Lead Security Engineer
CNTXT AI · Abu Dhabi Emirate, United Arab Emirates
قدّم وتابع مع أبلاي إيدجSecurity Lead Engineer Company: CNTXTLocation: Onsite, UAEType: Full-timeReports to: CTO / VP EngineeringAbout CNTXT CNTXT is a high-growth technology scale-up building at the intersection of engineering, AI, and data. As our platforms, customer base, and cloud footprint expand, security becomes a first-class engineering discipline foundational to everything we ship.About the Role This is a hands-on, high-ownership role: you will be the first dedicated security hire and the single point of accountability for cybersecurity across CNTXT from application and cloud infrastructure security to endpoint protection, identity and access. You will define the security strategy, then roll up your sleeves and implement it: writing policies and Terraform in the same week, running a pentest one day and briefing leadership the next.As CNTXT grows, you will have the opportunity to build and lead a security team around the foundations you put in place.What You'll Own Security Strategy & Governance • Define and drive CNTXT's overall security roadmap, risk register, and security policies aligned to business and product priorities• Establish a pragmatic, engineering-friendly security culture security that enables shipping, not blocks itApplication & Code Security • Secure the SDLC end to end: threat modeling, secure code review practices, dependency and supply-chain scanning (SCA), SAST/DAST in CI/CD• Protect the codebase and developer environments against compromise — repository access controls, branch protection, signed commits, secrets scanningCloud & Infrastructure Security • Harden cloud environments (GCP / AWS / Azure): network segmentation, workload identity, security groups, WAF, and infrastructure-as-code guardrails• Implement DDoS protection and edge security (CDN/WAF, rate limiting, traffic anomaly detection)• Own container and Kubernetes security, image scanning, and runtime protection• Establish logging, monitoring, and alerting (SIEM/SOAR) with actionable detection rulesIdentity, Access & Secrets Management• Design and enforce IAM across cloud, SaaS, and internal systems — SSO, MFA, least privilege, role based access, and periodic access reviews• Implement secrets and key management (e.g., Vault, cloud KMS): rotation, encryption at rest and in transit, and elimination of hard-coded credentialsEndpoint & Corporate Security • Deploy and manage endpoint protection (EDR/XDR), device management (MDM), and disk encryption across employee devicesVulnerability Management & Offensive Testing • Own the vulnerability management lifecycle: continuous scanning, prioritization, remediation SLAs• Plan and conduct VA/PT (vulnerability assessments and penetration tests) internally, and manage external pentest and red-team engagementsIncident Response & Resilience • Build and own the incident response plan: detection, triage, containment, forensics, and post incident reviews• Establish backup, disaster recovery, and business continuity practices for critical systemsData & AI Security • Secure data pipelines, data stores, and ML/AI workloads — data classification, encryption, access controls, and privacy-by-design• Assess and mitigate AI-specific risks: model and prompt injection, training-data leakage, third party AI/API exposureWhat We're Looking For Must-have • 7–10+ years in security engineering, with at least 2–3 years in a lead or ownership role — ideally as an early/first security hire at a startup or scale-up• Deep hands-on experience across at least three of: cloud security, application security, IAM, offensive security (VA/PT), incident response• Strong cloud security expertise on GCP, AWS, or Azure (multi-cloud a plus), including Kubernetes and infrastructure-as-code (Terraform)• Practical experience implementing DDoS mitigation, WAF, SIEM, EDR, and secrets management tooling• Proficiency in scripting/automation (Python, Go, or Bash) — you automate before you administer • Ability to communicate risk clearly to both engineers and executives, in a fast-moving environment with limited resourcesNice-to-have • Certifications such as OSCP, CISSP, CCSP, CISM, or cloud security specialty certsWhy This Role Greenfield ownership — you define security at CNTXT from the ground up, with executive backingBreadth and impact — your decisions shape the security of AI and data products used at scale • -Growth path — clear trajectory to Head of Security / CISO as the team grows around you • Competitive compensation, relocation support to the UAE, and the chance to build in one of the region's fastest-growing tech ecosystems