Senior Manager - Cyber Security Engineers
About Us
Operating from Abu Dhabi since 1985, our client provides personal and business banking services across retail banking, wealth management, commercial banking, corporate finance, investment banking, and cash management. The institution supports a broad financial‑services ecosystem where resilient technology, secure digital operations, and disciplined risk management are essential to protecting customers, transactions, and business continuity.
Its scale and service breadth create a demanding environment for cyber security professionals, with engineering teams contributing directly to the assurance of critical banking platforms and emerging technologies.
Job DescriptionThe Senior Manager, Cyber Security Engineers will lead the development and operation of a continuous security‑validation capability across the banking environment. The role will convert threat intelligence and approved adversarial scenarios into automated, repeatable tests covering cloud services, infrastructure, artificial intelligence systems, and model supply chains.
Success will be measured by stronger threat coverage, faster remediation, reliable deployment gates, and clear executive reporting. You will guide engineering delivery, coordinate with security governance stakeholders, and maintain an effective first‑line validation model while preserving the second line of defence's responsibility for independent red teaming and unknown‑scenario assessment.
This position requires a leader who can combine strategic direction with technical credibility, establish measurable operating standards, and ensure that security findings are resolved before material changes are approved for release.
Key Responsibilities- Lead the strategy, roadmap, and day‑to‑day operation of continuous cyber security control validation.
- Direct automated testing across cloud platforms, enterprise infrastructure, AI applications, large‑language‑model use cases, and model supply chains.
- Translate second‑line‑approved threat scenarios into a structured coverage matrix and maintain alignment with business risk.
- Manage the ingestion of MITRE ATLAS and OWASP LLM threat intelligence, using Jira automation to meet the seven‑day service‑level agreement for new techniques.
- Turn emerging attack methods into practical validation test cases and ensure they are deployed within the agreed operational timeframe.
- Oversee the aggregation, deduplication, ownership, and lifecycle management of findings through platforms such as Defect Dojo and Attestation.
- Set severity‑based remediation targets and enforce mean‑time‑to‑remediate gates before re‑deployment approval.
- Partner with engineering, architecture, risk, and technology teams to resolve material weaknesses and improve control effectiveness.
- Maintain Power BI reporting for open findings, remediation performance, pipeline‑gate pass rates, threat coverage, and prompt‑injection block rates.
- Provide concise management information on exposure, trends, exceptions, overdue actions, and deployment assurance.
- Establish quality standards for validation evidence, test repeatability, scenario traceability, and audit readiness.
- Keep first‑line control validation clearly separated from second‑line independent red teaming, escalation, and challenge activities.
- Extensive experience leading cyber security engineering, offensive security, adversarial validation, or comparable assurance functions within a complex enterprise.
- Demonstrable success replacing periodic manual penetration testing with continuous or automated control‑validation practices.
- Strong technical understanding of cloud security, infrastructure security, application delivery pipelines, and security testing automation.
- Practical experience with autonomous…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).