Job matched to your search
Senior Manager – Cyber Security Engineer
TAT IT Technolgies · Abu Dhabi
Free · Join 5,000+ job seekers using Qarera
How well do you match this role?
Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.
Job description
We have an urgent requirement for Senior Manager – Cyber Security Engineer with experience in banking domain is required for our clients in Abu Dhabi ,UAE Strong Experience On AI/LLM Model And Supply Chain Model Strong experience on AWS Security Agent (cloud/infra) Strong experience in AI/LLM Security & Red Teaming – prompt injection, model attacks, OWASP LLM + MITRE ATLAS exposure.-- -Must Strong experience Garak, PyRIT, Claude Security / Opus 4.x, Codex, 1LoD/2LoD Strong experience in Threat Intel to Test Engineering – convert MITRE/OWASP intel into automated attack test cases within strict SLAs --- Must Role Purpose Lead the organisation’s transition from periodic, manual penetration testing to continuous, automated adversarial security validation across cloud infrastructure, applications, AI/LLM systems, and model supply chains. The role will own continuous control validation, threat-informed security testing, vulnerability orchestration, and remediation governance while maintaining a clear 1LoD/2LoD operating model.
Key Responsibilities
- Continuous Security Validation
- Design and operate continuous security validation across AWS cloud/infrastructure, applications, AI/LLM workloads, and model supply chains.
- Integrate autonomous security testing tools such as AWS Security Agent, Horizon3.ai, or equivalent platforms into CI/CD pipelines.
- Execute automated adversarial tests against significant deployments based on a 2LoD-approved threat coverage matrix.
- Establish automated security gates to prevent deployment where critical security controls fail.
- Threat Intelligence & Adversarial Testing
- Own the 7-day threat-intelligence operationalisation SLA.
- Monitor MITRE ATLAS, OWASP LLM Top 10, and other relevant threat-intelligence sources.
- Use Jira automation and security engineering workflows to translate emerging attack techniques into repeatable security test cases within seven days.
- Develop and maintain adversarial test scenarios covering cloud, application, AI/LLM, prompt-injection, model-abuse, and model-supply-chain risks.
- AI / LLM Security & Red Teaming
- Lead continuous AI security validation using tools such as Garak, PyRIT, Claude Security/Opus 4.x, Codex, or equivalent platforms.
- Design tests for prompt injection, jailbreaks, data leakage, excessive agency, insecure tool use, model manipulation, and supply-chain risks.
- Continuously measure and improve Prompt Injection Block Rate and other AI security control effectiveness metrics.
- Vulnerability & Finding Management
- Aggregate, deduplicate, prioritise, and SLA-manage security findings through DefectDojo.
- Establish severity-based MTTR remediation gates and ensure remediation evidence is validated before re-deployment approval.
- Drive end-to-end finding lifecycle management from discovery through remediation, validation, attestation, and closure.
- Security Metrics & Governance
- Develop executive-level Power BI dashboards covering:
- Open Findings
- MTTR
- Pipeline Gate Pass Rate
- Prompt Injection Block Rate
- Security Control Effectiveness
- Threat Coverage
- Remediation SLA Compliance
- Provide management-level reporting on security posture, control effectiveness, emerging threats, and remediation performance.
- 1LoD / 2LoD Operating Model
- Maintain a clear separation between 1LoD control validation and independent 2LoD security assurance/red teaming.
- Execute blue-team control validation against 2LoD-approved threat scenarios and test coverage.
- Ensure independent unknown-scenario testing remains within the 2LoD remit to preserve appropriate challenge and assurance independence.
Required Technical Expertise
- Strong experience in offensive security, penetration testing, adversarial simulation, blue-team validation, and continuous security validation.
- Proven experience transitioning organisations from periodic manual penetration testing to automated/continuous security control validation.
- Hands-on experience with autonomous penetration-testing platforms such as AWS Security Agent, Horizon3.ai, or equivalent.
- Strong expertise in AI/LLM security and AI red teaming, including Garak, PyRIT, Claude Security/Opus, Codex, or comparable tooling.
- Strong knowledge of OWASP LLM Top 10 and MITRE ATLAS.
- Experience integrating security validation into CI/CD and DevSecOps pipelines.
- Experience with DefectDojo, Jira automation, vulnerability management, security metrics, and Power BI.
- Strong understanding of cloud security, AWS security controls, application security, threat modelling, and adversarial testing.
- Strong understanding of 1LoD/2LoD governance, control validation, independent assurance, and security risk management.
Skills: manager,security,cybersecurity
More jobs in Abu Dhabi
Browse related jobs
Don’t just read the job — see if you’ll get it.
Get your match score, a resume tailored to this exact role, and jobs like it — free.
Check my fit for this job