Al Etihad Payments empowers employees to work in an environment that best promotes their productivity and well-being, while providing high-quality workplace and fantastic professional experience.
|Get to Know Us
Al Etihad Payments is the UAE’s designated retail payments entity, dedicated to developing and operating world-class infrastructure, standards, and solutions for the UAE Economy. Al Etihad Payments is a subsidiary of the Central Bank of the UAE, strongly supported by the UAE Government.
Al Etihad Payments is the UAE’s designated retail payments entity, dedicated to developing and operating world-class infrastructure, standards, and solutions for the UAE Economy. Al Etihad Payments is a subsidiary of the Central Bank of the UAE, strongly supported by the UAE Government.
Our employees are committed to work with licensed financial institutions and other payment service providers to foster innovation and deliver excellent financial services to all in the UAE, efficiently and without friction.
Al Etihad Payments supports the government’s objectives of a cashless society, national digitization, and the Central Bank of the UAE objective of being a top ten central bank globally.
|Our Culture
We are a collaborative, diverse and passionate group of individuals that works as one team. We support one another, make impactful contributions to the organization, and develop and nurture meaningful connections across the payment’s ecosystem!
|About the role
Lead AEP’s vulnerability management, penetration testing and security assessment activities to identify, assess and drive remediation of security weaknesses across applications, infrastructure, networks, cloud environments and other technology assets.
|What You’ll Do:
Penetration Testing
- Develop and maintain the annual penetration-testing program.
- Coordinate internal and external penetration tests.
- Manage testing of:
- Web application
- APIs
- Mobile applications
- Network infrastructure
- External perimeter
- Internal infrastructure
- Authentication and access controls
- Review penetration-testing reports and validate findings.
- Ensure identified vulnerabilities are assigned to appropriate risk owners.
- Track remediation and conduct retesting.
Application & API Security
- Establish VAPT requirements for applications and APIs.
- Work with application development and DevSecOps teams to integrate security testing into the SDLC.
- Coordinate SAST, DAST, and API security testing where applicable.
- Ensure security testing is performed before production release based on risk and application criticality.
Vulnerability Management
- Establish and manage the vulnerability management program.
- Coordinate vulnerability scanning across servers, endpoints, network devices, applications, databases, and other relevant assets.
- Review and validate vulnerability scan results.
- Prioritize vulnerabilities based on severity, exploitability, asset criticality, exposure, business impact and threat intelligence.
- Establish remediation timelines and risk-based exceptions.
- Track remediation through closure and validate remediation effectiveness.
- Provide vulnerability risk dashboards and management reporting.
Risk & Exception Management
- Coordinate with asset/application owners for remediation.
- Review requests for vulnerability exceptions or risk acceptance.
- Aligning with GRC Team to manage the vulnerability exceptions
- Ensure residual risks are appropriately documented and approved by the relevant risk owner.
- Escalate overdue critical/high-risk vulnerabilities.
Qualifications & Years of Experience
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science or related field.
- 8+ years of cybersecurity experience, with significant VAPT/vulnerability-management experience.
- Strong understanding of network, application, API, and infrastructure security.
- Experience managing external VAPT
Required Skills
- OSCP / OSCP+
- CREST certifications/GPEN / GWAPT/CEH
- Proficient with web application testing tools, specifically Burp Suite Professional.
- Hands-on experience with network assessment and exploitation tools including Nmap, Metasploit, Wireshark, and sqlmap.
- Ability to write custom automation scripts utilizing Python, PowerShell, or Bash.
- Strong understanding of operating security testing environments within Kali Linux.
- Programming & Scripting: Ability to read and modify code, and write automation scripts using Python, PowerShell, or Bash to bypass standard security controls.
- Web & API Security: Comprehensive understanding of the OWASAP Top 10
vulnerabilities (e.g., SQL Injection, Cross-Site Scripting, Broken Authentication) and API security risks.
- Technical Writing & Reporting: The ability to translate complex technical vulnerabilities into clear, actionable remediation steps for developers, and write high-level summaries for executive stakeholders.
|What you can expect from us
- Modern work environment with level of flexibility;
- Dynamic and motivated team of colleagues working towards achieving UAE National Objectives;
- Competitive compensation package, including annual bonus and additional benefits like child educational allowance and annual flight tickets (where eligible);
- Comprehensive health insurance coverage;