Company logo hidden

Senior Security Engineer – Vulnerability Management

Unlock employer Dubai, United Arab Emirates Direct to Company 1 hour ago · 09 Oct 2026

Financial

  • Estimate: $90k - $150k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional

Position

About the Role
We're not hiring someone to run scans. We're hiring someone to build the engine that finds and closes risk before it becomes an incident. We're looking for a Tech Lead who thinks like an attacker prioritizing targets, not an analyst clearing a scan queue. This role involves owning the full vulnerability lifecycle, building AI-driven prioritization into the pipeline, and turning remediation into a measurable, automated system instead of a spreadsheet of open tickets.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

You will lead Vulnerability Management across cloud, infrastructure, endpoints, and internal environments - transforming every scan, exception, and remediation into a shorter exposure window and a more mature program. The goal isn't to keep the vulnerability count low on a dashboard; it's to make exploitable exposure structurally rare.

Why This Matters
In our mission to achieve Trading for Anyone, Anywhere, Anytime, vulnerability management becomes critical. Millions of traders depend on our platform across regulatory environments. An unpatched exposure sitting past its SLA jeopardizes a trader's funds and could alert regulators.

Vulnerability Management serves as a core defensive layer for a platform that continuously processes transactions. With new assets, cloud workloads, and code being introduced at a rapid pace, your discovery and remediation engine must keep up - which is precisely why this role exists to turn Vulnerability Management into a fully automated, intelligence-driven function.

The Challenge
Most vulnerability programs amount to a scan, a spreadsheet, and a monthly report that often goes unread until an audit arises. That won’t be the case in this role.

You will own the entire vulnerability lifecycle: discovery, enrichment, risk-based prioritization, remediation, validation, and executive reporting, spanning AWS, GCP, Azure, Kubernetes, containers, endpoints, and network infrastructure. You’ll construct automated workflows and AI-assisted prioritization that will shrink exposure windows quarter over quarter, rather than merely chasing CVSS scores in isolation.

If your idea of vulnerability management is exporting a Qualys report and emailing it to engineering, this role is not for you. If you desire to architect an automation-first vulnerability engine at a global scale and become the technical authority behind it, we encourage you to keep reading.

What You’ll Do

  • Own the full vulnerability lifecycle: discovery, enrichment, prioritization, remediation, validation, and executive reporting.
  • Lead the operation and optimization of Qualys VMDR (Cloud Agents, SCA, PCI, dashboards, tagging, scan profiles) across AWS, GCP, Azure, Kubernetes, container workloads, endpoints (macOS, Windows, Linux), and office/network infrastructure.
  • Implement risk-based prioritization using CVSS, EPSS, CISA KEV, exploit intelligence, and asset criticality; design sustainable exception management and risk acceptance governance.
  • Define and enforce remediation SLAs across engineering and IT; reduce exposure windows (MTTR) and aging vulnerabilities quarter over quarter.
  • Correlate vulnerability findings with CSPM insights, IAM exposure, and threat intelligence to prioritize exploitable and externally exposed assets.
  • Strengthen integration between vulnerability data, SIEM, EDR, and cloud-native security controls; support hardening aligned with CIS, NIST, ISO 27001, PCI-DSS, and DORA.
  • Design automated workflows for vulnerability intake, ticket creation, assignment, tracking, and remediation validation across scanning platforms, workflow tools, and internal security systems.
  • Utilize AI to enrich vulnerability context (exploitability, clustering, attack path, asset importance) and implement secure automated patching where technically validated and risk-appropriate.
  • Act as the bridge between Global Security Operations and local IT/Engineering, aligning vulnerability data with detection engineering and blue team strategy.
  • Serve as the technical authority for Vulnerability Management in Cyberjaya, mentoring analysts in risk-based triage and exploit analysis; represent the function during audits and architecture reviews.

Who You Are

  • 8-12+ years of cybersecurity experience with deep specialization in vulnerability management.
  • Expert-level experience with Qualys VMDR or equivalent (Tenable, Rapid7).
  • Strong understanding of exploit intelligence, risk scoring models, and vulnerability lifecycle governance.
  • Hands-on experience across cloud security (AWS, GCP, Azure), CSPM integrations, endpoint patching and configuration management, and SIEM/EDR correlation.
  • Strong automation capability: Python, Bash, API integrations, workflow automation.
  • Experience implementing AI-assisted prioritization or remediation workflows.
  • Proven ability to build dashboards and KPIs that influence executive decisions.
  • Experience operating in regulated environments (ISO 27001, GDPR, PCI-DSS, DORA).
  • Strong communicator able to translate technical exposure into business risk.

The Honest Reality
This is a hands-on leadership role for someone who builds systems, not just processes. You will be raising findings and SLA breaches that may not always be welcomed, and you will be accountable for exposure windows in a regulated environment where a missed patch cycle is not trivial.

However, you will enjoy high ownership and strategic influence within a global fintech security organization, the opportunity to architect automation-first vulnerability management at scale, and a direct impact on enterprise risk reduction as part of a competitive compensation package and a long-term leadership growth path.

If you want to run scans and forward reports, this isn't the opportunity for you. If you want to build the vulnerability engine that makes exploitable exposure the exception rather than the norm, this could be the perfect fit.

Apply Direct

Jobs you might like   View all jobs

About Financial Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct