أبلاي إيدج ابدأ البحث عن عمل

Head of Application Security and Cloud Risk

amana · Dubai, United Arab Emirates

قدّم وتابع مع أبلاي إيدج
We are looking for a hands-on leader to own cloud and security across Amana. This person is the senior authority for application security, cloud architecture, cloud security, and the engineering practices that keep our systems resilient.The title reflects the breadth of accountability, not the scale of a corporate hierarchy. Amana is a small company, and this role leads a compact function while remaining personally involved in the work.The right person has already led a small technical security team and is comfortable operating as its most senior engineer, initially supported by one engineer or analyst. They can review architecture, challenge engineering decisions, set priorities, and own outcomes across cloud, application security, vulnerability management, and incident readiness.What you’ll doOwn cloud and security across our customer-facing and internal platforms, including application security, cloud architecture, security standards, and operational risk.Review product, engineering, and cloud designs for security and resilience risks before they become production issues.Run threat modeling for new features, integrations, APIs, authentication flows, payments, trading, admin tools, and data handling.Work directly with engineering and DevOps teams to identify, prioritize, and resolve vulnerabilities and control gaps across applications, architecture, cloud configuration, CI/CD, secrets, IAM, and access control.Lead secure architecture reviews across web, mobile, backend, AWS, GCP, and third-party integrations.Build a practical security program around the risks that matter most: account takeover, data leakage, privilege escalation, fraud vectors, API abuse, insecure admin access, supply chain risk, and production misconfiguration.Own vulnerability management across applications, cloud assets, dependencies, and infrastructure.Drive penetration testing, security assessments, remediation plans, and follow-through.Set and improve cloud and security controls for identity, access, network boundaries, secrets, logging, alerting, resilience, and production change management.Partner with engineering to make secure delivery part of normal delivery, not a separate ceremony.Support compliance and regulatory expectations with evidence, controls, and clear technical ownership.Prepare the company for security incidents: playbooks, escalation paths, logging coverage, tabletop exercises, and post-incident review.Lead a compact cloud and security function, initially the Head plus one engineer or analyst, including prioritization, work allocation, coaching, and accountability.Work directly with technology leadership on security priorities, trade-offs, and risk acceptance.Essential skills and experience10+ years across application security, cloud security, security engineering, platform engineering, DevSecOps, or related technical security roles.Prior experience in fintech, banking, payments, trading, brokerage, crypto, or another regulated environment.Strong practical application security experience at architecture and system level: threat modeling, authentication, authorization, session management, API security, secure design, secrets handling, business logic abuse, and secure SDLC.Strong technical literacy and the ability to work directly with engineers. You should be able to understand and challenge code-level findings, but routine source-code review is not the primary responsibility of this role.Deep practical understanding of cloud architecture and security across AWS and GCP, including the judgment to set standards and challenge implementation decisions.Strong knowledge of IAM, RBAC, networking, WAF, logging, monitoring, secrets management, encryption, key management, and least privilege design.Strong working knowledge of cloud infrastructure, CI/CD, infrastructure as code, Linux, reliability, and production operations. This is not a Kubernetes specialist role.Experience running or coordinating penetration tests, vulnerability scans, dependency scanning, SAST/DAST, cloud posture reviews, and remediation tracking.Good judgment on risk. Able to separate theoretical issues from problems that can actually hurt the business.Experience working with compliance, audit, legal, product, and engineering without turning security into paperwork theatre.Strong written communication. Able to explain technical risk clearly to executives and engineers.Proven experience leading a small technical team while remaining personally hands-on, including setting priorities, allocating work, coaching, and owning outcomes.Our office is in the UAE, and onsite presence is preferred, but we are open to remote candidates.Strongly preferredExperience securing trading platforms, investment products, wallets, payments, onboarding/KYC flows, or financial APIs.Experience with modern web, mobile, and backend application stacks. Prior software engineering experience is an advantage.Experience with cloud incident response, breach investigation, forensics basics, or security monitoring.Security certifications such as CISSP, CSSLP, OSCP, AWS Security Specialty, GCP Professional Cloud Security Engineer, or other credible security certifications.Experience with bug bounty programs or external researcher intake.Experience building security programs in companies where engineering speed still matters.What this role is notThis is not a classic Head of DevOps role. This person will not run every deployment or production operations ticket, but will remain accountable for cloud architecture, security standards, and cloud risk.This is not a platform empire role. The priority is effective ownership of cloud and security, not building a large DevOps or platform organization.This is not a policy-only security role. This person must be able to inspect systems, review application and cloud architecture, challenge engineering decisions, and work with engineers until material risks are resolved.This is not a large management role. The function is expected to remain compact, initially the Head plus one engineer or analyst.What success looks likeOur most important applications have clear threat models and known risk owners.Critical vulnerabilities are found earlier and fixed faster.Cloud architecture, production access, secrets, IAM, network boundaries, and admin surfaces are controlled and reviewed.Security issues are tracked with the same seriousness as product and engineering work.Penetration tests produce fewer surprises over time.Engineering teams know what good security looks like and can apply it without waiting for a committee.Leadership has a clear view of real security risk, not a long list of low-value findings.