بازگشت به فرصت‌ها
لوگوی Bank Muscat
جدیدEnglish

Head of Security Design and Engineering

Bank Muscat·Masqaţ·امروز

حضوریارشدتمام‌وقتتوافقی

Bank Muscat

leading financial institution with a strong presence in corporate, personal, investment & islamic banking in Oman

شرح موقعیت

Job Title: Head of Security Design and Engineering Department: IT Department Reporting to: Head of Cyber Security Main Role: Lead the design and engineering phase of the security-control lifecycle by translating control objectives and minimum-security standards into secure architectures, engineering patterns, integrated platforms and automated controls across infrastructure, applications, cloud and identity. Principal Duties and Responsibilities 1. Core Accountabilities Own security architecture principles, guardrails, patterns and reference architectures. Direct engineering and integration of platform, infrastructure, cloud, application and identity security capabilities. Embed security into SDLC and DevSecOps, including SAST, DAST, SCA, secrets, API, container and Kubernetes security. Maintain the security-technology inventory, lifecycle, ownership, licensing, use cases and technical roadmap. Establish security-by-design, threat-modelling and architecture-review services for projects and material changes. Drive policy-as-code, orchestration and automation to improve control consistency, speed and evidence. 2. Governance Stakeholder and Reporting Responsibilities Maintain clear operating procedures, evidence, service metrics and management reporting for the assigned security services. Coordinate with IT operations, architecture, application, risk, compliance, audit and business stakeholders to resolve control gaps and delivery dependencies. Escalate material risks, incidents, SLA breaches and control weaknesses through the approved governance and incident-management channels. Support regulatory examinations, internal and external audits, risk assessments and management committees by providing accurate evidence and subject-matter input. Personnel Specification 1. Education and Experience Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline; a relevant master’s degree is advantageous. 10-15 years, including at least 5 years leading security architecture or engineering teams. Demonstrated experience in a regulated, high-availability or financial-services environment is strongly preferred. 2. Technical Knowledge and Skills Enterprise security architecture and control engineering. Cloud, infrastructure, application, API, container, network and identity security. Security technology lifecycle, integration architecture, automation and engineering assurance. Secure SDLC, DevSecOps, threat modelling and architecture governance. Working knowledge of NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and the control lifecycle from design through operation and assurance. Ability to translate business, regulatory and risk requirements into measurable security outcomes, procedures and service metrics. Strong analytical, written communication, stakeholder-management and evidence-management skills in a regulated environment. 3. Operational and Behavioral Skills Sound judgement, integrity and the ability to handle sensitive information and high-pressure situations appropriately. Ability to prioritize risk, manage competing demands and deliver clear decisions, actions and escalation. Strong collaboration, influencing and communication skills across technical, business and executive audiences. Commitment to measurable service quality, continuous improvement and disciplined documentation. Ability to work effectively with internal teams, external suppliers, auditors and regulators. Desired Certifications CISSP, preferably ISSAP SABSA Chartered Security Architect or TOGAF CCSP or recognised cloud security certification CISM