8+ years of experience in Information Security, including 3+ years leading a security domain end-to-end.
Experience delivering security within a regulated financial services environment, with direct exposure to regulatory examinations and audits.
Strong hands-on cloud security expertise covering IAM, network architecture, encryption and key management, threat detection services, and Infrastructure-as-Code (IaC).
Practical experience in container and Kubernetes security, including RBAC, admission control, network policies, workload identity, and image supply-chain security.
Proven experience embedding security into CI/CD pipelines and collaborating effectively with engineering teams, with the ability to read and understand application code and infrastructure plans.
Experience building or significantly maturing at least one of the following:
- Vulnerability Management
- Security Monitoring & Incident Response
- Third-Party Risk Management
Strong written communication skills, with the ability to communicate effectively with both technical audiences (engineers) and senior stakeholders, executives, or regulators.
Professional working proficiency in English.
Arabic language proficiency is strongly preferred, particularly for regulatory correspondence.
Skills
Preferred CBK regulatory experience, or comparable GCC financial-sector regulation (SAMA, CBUAE, CBB) PCI-DSS implementation or assessment experience BNPL, lending, payments, or e-money domain experience, including fraud exposure Experience where the security function had to be built rather than inherited Incident response experience on a real, material incident