Digital Zone

Staff Security Engineer

Digital Zone

United Arab Emirates · Full Time

Be the first to apply

Experience
8+ yrs
Salary
Openings
1
Posted
8 કલાક પેહલા
Work mode
In office
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Role Overview

As the lead technical authority for security at DigitalZone, you will drive the security strategy across the platform, covering application security, cloud infrastructure, and critical flows like payment and identity management. This senior individual contributor role demands ownership of complex challenges, performing hands-on work, and elevating security standards across the engineering teams. Beyond identifying issues, you will actively engage in coding, tooling development, and direct remediation efforts.

Key Responsibilities

  • Develop and refine a secure Software Development Life Cycle (SDLC) to support engineers in identifying and addressing security vulnerabilities efficiently.
  • Enhance application security through the use of deterministic methods and large language model (LLM) assisted automation for vulnerability detection and resolution in codebases.
  • Architect and implement supply chain security measures to address risks associated with third-party dependencies, including ensuring feature and release integrity.
  • Design scalable infrastructure and cloud security solutions that detect and remediate vulnerabilities within containerized and cloud environments, incorporating scanning, signing, admission control, and runtime protections.
  • Manage vulnerability assessment processes, conduct penetration tests, and maintain metrics to monitor security posture.
  • Establish secure-by-design standards and criteria for authentication and authorization mechanisms, cloud network configurations, secrets management, and identity and access management (IAM).
  • Serve as the chief intermediary between customers and security vendors, facilitating alignment on findings, prioritizing remediation actions, managing risk acceptance, and advancing strategic security objectives.

Candidate Profile

  • Possess a minimum of eight years’ experience in software or security engineering, with comprehensive hands-on expertise in application, cloud/infrastructure security, and incident detection and response.
  • Demonstrate a solid history of threat modeling and safeguarding systems that process payments, sensitive financial information, or personal identifiable information (PII).
  • Exhibit strong software engineering foundations, including proficiency in AWS security practices, modern authentication and authorization methods, and expertise in at least one primary programming language used within the company.
  • Have working knowledge of security frameworks and standards such as PCI DSS, ISO 27001, OWASP, and SOC 2, with experience operationalizing them efficiently to avoid hindering delivery timelines.
  • Apply sound judgment to balance risk trade-offs and communicate clearly, directly, and practically with both engineers and senior leadership.

Benefits and Advantages

  • Opportunity to impact a fast-growing enterprise on a large scale immediately.
  • Competitive compensation packages at the top of the market.
  • Collaborate with esteemed regional professionals from leading companies like Talabat, Careem, and Etisalat.

Level

Mid

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help