Cyber Technical Lead
Role Overview
We are seeking an experienced Cyber Technical Lead to lead a strategic cybersecurity transformation initiative within a highly regulated banking environment.
This role will be responsible for operating and governing a multi-disciplinary cyber security squad delivering Application Security, AI Governance, Continuous Security Validation, and Compliance Assurance services. The successful candidate will act as the primary First Line of Defense (1LoD) technology leader, ensuring security controls are embedded across the software delivery lifecycle while maintaining alignment with regulatory requirements, enterprise security policies, and operational risk frameworks.
The ideal candidate will have extensive expertise in DevSecOps, Cloud Security, AI Security, Cyber Governance, Secure Software Delivery, and Banking Regulatory Compliance, with a proven record of leading cross-functional security teams within large-scale regulated organizations.
Key Responsibilities
- Lead and manage a cyber security squad across four strategic workstreams:
- Application Security (AppSec)
- AI Governance
- Continuous Security Validation
- Compliance & Audit Trail Management
- Ensure delivery aligns with approved security policies, regulatory requirements, and agreed service level agreements (SLAs).
- Own and govern the enterprise security tooling ecosystem, driving optimization, integration, and vendor consolidation strategies.
- Define and oversee integration architecture across security platforms and engineering toolchains.
- Establish and manage evidence management processes supporting audit, attestation, and regulatory reporting requirements.
- Act as the primary 1LoD counterpart to Risk, Compliance, Internal Audit, and AI Centre of Excellence teams.
- Lead and facilitate Security Champions programs across engineering teams.
- Drive DevSecOps adoption and secure-by-design principles across software delivery environments.
- Present monthly cybersecurity governance metrics, risk posture assessments, and executive reporting dashboards.
- Govern vulnerability management, remediation tracking, and security posture improvement initiatives.
- Collaborate with cloud, infrastructure, application, and platform teams to enhance cyber resilience.
- Ensure readiness for internal reviews, audits, and regulatory inspections.
- Support implementation of AI governance, AI risk management, and emerging technology security controls.
- Drive continuous improvement initiatives across cyber operations, automation, and security engineering practices.
Required Skills & Qualifications
- 12+ years of experience in Cybersecurity Engineering, Security Architecture, DevSecOps, or Cloud Security leadership roles.
- Proven experience leading large-scale security engineering and governance initiatives within banking or highly regulated industries.
- Strong expertise in:
- DevSecOps
- Cloud Security
- AI Security
- Application Security
- Security Governance
- Risk & Compliance
- Demonstrated experience operating within a Three Lines of Defense (3LoD) model.
- Expertise in designing and implementing security controls across Azure and AWS environments.
- Hands-on experience managing enterprise security tooling and integrated security platforms.
- Strong knowledge of secure software development lifecycle (SSDLC) practices.
- Experience implementing AI governance and AI risk management frameworks.
- Familiarity with regulatory and compliance requirements within financial services environments.
- Excellent stakeholder management and executive communication skills.
- Proven experience leading multidisciplinary cybersecurity teams and security transformation programs.
Certifications (Mandatory & Preferred)
Mandatory
Preferred
- CCSP
- AWS Certified Security – Specialty
- Azure Security Engineer Associate
- CISM
- ISO/IEC 42001 Lead Implementer
- Certified DevSecOps Professional (CDP) or equivalent
Highly Desirable
Preferred Skills & Experience
- Banking and financial services industry experience.
- Exposure to AI/ML governance and security frameworks.
- Experience implementing cloud-native security architectures.
- Familiarity with security metrics, executive dashboards, and governance reporting.
- Experience leading regulatory remediation and cyber transformation initiatives.
- Deep understanding of vulnerability management and compliance automation.
- Proven track record of driving security culture and engineering enablement programs.
Halian Group
With over 28 years of experience, we have come to understand that innovation is the only way to provide agile, practical solutions that transform businesses and careers. Our resourcing and smart services help you to realise tomorrow's potential. Discover the amazing things possible when you bring the right people and the right technologies together.
At Halian, we recognise that diversity, equity, and inclusion (DEI) are essential to building high-performing teams for our clients. We are committed to connecting organisations with top talent from all backgrounds, ensuring that every individual feels valued, respected, and empowered to contribute their unique perspectives.
We encourage applications from all qualified candidates, regardless of race, gender, disability, or any other characteristic that makes them unique.
Cyber Technical Lead in Abu Dhabi, United Arab Emirates
قائد تقني للأمن السيبراني
نظرة عامة على الدور الوظيفي
نحن نبحث عن قائد تقني للأمن السيبراني ذي خبرة لقيادة مبادرة استراتيجية للتحول في مجال الأمن السيبراني ضمن بيئة مصرفية تخضع لضوابط تنظيمية صارمة.
سيكون هذا الدور مسؤولاً عن تشغيل وإدارة فرقة أمن سيبراني متعددة التخصصات تقدم خدمات أمن التطبيقات، وحوكمة الذكاء الاصطناعي، والتحقق المستمر من الأمن، وضمان الامتثال. وسيعمل المرشح الناجح كقائد تكنولوجي رئيسي في خط الدفاع الأول (1LoD)، مما يضمن إدراج ضوابط الأمن عبر دورة حياة تسليم البرمجيات مع الحفاظ على التوافق مع المتطلبات التنظيمية وسياسات أمن المؤسسة وأطر المخاطر التشغيلية.
سيمتلك المرشح المثالي خبرة واسعة في DevSecOps، وأمن السحابة، وأمن الذكاء الاصطناعي، والحوكمة السيبرانية، والتسليم الآمن للبرمجيات، والامتثال التنظيمي المصرفي، مع سجل مثبت في قيادة فرق أمنية متعددة الوظائف داخل مؤسسات كبرى خاضعة للتنظيم.
المسؤوليات الرئيسية
- قيادة وإدارة فرقة الأمن السيبراني عبر أربعة مسارات عمل استراتيجية:
- أمن التطبيقات (AppSec)
- حوكمة الذكاء الاصطناعي
- التحقق المستمر من الأمن
- إدارة الامتثال وسجل المراجعة
- ضمان توافق التسليم مع سياسات الأمن المعتمدة، والمتطلبات التنظيمية، واتفاقيات مستوى الخدمة (SLAs) المتفق عليها.
- امتلاك وحوكمة منظومة أدوات الأمن في المؤسسة، وتوجيه استراتيجيات التحسين والتكامل وتجميع الموردين.
- تحديد والإشراف على هندسة التكامل عبر المنصات الأمنية وسلاسل أدوات الهندسة.
- إنشاء وإدارة عمليات إدارة الأدلة التي تدعم متطلبات المراجعة والإقرار والتقارير التنظيمية.
- العمل كنظير رئيسي لخط الدفاع الأول (1LoD) لفرق المخاطر والامتثال والمراجعة الداخلية ومركز تميز الذكاء الاصطناعي.
- قيادة وتسهيل برامج رواد الأمن (Security Champions) عبر فرق الهندسة.
- تعزيز اعتماد DevSecOps ومبادئ الأمن بالصميم (secure-by-design) عبر بيئات تسليم البرمجيات.
- تقديم مقاييس حوكمة الأمن السيبراني الشهرية، وتقييمات وضع المخاطر، ولوحات تقارير الإدارة التنفيذية.
- حوكمة إدارة الثغرات الأمنية، وتتبع المعالجة، ومبادرات تحسين الوضع الأمني.
- التعاون مع فرق السحابة والبنية التحتية والتطبيقات والمنصات لتعزيز المرونة السيبرانية.
- ضمان الجاهزية للمراجعات الداخلية وتدقيق الحسابات والتفتيش التنظيمي.
- دعم تنفيذ حوكمة الذكاء الاصطناعي وإدارة مخاطر الذكاء الاصطناعي وضوابط أمن التقنيات الناشئة.
- قيادة مبادرات التحسين المستمر عبر العمليات السيبرانية والأتمتة وممارسات الهندسة الأمنية.
المهارات والمؤهلات المطلوبة
- خبرة أكثر من 12 عاماً في أداء أدوار قيادية في هندسة الأمن السيبراني، أو الهندسة المعمارية للأمن، أو DevSecOps، أو أمن السحابة.
- خبرة مثبتة في قيادة مبادرات هندسة الأمن والحوكمة واسعة النطاق في القطاع المصرفي أو القطاعات الخاضعة لتنظيم صارم.
- خبرة قوية في:
- DevSecOps
- أمن السحابة
- أمن الذكاء الاصطناعي
- أمن التطبيقات
- الحوكمة الأمنية
- المخاطر والامتثال
- خبرة عملية مثبتة في العمل ضمن نموذج خطوط الدفاع الثلاثة (3LoD).
- خبرة في تصميم وتنفيذ الضوابط الأمنية عبر بيئات Azure وAWS.
- خبرة عملية في إدارة أدوات أمن المؤسسة والمنصات الأمنية المتكاملة.
- معرفة قوية بممارسات دورة حياة تطوير البرمجيات الآمنة (SSDLC).
- خبرة في تطبيق أطر حوكمة الذكاء الاصطناعي وإدارة مخاطر الذكاء الاصطناعي.
- الاطلاع على المتطلبات التنظيمية ومتطلبات الامتثال في بيئات الخدمات المالية.
- مهارات ممتازة في إدارة أصحاب المصلحة والتواصل التنفيذي.
- خبرة مثبتة في قيادة فرق الأمن السيبراني متعددة التخصصات وبرامج التحول الأمني.
الشهادات (إلزامية ومفضلة)
إلزامية
مفضلة
- CCSP
- AWS Certified Security – Specialty
- Azure Security Engineer Associate
- CISM
- ISO/IEC 42001 Lead Implementer
- محترف DevSecOps معتمد (CDP) أو ما يعادلها
مرغوبة بشدة
المهارات والخبرات المفضلة
- خبرة في قطاع البنوك والخدمات المالية.
- الاطلاع على أطر حوكمة وأمن الذكاء الاصطناعي/تعلم الآلة (AI/ML).
- خبرة في تنفيذ البنيات المعمارية الأمنية المخصصة للسحابة (Cloud-native).
- الاطلاع على المقاييس الأمنية، ولوحات القيادة التنفيذية، وتقارير الحوكمة.
- خبرة في قيادة مبادرات المعالجة التنظيمية والتحول السيبراني.
- فهم عميق لإدارة الثغرات وأتمتة الامتثال.
- سجل حافل ومثبت في تعزيز الثقافة الأمنية وبرامج تمكين الهندسة.
مجموعة هاليان (Halian Group)
مع أكثر من 28 عاماً من الخبرة، أدركنا أن الابتكار هو الطريق الوحيد لتقديم حلول مرنة وعملية تحول الأعمال والمسارات المهنية. تساعدك خدماتنا التوظيفية والذكية على تحقيق إمكانات الغد. اكتشف الأشياء المذهلة الممكنة عندما تجمع بين الأشخاص المناسبين والتقنيات المناسبة.
في هاليان، ندرك أن التنوع والعدالة والشمول (DEI) أمور أساسية لبناء فرق عالية الأداء لعملائنا. نحن نلتزم بربط المؤسسات بأفضل المواهب من جميع الخلفيات، مع ضمان شعور كل فرد بالتقدير والاحترام والتمكين للمساهمة برؤاهم الفريدة.
نحن نشجع الطلبات المقدمة من جميع المرشحين المؤهلين، بغض النظر عن العرق أو الجنس أو الإعاقة أو أي سمة أخرى تجعلهم فريدين.
قائد تقني للأمن السيبراني في أبوظبي، الإمارات العربية المتحدة