Manager - AI & Application Security

Bupa Arabia

Saudi Arabia

On-site

SAR 260,000 - 360,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bupa Arabia is seeking an experienced security leader to govern Application and AI security across enterprise systems. You will define standards, oversee secure software practices, and drive threat modelling and risk-based decisions.

The role blends governance with hands-on secure SDLC enablement, demanding collaboration with cyber, privacy, and engineering teams to protect sensitive data while enabling AI innovation.

Qualifications

  • Bachelor’s degree in computer science, Software Engineering, Cybersecurity, or related field.
  • 4+ years of relevant experience.
  • CSSLP, GWAPT, CISSP, or vendor AI security certifications preferred.
  • Experience with securing APIs and DevSecOps.

Responsibilities

  • Establish and maintain the Application Security and AI Security program.
  • Define security standards, control requirements, and governance for apps and AI-enabled solutions.
  • Align security with cybersecurity, privacy, data protection, enterprise architecture, and risk management.
  • Maintain secure development guidelines for traditional apps, APIs, cloud-native apps, and AI solutions.
  • Perform threat modelling for applications, APIs, cloud apps, and AI workflows.
  • Review architectures to identify security design weaknesses; assess authentication, authorization, data flows.
  • Identify risks such as prompt injection, data leakage, model misuse, unauthorized access.
  • Embed security requirements across SDLC and promote DevSecOps.

Skills

Communication skills
Risk based approach
Secure SDLC
Threat modelling
APIs security
Source code review
AI/LLM security
DevSecOps
Regulated environments experience
CSSLP
GWAPT
CISSP
AI governance certifications

Education

Bachelor’s degree in Computer Science
Software Engineering
Cybersecurity
Related field

Job description

Job Description

To manage application and AI security across enterprise systems and AI-enabled solutions.

Job Description

To manage application and AI security across enterprise systems and AI-enabled solutions.

1 - Application & AI Security Governance:
  • Establish and maintain the Application Security and AI Security program.
  • Define security standards, control requirements, and governance processes for applications and AI-enabled solutions.
  • Align application and AI security practices with cybersecurity, privacy, data protection, enterprise architecture, and risk management requirements.
  • Maintain secure development guidelines for traditional applications, APIs, cloud-native applications, and AI solutions.
2 - Secure Design, Architecture Review & Threat Modeling:
  • Conduct threat modelling for business applications, APIs, cloud applications, AI use cases, and AI-enabled workflows.
  • Review application and AI solution architectures to identify security design weaknesses.

Assess authentication, authorization, session management, data flows, integration patterns, and trust boundaries.

  • Identify risks such as prompt injection, insecure AI integrations, model misuse, excessive agency, data leakage, and unauthorized access to sensitive information.
3 - Secure SDLC & DevSecOps Enablement:
  • Embed application and AI security requirements across design, development, testing, release, and production deployment stages.
  • Advise development teams on secure software engineering, secure coding, API security, secrets management, dependency management, and DevSecOps practices.
  • Define security gates before production deployment for applications and AI solutions.

Promote developer security awareness and practical secure coding practices.

4 - Application Security Testing & Vulnerability Management:
  • Manage and review findings from SAST, DAST, API security testing, software composition analysis, container scanning, and manual security reviews.
  • Prioritize vulnerabilities based on severity, exploitability, exposure, business criticality, and data sensitivity.
  • Coordinate remediation with development, infrastructure, application owners, and cybersecurity teams.
  • Track closure of security findings and validate remediation before release or production go-live.
5 - AI Security, Privacy & Data Protection Risk Assessment:
  • Assess AI use cases for cybersecurity, privacy, legal, regulatory, and data protection risks.

Review AI-related data flows, training data, input/output handling, access controls, logging, retention, and sensitive data exposure risks.

  • Evaluate third-party AI services, internal AI platforms, APIs, plugins, and AI integrations with enterprise systems from cybersecurity perspective
  • Define controls for prompt injection, data leakage, model misuse, insecure outputs, unauthorized data access, and AI-assisted software vulnerabilities.
6 - Advisory, Monitoring & Continuous Improvement:
  • Monitor emerging application security and AI security threats, vulnerabilities, attack techniques, and industry best practices.
  • Provide expert advisory to development, infrastructure, cybersecurity, privacy, and business teams.
  • Support secure adoption of AI technologies across the organization while enabling innovation safely.
  • Report application and AI security posture, risks, remediation progress, and key metrics to management.
  • Continuously improve tools, processes, standards, and security review practices.
Skills
  • Communication skills
  • Risk based approach.
  • Experience with Secure SDLC.
  • Experience performing threat modelling.
  • Experience securing APIs.
  • Experience reviewing source code.
  • Exposure to AI/LLM technologies, either through implementation, governance, or security assessments.
  • Experience supporting DevSecOps environments.
  • Experience assessing application security risks in regulated environments is preferred
  • Certified Secure Software Lifecycle Professional (CSSLP) preferred
  • GIAC Web Application Penetration Tester (GWAPT) preferred
  • CISSP preferred
  • Vendor AI security or AI governance certifications (Microsoft, AWS, google, or equivalent)

4+ years of relevant experience

Education

Bachelor’s degree in computer science, Software Engineering, Cybersecurity, or related field.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Practical DevSecOps • Al Khobar

On-site
SAR 90,000 - 120,000
Application & Security Architecture Consultant
Application & Security Architecture Consultant

Paramount Computer Systems Co • Saudi Arabia

On-site
SAR 180,000 - 300,000
Digital Identity & Security Access Management Specialist
Digital Identity & Security Access Management Specialist

Accenture Middle East • Riyadh

On-site
SAR 180,000 - 240,000
AI Solutions Architect
AI Solutions Architect

JODAYN | جودين • Riyadh

On-site
SAR 300,000 - 400,000
Application Security Engineer
Application Security Engineer

Practical DevSecOps • Saudi Arabia

On-site
SAR 150,000 - 200,000
Manager - Technology Consulting - Cybersecurity - AI Security - Riyadh
Manager - Technology Consulting - Cybersecurity - AI Security - Riyadh

EY • Riyadh

On-site
SAR 420,000 - 660,000
Manager - IT Security Delivery
Manager - IT Security Delivery

Qiddiya | القدية • Riyadh

On-site
SAR 260,000 - 360,000
Manager - IT Security Delivery
Manager - IT Security Delivery

Qiddiya • Riyadh

On-site
SAR 240,000 - 360,000
Manager - IT Security Delivery
Manager - IT Security Delivery

Qiddiya Investment Company • Riyadh

On-site
SAR 300,000 - 480,000
AI Architecture Manager
AI Architecture Manager

Accenture Middle East • Saudi Arabia

On-site
SAR 450,000 - 750,000