Assistant Manager - Application Security Architect (UAE National Only) - Al Hilal Bank
Abu Dhabi Commercial Bank · Abu Dhabi Emirate, United Arab Emirates
قدّم وتابع مع أبلاي إيدجEmbark on a journey where your unique contributions are celebrated, and your professional growth is embraced. At ADCB, we nurture a diverse, inclusive community where every voice is valued.About the business area - Group Risk ManagementADCB prioritises a disciplined approach to risk, recognising its fundamental importance to the Bank’s long-term organisational and financial resilience. Group Risk Management oversees the implementation of ADCB's risk objectives, identifying and addressing gaps in the bank's risk infrastructure/framework. Their responsibilities include nurturing the independence of the risk function, establishing provisioning policies, and introducing changes to energise risk awareness among front office personnel and decision-makers. Continuously tuning the risk organisation in line with market best practices, they manage ADCB's portfolio and associated risks to international standards, while establishing a clear risk culture across all areas of operation.In this role, your key responsibilities include:To design, implement and maintain secure technology architectures across the Bank’s digital platforms, applications, infrastructure and cloud environments in order to strengthen cyber resilience, reduce technology risks, support regulatory compliance and ensure security-by-design principles are embedded throughout the technology lifecycle. The role provides specialist expertise in application security, cloud security, secure architecture, threat modelling and cyber security governance.Develop, implement and maintain security architecture standards, reference architectures, security patterns and secure design principles across applications, infrastructure, cloud services, APIs and digital platforms to ensure technology solutions are aligned with security requirements and risk management objectivesReview and assess solution designs, technology architectures and project initiatives to ensure compliance with approved security standards, regulatory requirements, cyber security controls and industry best practices prior to implementationConduct threat modelling exercises, architecture risk assessments and security design reviews during project initiation, solution design and change implementation phases to identify security risks and recommend mitigating controlsSupport the establishment and maintenance of a Secure Software Development Lifecycle (SSDLC) by defining security requirements, secure coding standards and security checkpoints to ensure security controls are integrated within software development activitiesCollaborate with development and technology teams to integrate security controls, automated testing capabilities and continuous security monitoring into DevSecOps and CI/CD pipelines to strengthen security throughout the application lifecycleAssess the security posture of web applications, mobile applications, application programming interfaces (APIs) and customer-facing digital platforms by evaluating authentication, authorization, encryption, session management and data protection controlsConduct or coordinate penetration testing, vulnerability assessments and security validation exercises relating to web applications, mobile applications, APIs, authentication platforms and cloud environments to identify, validate and remediate security weaknesses prior to production deploymentAssess cloud-native applications, microservices, containerised environments and emerging technologies to ensure appropriate security architecture, configuration standards and control requirements are implemented and maintainedSupport compliance with applicable cyber security regulations, information assurance standards and industry frameworks by implementing appropriate controls, conducting reviews and supporting governance and assurance activitiesFacilitate internal audits, external audits, security reviews and regulatory assessments by providing evidence, supporting remediation activities and monitoring closure of identified observations and vulnerabilitiesSupport investigations relating to application security incidents, cyber security events and digital channel compromises through technical analysis, root cause identification and implementation of corrective actions to strengthen security resilienceManage self and team in line with AHB’s people management policies, procedures, processes and practices to ensure adherence and to maximise own and employee contribution to business performanceOrganise and supervise the activities and work of the team to ensure that targets and objectives are achieved and the business plan is delivered in line with the required policies, processes, procedures and systemsImplement approved departmental policies, processes and procedures, and ensure employee adherence so that work is carried out to the required standard while delivering the required standards of service to customers and stakeholdersManage and motivate the team to ensure they contribute to, and participate in, the identification and implementation of change initiatives, programmes and projects in line with the Bank’s standardsDemonstrate Our Promise and apply the AHB Service Standards to deliver the Bank’s required levels of service in all internal and external customer interactionsThe ideal candidate should have the following experience:At least 5 years of experience in cyber security, information security, technology risk, security architecture, application security or infrastructure security, including experience in security architecture reviews, threat modelling, vulnerability assessments and cyber security governance activities. Experience within banking, financial services or a regulated industry is preferredBachelor’s Degree from a well recognised university in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering or a related disciplineOne or more industry-recognised certifications such as Certified Information Systems Security Professional (CISSP), Certified Secure Software Lifecycle Professional (CSSLP), Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), Certificate of Cloud Security Knowledge (CCSK), SABSA, Cloud Security certifications or equivalent cyber security certificationsSecurity architecture,Application security architectureCloud security architectureThreat modelling methodologiesSecure software development lifecycle (SSDLC)DevSecOps practices, secure coding principlesWeb application securityMobile application securityAPI securityPenetration testingVulnerability managementCloud security controlsZero trust architectureIdentity and access managementAuthentication mechanismsCryptographyContainer securityCyber security governanceTechnology risk managementOWASP Top 10OWASP Mobile Top 10OWASP API Security Top 10MITRE ATT&CK FrameworkSecure authentication mechanismsStakeholder managementAnalytical thinkingCommunication and reportingWhat we offer:Competitive Salary & Additionally, all employees are eligible to participate in one of our rewarding variable pay plans.Comprehensive Benefits Package: This includes market-leading medical insurance, group life and personal accident insurance, paid leave and leave airfare, employee preferential rates on loans and finance facilities, staff discounts and offers, and children education assistance (for certain job levels).Flexible and Remote Working Options: We understand the importance of work-life balance and offer flexible working arrangements, subject to eligibility and job requirements.Learning and Development Opportunities: We value and facilitate continuous learning and personal development through a variety of exciting learning opportunities, such as structured instructor-led courses, a comprehensive e-learning catalog, on-the-job training, and professional development programs.At ADCB, we are dedicated to creating a respectful, caring and disciplined work environment that aligns with your career ambitions.