Senior Cyber Security Assessment Specialist
Indexed description
We believe in empowering our employees, providing them with opportunities for growth and professional development.
By Joining us, you’ll be part of a workplace culture that fosters innovation, supports work-life balance, and encourages you to reach your full potential.
Join us in shaping the future of banking!
Job Summary
The Senior Security Assessment Specialist will be a subject matter expert in all aspects of security assessment; architecture, application security, penetration testing, red teaming and vulnerability assessment. They will be the lead role in ensuring the banks level of security is assessed taking into account the current and future threat landscape, attacker tradecraft and regulatory requirements.
This role will suit an individual who has a passion to develop their own skills and knowledge in information security and security assessments; a proactive person who is a ‘hands on’ starter/finisher, that’s driven, enjoys responsibility, takes ownership of the work and is achieving results; a highly organized person with an ability to manage and prioritize workload; adept at operating effectively within an organization delivering via influence and relationships rather than all under their control.
Key Accountabilities
Penetration Testing & Red Teaming
- Design, delivery and development of Penetration Testing processes.
- Design, delivery and development of the Red Team programs and ensure they are aligned to current and future threats and attacker techniques
- Design, delivery, selection and adoption of automated tools where applicable while having the ability to write custom tooling.
- Design, delivery and development of application security processes (eg: SAST, DAST, RASP, IAST) and integrate these processes into the SDLC.
- Effectively identify information security issues, concerns, threats and vulnerabilities in the current environment in order to ensure the security of existing systems.
- Investigate the effectiveness of current security technologies, build in house tooling’s, automations and recommend vendor specific security solutions to treat or mitigate the threats and vulnerabilities.
- Assist in the configuration, enhancement, and fine-tuning of the existing application security controls and manage the deployment of security solutions.
- Conduct security architecture review by using the tools of the trade and Threat Modelling Methodologies in coordination with relevant stakeholders and participate in performing the risk management process to facilitate adherence of all operations to the defined security regulations.
- Design, delivery and development of regular external and internal vulnerability scanning
- Managing the internal Vulnrability Management Process as well as External Vulnerability Management Process.
- Assessing the vulnerabilities, performing risk assessment, risk prioritization.
- Managing technical terms and defining them into Business Terminologies to make business understand the technical as well as business risks.
- Working closely with the business as well as technical teams for the resolution of the vulnerabilities.
- Staying ahead of the Cyber Threats, 0Days, Vulnerabilities in the market to make proactive decisions for vulnerabilities remediation.
- Recommend improvements to departmental procedure and direct the implementation of instructions and controls covering a specific area of activity so that all relevant procedural/legislative requirements are fulfilled while delivering a quality, cost-effective service.
- Ensure compliance to all relevant quality, health, safety and environmental management procedures and controls within a defined area of activity to guarantee employee safety, compliance, delivery of high quality products/service and a responsible environmental attitude.
- Prepare departmental MIS statements and reports timely and accurately to meet CBQ and department requirements, policies and standards.
- Perform other related duties or assignments as directed.
- Motivate subordinates and contribute to the identification of opportunities for continuous improvement of systems, processes and practices taking into account ‘international leading practice’, improvement of business processes, cost reduction and productivity improvement.
- Bachelor’s Degree
- 5-8 years’ relevant experience
- Relevant security assessment certifications (OSCP, OSWP, PNPT, CRTP, CRTE, CPTS, CWEE, CWES, SANS Certifications etc.) – One or more is preferred.
- Web application, Infrastructure and thick/thin client penetration testing
- AI Penetration Testing (LLMs, MCPs, Agentic etc.)
- API Penetration Testing.
- Experience in performing code reviews and working with developers to remediate potential misconfigurations/vulnerabilities.
- Proficient in any automation languages i.e. Python, Bash, Golang etc.
- Effective communication, presentation and interpersonal skills.
- High computer literacy skills.
- Ability to work and adapt to change under tight deadlines to support business needs.
External: System Security Vendors
Why Commercial Bank?
- Best Digital Bank in the Middle East 2024 by World Finance and Best Mobile Banking App in the Middle East 2024 by Global Finance.
- An Innovation-Driven, Digital-First Environment where employees work with the latest tools and technologies to redefine banking
- Opportunities for Global Partnerships & International Exposure, connecting employees with global networks and perspectives.
- A focus on Employee Well-being & Work-Life Balance, ensuring a healthy and supportive environment for all team members
- Competitive Compensation & Benefits that ensure our employees are rewarded for their dedication and performance
- A strong Commitment to Diversity, Equity & Inclusion, fostering a culture that values every individual’s unique perspective.
Disclaimer
We appreciate your interest in joining CBQ! Please note that only selected candidates will be contacted for further steps in the hiring process. This job posting is for informational purposes only, and CBQ reserves the right to modify, withdraw, or close it at any time without notice.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search