The Staff Security Engineer, AI & Application Security is accountable for establishing the company's security engineering capability end-to-end. This role is focused on security, encompassing offensive assurance, defensive engineering, secure architecture, and technical governance across applications, APIs, cloud infrastructure, and the group's growing estate of large language models. The role exists to provide an independent view of technical risk and ensure secure delivery becomes the default approach rather than an afterthought.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Define and maintain a prioritised security roadmap for the company, assessing the current posture and setting clear objectives per period.
- Review the architecture and design of new systems to prevent security weaknesses by embedding threat modelling and defining secure design patterns.
- Act as a trusted AI security advisor to enable safe adoption of AI, providing guidance on secure patterns for LLM and agentic systems.
- Build and maintain an AI security framework and set of engineering standards to ensure repeatable and auditable secure AI deployment.
- Establish and manage the company's internal penetration testing capability, defining scope, methodology, and prioritised testing calendars.
- Own and direct independent external penetration testing, ensuring comprehensive coverage and integrating results into a remediation backlog.
- Execute technical penetration tests and red team exercises to identify vulnerabilities in production systems.
- Design AI red team exercises to test AI deployments against potential abuses, ensuring robust security measures.
- Improve application and cloud security posture through the establishment of hardening standards and automated security testing.
- Strengthen identity, access, and data protection controls to limit risk from security compromises.
- Own the technical relationship with the company's Managed Detection and Response partner to maximize protective value from the service.
- Define logging and telemetry requirements to enhance detection and incident response capabilities.
- Manage the end-to-end vulnerability lifecycle to achieve measurable risk reduction.
- Build tooling and automation for continuous security testing to scale impact with limited resources.
- Assess third-party software, AI models, and vendors to protect data and provide clear recommendations.
- Uplift the security capability of engineering teams through hands-on guidance and targeted workshops.
- Maintain documentation and metrics on security posture for leadership reporting and auditability.
Requirements
- No specific degree or certification required; a background in Computer Science or Information Security is welcome.
- Evidence of finding vulnerabilities in real systems is essential, with examples of personal discoveries and technical depth.
- 8+ years of total experience in security engineering, covering both offensive and defensive roles.
- At least 4 years of hands-on offensive experience, leading penetration tests and red team exercises.
- Demonstrable defensive engineering experience in hardening environments and designing protective controls.
- Proven experience securing AI systems in production and assessing associated vulnerabilities.
- Experience as the first or sole security hire, building functionality from the ground up.
- Track record influencing security architecture and design decisions across teams.
- Experience in security incident response within a production environment is preferred.
- Experience managing relationships with MDR or SOC providers and integrating findings into remediation processes.
- Experience in regulated industries, such as B2B, fintech, maritime, or logistics, is preferred.
Benefits
- Competitive Salary and Bonus: We reward your expertise and contributions.
- Inclusive Onboarding Experience: Our program is designed to set you up for success from day one.
- The company Wellness Zone: We value your work-life balance and well-being.
- Global Opportunities: Be part of an ambitious, expanding company with a local touch.
- Diverse, Supportive Work Culture: We’re committed to inclusion, diversity, and a sense of belonging for all team members.