We have an urgent requirement for Senior Manager – Cyber Security Engineerwith experience in banking domain is required for our clients in Abu Dhabi ,UAE
Strong experience on AI/LLM Model and Supply chain model
Strong experience on AWS Security Agent (cloud/infra)
Strong experience in AI/LLM Security & Red Teaming – prompt injection, model attacks, OWASP LLM + MITRE ATLAS exposure.---Must
Strong experience Garak, PyRIT, Claude Security / Opus 4.x, Codex, 1LoD/2LoD
Strong experience in Threat Intel to Test Engineering – convert MITRE/OWASP intel into automated attack test cases within strict SLAs ---Must
Role Purpose: Lead the organisation’s transition from periodic, manual penetration testing to continuous, automated adversarial security validation across cloud infrastructure, applications, AI/LLM systems, and model supply chains. The role will own continuous control validation, threat-informed security testing, vulnerability orchestration, and remediation governance while maintaining a clear 1LoD/2LoD operating model.
Key Responsibilities:
Continuous Security Validation
Design and operate continuous security validation across AWS cloud/infrastructure, applications, AI/LLM workloads, and model supply chains.
Integrate autonomous security testing tools such as AWS Security Agent, Horizon3.ai, or equivalent platforms into CI/CD pipelines.
Execute automated adversarial tests against significant deployments based on a 2LoD-approved threat coverage matrix.
Establish automated security gates to prevent deployment where critical security controls fail.
Threat Intelligence & Adversarial Testing
Own the 7-day threat-intelligence operationalisation SLA.
Monitor MITRE ATLAS, OWASP LLM Top 10, and other relevant threat-intelligence sources.
Use Jira automation and security engineering workflows to translate emerging attack techniques into repeatable security test cases within seven days.
Develop and maintain adversarial test scenarios covering cloud, application, AI/LLM, prompt-injection, model-abuse, and model-supply-chain risks.
AI / LLM Security & Red Teaming
Lead continuous AI security validation using tools such as Garak, PyRIT, Claude Security/Opus 4.x, Codex, or equivalent platforms.
Design tests for prompt injection, jailbreaks, data leakage, excessive agency, insecure tool use, model manipulation, and supply-chain risks.
Continuously measure and improve Prompt Injection Block Rate and other AI security control effectiveness metrics.
Vulnerability & Finding Management
Aggregate, deduplicate, prioritise, and SLA-manage security findings through DefectDojo.
Establish severity-based MTTR remediation gates and ensure remediation evidence is validated before re-deployment approval.
Drive end-to-end finding lifecycle management from discovery through remediation, validation, attestation, and closure.
Security Metrics & Governance
Develop executive-level Power BI dashboards covering:
Open Findings
MTTR
Pipeline Gate Pass Rate
Prompt Injection Block Rate
Security Control Effectiveness
Threat Coverage
Remediation SLA Compliance
Provide management-level reporting on security posture, control effectiveness, emerging threats, and remediation performance.
1LoD / 2LoD Operating Model
Maintain a clear separation between 1LoD control validation and independent 2LoD security assurance/red teaming.
Execute blue-team control validation against 2LoD-approved threat scenarios and test coverage.
Ensure independent unknown-scenario testing remains within the 2LoD remit to preserve appropriate challenge and assurance independence.
Required Technical Expertise
Strong experience in offensive security, penetration testing, adversarial simulation, blue-team validation, and continuous security validation.
Proven experience transitioning organisations from periodic manual penetration testing to automated/continuous security control validation.
Hands-on experience with autonomous penetration-testing platforms such as AWS Security Agent, Horizon3.ai, or equivalent.
Strong expertise in AI/LLM security and AI red teaming, including Garak, PyRIT, Claude Security/Opus, Codex, or comparable tooling.
Strong knowledge of OWASP LLM Top 10 and MITRE ATLAS.
Experience integrating security validation into CI/CD and DevSecOps pipelines.
Experience with DefectDojo, Jira automation, vulnerability management, security metrics, and Power BI.
Strong understanding of cloud security, AWS security controls, application security, threat modelling, and adversarial testing.
Strong understanding of 1LoD/2LoD governance, control validation, independent assurance, and security risk management.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UAE.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UAE, connecting you to thousands of jobs fast!
Find the best jobs in the UAE, apply in 1 click and get a job today!