Senior Manager – Cyber Security Engineer
TAT IT Technolgies · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates
Apply & track with Apply EdgeWe have an urgent requirement for Senior Manager – Cyber Security Engineer with experience in banking domain is required for our clients in Abu Dhabi ,UAEStrong Experience On AI/LLM Model And Supply Chain ModelStrong experience on AWS Security Agent (cloud/infra)Strong experience in AI/LLM Security & Red Teaming – prompt injection, model attacks, OWASP LLM + MITRE ATLAS exposure.---MustStrong experience Garak, PyRIT, Claude Security / Opus 4.x, Codex, 1LoD/2LoDStrong experience in Threat Intel to Test Engineering – convert MITRE/OWASP intel into automated attack test cases within strict SLAs ---MustRole PurposeLead the organisation’s transition from periodic, manual penetration testing to continuous, automated adversarial security validation across cloud infrastructure, applications, AI/LLM systems, and model supply chains. The role will own continuous control validation, threat-informed security testing, vulnerability orchestration, and remediation governance while maintaining a clear 1LoD/2LoD operating model.Key ResponsibilitiesContinuous Security ValidationDesign and operate continuous security validation across AWS cloud/infrastructure, applications, AI/LLM workloads, and model supply chains.Integrate autonomous security testing tools such as AWS Security Agent, Horizon3.ai, or equivalent platforms into CI/CD pipelines.Execute automated adversarial tests against significant deployments based on a 2LoD-approved threat coverage matrix.Establish automated security gates to prevent deployment where critical security controls fail.Threat Intelligence & Adversarial TestingOwn the 7-day threat-intelligence operationalisation SLA.Monitor MITRE ATLAS, OWASP LLM Top 10, and other relevant threat-intelligence sources.Use Jira automation and security engineering workflows to translate emerging attack techniques into repeatable security test cases within seven days.Develop and maintain adversarial test scenarios covering cloud, application, AI/LLM, prompt-injection, model-abuse, and model-supply-chain risks.AI / LLM Security & Red TeamingLead continuous AI security validation using tools such as Garak, PyRIT, Claude Security/Opus 4.x, Codex, or equivalent platforms.Design tests for prompt injection, jailbreaks, data leakage, excessive agency, insecure tool use, model manipulation, and supply-chain risks.Continuously measure and improve Prompt Injection Block Rate and other AI security control effectiveness metrics.Vulnerability & Finding ManagementAggregate, deduplicate, prioritise, and SLA-manage security findings through DefectDojo.Establish severity-based MTTR remediation gates and ensure remediation evidence is validated before re-deployment approval.Drive end-to-end finding lifecycle management from discovery through remediation, validation, attestation, and closure.Security Metrics & GovernanceDevelop executive-level Power BI dashboards covering:Open FindingsMTTRPipeline Gate Pass RatePrompt Injection Block RateSecurity Control EffectivenessThreat CoverageRemediation SLA ComplianceProvide management-level reporting on security posture, control effectiveness, emerging threats, and remediation performance.1LoD / 2LoD Operating ModelMaintain a clear separation between 1LoD control validation and independent 2LoD security assurance/red teaming.Execute blue-team control validation against 2LoD-approved threat scenarios and test coverage.Ensure independent unknown-scenario testing remains within the 2LoD remit to preserve appropriate challenge and assurance independence.Required Technical ExpertiseStrong experience in offensive security, penetration testing, adversarial simulation, blue-team validation, and continuous security validation.Proven experience transitioning organisations from periodic manual penetration testing to automated/continuous security control validation.Hands-on experience with autonomous penetration-testing platforms such as AWS Security Agent, Horizon3.ai, or equivalent.Strong expertise in AI/LLM security and AI red teaming, including Garak, PyRIT, Claude Security/Opus, Codex, or comparable tooling.Strong knowledge of OWASP LLM Top 10 and MITRE ATLAS.Experience integrating security validation into CI/CD and DevSecOps pipelines.Experience with DefectDojo, Jira automation, vulnerability management, security metrics, and Power BI.Strong understanding of cloud security, AWS security controls, application security, threat modelling, and adversarial testing.Strong understanding of 1LoD/2LoD governance, control validation, independent assurance, and security risk management.Skills: manager,security,cybersecurity