Security Architect — Integration Platform Security & Compliance
Birbal AI · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates
Apply & track with Apply EdgeKey responsibilities
- Produce the security low-level design and the SIEM (Microsoft Sentinel) log-source and integration specification; obtain approval from the client’s security function.
- Own third-party risk management (TPRM) questionnaires and evidence packs; maintain ISO/IEC 27001- aligned control statements and compliance mappings to the client’s cyber-security standards.
- Design identity and access: Entra ID SSO (SAML 2.0/OIDC), SCIM 2.0 provisioning, RBAC and entity scoping, privileged-access approval and logging, MFA and conditional access.
- Define encryption in transit and at rest (TLS 1.2+, mutual TLS), message-level signing (JWS/XML-DSig), customer-managed keys and key custody, secrets vaulting and credential rotation.
- Embed secure SDLC: threat modelling, SAST/DAST, dependency, secret and image scanning, pipeline security gates; structured input validation, rate limiting and abuse detection for APIs.
- Run internal security assessments; coordinate the client’s VAPT before each production deployment and drive remediation or formal risk acceptance of High/Critical findings.
- Own the incident-response and breach-notification protocol (24-hour notification, major incident report, RCA), the support-access control procedure and audit evidence. Required experience and skills
- 10+ years in information security with 4+ years as security architect for cloud-hosted enterprise applications or integration platforms.
- Hands-on with Azure security services, Microsoft Entra ID, Sentinel/SIEM integration, Key Vault/HSM, API security (OAuth 2.0, OIDC, mTLS, JWS) and Kubernetes/container security.
- Experience passing large-enterprise TPRM / vendor security assessments and VAPT cycles; working knowledge of ISO/IEC 27001, SOC 2 and OWASP API Security Top 10.
- Knowledge of UAE data-protection, data-residency and tax-record retention requirements.
- CISSP, CCSP, CISM or Microsoft Azure Security Engineer certification. Nice to have
- SOC operations or detection-engineering experience.
- Experience securing regulated financial-data or tax platforms.