We have an urgent requirement for Senior Manager – Offensive Security Engineering & AI Security Validation with OSCP or OSCE certified is required for our banking clients in Abu Dhabi ,UAE
Strong experience on on AI/LLM red teaming & blue teaming experience is MUST
Strong experience in Advanced Offensive Security Engineering – deep exploit knowledge, not just pentesting/tools--Must
AppSec problem owned end-to-end--Must
Strong experience in Security Automation & Continuous Validation – CI/CD-based, always-on security testing pipelines--Must
Strong experience in AI/LLM Security & Red Teaming – prompt injection, model attacks, OWASP LLM + MITRE ATLAS exposure.---Must
linking detection (SAST, pentests) with prevention and remediation.
Strong experience in Threat Intel to Test Engineering – convert MITRE/OWASP intel into automated attack test cases within strict SLAs ---Must
Mandatory certification - OSCP OR OSCE ( one is Must to have )
We are seeking a Senior Manager – Cyber Security Engineering to lead offensive security engineering, continuous adversarial validation, and AI/cloud security testing. The role focuses on transitioning from periodic penetration testing to continuous security validation across cloud, infrastructure, and AI/ML systems, aligned to 1LoD/2LoD governance models in a regulated environment.
The incumbent will own automated security validation pipelines, threat intelligence operationalization, and security metrics reporting, ensuring production systems are continuously assessed against evolving adversarial techniques.
Experience Required
· 8–10 years in Cyber Security / Offensive Security / Red Team / Security Engineering
· Strong background in:
· Offensive security and penetration testing
· Cloud security (preferably AWS)
· Blue-team validation / security assurance engineering
· Adversarial simulation and continuous security testing frameworks
· Experience in financial services / regulated banking environment preferred
Mandatory Certifications
· Candidates must hold at least one OSCP or OSCE (mandatory requirement) plus additional certifications:
· Core Mandatory
· Offensive Security Certified Professional (OSCP) OR
· Offensive Security Certified Expert (OSCE)
· Additional Required / Strongly Preferred
· GIAC GPEN or GIAC GXPN
· GIAC GMLE or equivalent AI-security / ML security credential
· CREST Certified Simulated Attack Tester (CCT) (desirable, especially for banking/financial sectors)
· Emerging / AI Security Exposure (Preferred)
· Exposure or enrollment in AI security/red-teaming programs (e.g., Anthropic or equivalent frontier model security evaluation programs)
Core Responsibilities
1. Continuous Security Validation
· Design and operate continuous adversarial testing pipelines across:
· Cloud infrastructure (AWS-focused)
· Application security layers
· AI/ML models and LLM supply chain
· Implement automated security validation aligned with a 2LoD-approved threat coverage matrix
· Replace periodic penetration testing with always-on security validation systems
2. Threat Intelligence Operationalization (7-Day SLA)
· Ingest and analyze threat intelligence from:
· MITRE ATLAS (AI attack techniques)
· OWASP LLM Top 10
· Convert new adversarial techniques into automated test cases within 7 days
· Maintain a structured and auditable threat-to-test traceability pipeline
3. Vulnerability Aggregation & Governance
· Own centralized defect tracking using tools such as:
· DefectDojo or equivalent vulnerability management platforms
· Deduplicate, classify, and manage security findings end-to-end
· Enforce severity-based remediation SLAs and gating controls before production release
4. Security Metrics & Reporting
· Build and maintain executive dashboards (e.g., Power BI) tracking:
· Open findings
· Mean Time to Remediate (MTTR)
· Pipeline gate pass rate
· Prompt injection / AI attack block rate
· Provide governance-ready reporting for 1LoD/2LoD stakeholders
5. Offensive Security & AI Red Teaming
· Conduct and oversee:
· Automated penetration testing using tools such as Horizon3.ai or equivalent autonomous pentest platforms
· AI red-teaming using tools like Garak, PyRIT, and LLM-based attack frameworks
· Develop adversarial test cases aligned with:
· OWASP LLM Top 10
· MITRE ATLAS framework
· Validate resilience of AI systems against prompt injection, data leakage, and model manipulation attacks
6. Governance & Operating Model Alignment
· Maintain clear separation of responsibilities between:
· 1LoD: Continuous control validation and security assurance
· 2LoD: Independent red teaming and unknown-scenario adversarial testing
· Ensure compliance with internal risk governance frameworks in regulated environments
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.