وAWS.
- خبرة عملية في إدارة أدوات أمن المؤسسات والمنصات الأمنية المدمجة.
- معرفة قوية بممارسات دورة حياة تطوير البرمجيات الآمنة (SSDLC).
- خبرة في تطبيق أطر حوكمة الذكاء الاصطناعي وإدارة مخاطره.
- دراية بالمتطلبات التنظيمية ومتطلبات الامتثال ضمن بيئات الخدمات المالية.
- مهارات ممتازة في إدارة أصحاب المصلحة والتواصل التنفيذي.
- خبرة مثبتة في قيادة فرق الأمن السيبراني متعددة التخصصات وبرامج التحول الأمني.
الشهادات (إلزامية ومفضلة)
إلزامية
مفضلة
- CCSP
- AWS Certified Security – Specialty
- Azure Security Engineer Associate
- CISM
- ISO/IEC 42001 Lead Implementer
- Certified DevSecOps Professional (CDP) أو ما يعادلها
مرغوبة بشدة
المهارات والخبرات المفضلة
- خبرة في مجال الخدمات المصرفية والمالية.
- الاطلاع والخبرة في أطر حوكمة وأمن الذكاء الاصطناعي والتعلم الآلي (AI/ML).
- خبرة في تنفيذ البنيات الأمنية المصممة للسحابة (cloud-native).
- دراية بمقاييس الأمن، ولوحات معلومات الإدارة التنفيذية، وتقارير الحوكمة.
- خبرة في قيادة مبادرات المعالجة التنظيمية والتحول السيبراني.
- فهم عميق لإدارة الثغرات الأمنية وأتمتة الامتثال.
- سجل حافل في تعزيز الثقافة الأمنية وبرامج تمكين الهندسة.
مجموعة هاليان (Halian Group)
بفضل أكثر من 28 عاماً من الخبرة، أدركنا أن الابتكار هو الطريق الوحيد لتقديم حلول مرنة وعملية تحدث تحولاً في الأعمال والمسارات المهنية. تساعدك خدماتنا الذكية والتزويد بالكوادر على تحقيق إمكانات الغد. اكتشف الأمور المذهلة الممكنة عندما تجمع بين الأشخاص المناسبين والتقنيات المناسبة.
في هاليان، ندرك أن التنوع والعدالة والشمول (DEI) أمور أساسية لبناء فرق عالية الأداء لعملائنا. نحن ملتزمون بربط المؤسسات بأفضل المواهب من جميع الخلفيات، وضمان شعور كل فرد بالتقدير والاحترام والتمكين للمساهمة برؤاه الفريدة.
نحن نشجع الطلبات من جميع المرشحين المؤهلين، بغض النظر عن العرق أو الجنس أو الإعاقة أو أي خاصية أخرى تجعلهم فريدين.
قائد تقني للأمن السيبراني في أبوظبي، الإمارات العربية المتحدة