About the Role
As the Head of Security Design and Engineering, you will lead the design and engineering phase of the security-control lifecycle. This role involves translating control objectives and minimum-security standards into secure architectures, engineering patterns, integrated platforms, and automated controls across diverse environments, including infrastructure, applications, cloud, and identity.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Principal Duties and Responsibilities
1. Core Accountabilities
- Own security architecture principles, guardrails, patterns, and reference architectures.
- Direct engineering and integration of platform, infrastructure, cloud, application, and identity security capabilities.
- Embed security into SDLC and DevSecOps, including SAST, DAST, SCA, secrets, API, container, and Kubernetes security.
- Maintain the security-technology inventory, lifecycle, ownership, licensing, use cases, and technical roadmap.
- Establish security-by-design, threat-modelling, and architecture-review services for projects and material changes.
- Drive policy-as-code, orchestration, and automation to improve control consistency, speed, and evidence.
2. Governance Stakeholder and Reporting Responsibilities
- Maintain clear operating procedures, evidence, service metrics, and management reporting for the assigned security services.
- Coordinate with IT operations, architecture, application, risk, compliance, audit, and business stakeholders to resolve control gaps and delivery dependencies.
- Escalate material risks, incidents, SLA breaches, and control weaknesses through the approved governance and incident-management channels.
- Support regulatory examinations, internal and external audits, risk assessments, and management committees by providing accurate evidence and subject-matter input.
Personnel Specification
1. Education and Experience
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline; a relevant master’s degree is advantageous.
- 10-15 years of experience, including at least 5 years leading security architecture or engineering teams.
- Demonstrated experience in a regulated, high-availability, or financial-services environment is strongly preferred.
2. Technical Knowledge and Skills
- Enterprise security architecture and control engineering.
- Cloud, infrastructure, application, API, container, network, and identity security.
- Security technology lifecycle, integration architecture, automation, and engineering assurance.
- Secure SDLC, DevSecOps, threat modelling, and architecture governance.
- Working knowledge of NIST Cybersecurity Framework 2.0, ISO/IEC 27001, and the control lifecycle from design through operation and assurance.
- Ability to translate business, regulatory, and risk requirements into measurable security outcomes, procedures, and service metrics.
- Strong analytical, written communication, stakeholder-management, and evidence-management skills in a regulated environment.
3. Operational and Behavioral Skills
- Sound judgement, integrity, and the ability to handle sensitive information and high-pressure situations appropriately.
- Ability to prioritize risk, manage competing demands, and deliver clear decisions, actions, and escalation.
- Strong collaboration, influencing, and communication skills across technical, business, and executive audiences.
- Commitment to measurable service quality, continuous improvement, and disciplined documentation.
- Ability to work effectively with internal teams, external suppliers, auditors, and regulators.
Desired Certifications
- CISSP, preferably ISSAP
- SABSA Chartered Security Architect or TOGAF
- CCSP or recognized cloud security certification
- CISM