Overview
Information Security Engineer - penetration testing, DevSecOps practices, cloud security (AWS & Azure), and security architecture. Urgent requirement for banking experience in Abu Dhabi, UAE.
Responsibilities
- Perform penetration testing of web applications, mobile applications, and APIs.
- Perform secure code reviews to identify vulnerabilities in application code, scripts, and configurations.
- Configure, fine-tune, and review results from SAST, DAST, IaC, container, and dependency scanning tools.
- Drive DevSecOps initiatives, including security integration in CI / CD pipelines.
- Review and enhance Kubernetes security, container security, and infrastructure security.
- Contribute to security architecture design and reviews for applications, infrastructure, and cloud.
- Conduct threat modeling, risk assessments, and vulnerability management.
- Establish and deliver security training, awareness sessions, and best practices to teams.
- Collaborate with development, DevOps, and infrastructure teams to ensure secure design and delivery.
- Act as a security advisor to stakeholders, explaining risks and recommendations in simple, non-technical terms.
- Participate in incident response and post-incident reviews, ensuring lessons learned are applied.
- Stay updated on emerging threats, attack techniques, and new security technologies.
Qualifications
- 7-10 years of proven expertise in application, infrastructure, and cloud security.
- Hands-on experience in penetration testing (web, mobile, API).
- Strong experience in DevSecOps practices, cloud security (AWS & Azure), and security architecture.
- Experience configuring and reviewing security scanning (SAST, DAST, IaC, container, dependencies).
- Ability to drive security in a banking environment and communicate risks to stakeholders.
Experience and Employment Details
- Seniority level : Mid-Senior level
- Employment type : Contract
- Location : Abu Dhabi, United Arab Emirates
This description reflects the requirements and responsibilities as provided and does not include any external postings or unrelated content.