Al Hilal Bank | Abu Dhabi, UAE
For Emirate
In this role, your key responsibilities include:
- To design, implement and maintain secure technology architectures across the Bank’s digital platforms, applications, infrastructure and cloud environments in order to strengthen cyber resilience, reduce technology risks, support regulatory compliance and ensure security-by-design principles are embedded throughout the technology lifecycle. The role provides specialist expertise in application security, cloud security, secure architecture, threat modelling and cyber security governance.
- Develop, implement and maintain security architecture standards, reference architectures, security patterns and secure design principles across applications, infrastructure, cloud services, APIs and digital platforms to ensure technology solutions are aligned with security requirements and risk management objectives
- Review and assess solution designs, technology architectures and project initiatives to ensure compliance with approved security standards, regulatory requirements, cyber security controls and industry best practices prior to implementation
- Conduct threat modelling exercises, architecture risk assessments and security design reviews during project initiation, solution design and change implementation phases to identify security risks and recommend mitigating controls
- Support the establishment and maintenance of a Secure Software Development Lifecycle (SSDLC) by defining security requirements, secure coding standards and security checkpoints to ensure security controls are integrated within software development activities
- Collaborate with development and technology teams to integrate security controls, automated testing capabilities and continuous security monitoring into DevSecOps and CI/CD pipelines to strengthen security throughout the application lifecycle
- Assess the security posture of web applications, mobile applications, application programming interfaces (APIs) and customer-facing digital platforms by evaluating authentication, authorization, encryption, session management and data protection controls
- Conduct or coordinate penetration testing, vulnerability assessments and security validation exercises relating to web applications, mobile applications, APIs, authentication platforms and cloud environments to identify, validate and remediate security weaknesses prior to production deployment
- Assess cloud-native applications, microservices, containerised environments and emerging technologies to ensure appropriate security architecture, configuration standards and control requirements are implemented and maintained
- Support compliance with applicable cyber security regulations, information assurance standards and industry frameworks by implementing appropriate controls, conducting reviews and supporting governance and assurance activities
- Facilitate internal audits, external audits, security reviews and regulatory assessments by providing evidence, supporting remediation activities and monitoring closure of identified observations and vulnerabilities
- Support investigations relating to application security incidents, cyber security events and digital channel compromises through technical analysis, root cause identification and implementation of corrective actions to strengthen security resilience
- Manage self and team in line with AHB’s people management policies, procedures, processes and practices to ensure adherence and to maximise own and employee contribution to business performance
- Organise and supervise the activities and work of the team to ensure that targets and objectives are achieved and the business plan is delivered in line with the required policies, processes, procedures and systems
- Implement approved departmental policies, processes and procedures, and ensure employee adherence so that work is carried out to the required standard while delivering the required standards of service to customers and stakeholders
- Manage and motivate the team to ensure they contribute to, and participate in, the identification and implementation of change initiatives, programmes and projects in line with the Bank’s standards
- Demonstrate Our Promise and apply the AHB Service Standards to deliver the Bank’s required levels of service in all internal and external customer interactions
The ideal candidate should have the following experience:
- At least 5 years of experience in cyber security, information security, technology risk, security architecture, application security or infrastructure security, including experience in security architecture reviews, threat modelling, vulnerability assessments and cyber security governance activities. Experience within banking, financial services or a regulated industry is preferred
- Bachelor’s Degree from a well recognised university in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline
- One or more industry-recognised certifications such as Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional (CSSLP), Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), Certificate of Cloud Security Knowledge (CCSK), SABSA, Cloud Security certifications or equivalent cyber security certifications
- Security architecture,
- Application security architecture
- Cloud security architecture
- Threat modelling methodologies
- Secure software development lifecycle (SSDLC)
- DevSecOps practices, secure coding principles
- Web application security
- Mobile application security
- API security
- Penetration testing
- Vulnerability management
- Cloud security controls
- Zero trust architecture
- Identity and access management
- Authentication mechanisms
- Cryptography
- Container security
- Cyber security governance
- Technology risk management
- OWASP Top 10
- OWASP Mobile Top 10
- OWASP API Security Top 10
- MITRE ATT&CK Framework
- Secure authentication mechanisms
- Stakeholder management
- Analytical thinking
- Communication and reporting