Manager - AI & Application Security

Bupa Arabia
جدة, جدة دوام كامل
نشر: 1448/2/26 | 2026/08/09 ينتهي: 1448/3/26 | 2026/09/08 ✨ وصف بالذكاء الاصطناعي
تقدم للوظيفة الآن

الوصف الوظيفي

About the Role

We are seeking a seasoned Manager - AI & Application Security to lead the development, implementation, and oversight of a robust security framework for both traditional applications and AI-enabled solutions across our enterprise. In this pivotal role, you will be responsible for establishing and maintaining a comprehensive Application Security and AI Security program that aligns with cybersecurity, privacy, data protection, enterprise architecture, and risk management objectives. Your expertise will be instrumental in embedding security best practices into the software development lifecycle (SDLC), ensuring that all applications—whether cloud-native, API-driven, or AI-powered—are designed, developed, and deployed with security as a foundational priority.

Key Responsibilities

1. Application & AI Security Governance

You will define and enforce security standards, control requirements, and governance processes tailored to both traditional applications and AI-enabled solutions. This includes developing secure development guidelines for APIs, cloud-native applications, and AI systems, ensuring they meet enterprise-wide security, privacy, and compliance mandates. Your role will involve collaborating with cross-functional teams to integrate security requirements seamlessly into existing frameworks while fostering a culture of security awareness across the organization.

2. Secure Design, Architecture Review & Threat Modeling

As a thought leader in security architecture, you will conduct in-depth threat modeling for business applications, APIs, cloud solutions, and AI use cases. This involves reviewing system architectures to identify vulnerabilities in authentication, authorization, session management, data flows, and integration patterns. You will assess risks specific to AI, such as prompt injection, insecure AI integrations, model misuse, data leakage, and unauthorized access to sensitive information, and recommend mitigations to address these threats proactively.

3. Secure SDLC & DevSecOps Enablement

You will embed security requirements into every phase of the SDLC, from design and development to testing, release, and production deployment. This includes advising development teams on secure software engineering practices, secure coding, API security, secrets management, dependency management, and DevSecOps methodologies. By defining security gates and promoting developer security awareness, you will ensure that security is not an afterthought but a core component of the development process.

4. Application Security Testing & Vulnerability Management

You will oversee the execution of comprehensive security testing, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), API security testing, software composition analysis, container scanning, and manual security reviews. Your responsibilities will include prioritizing vulnerabilities based on severity, exploitability, exposure, business criticality, and data sensitivity, and coordinating remediation efforts with development, infrastructure, and cybersecurity teams. Additionally, you will track the closure of security findings and validate remediation to ensure a secure go-live for all applications and AI solutions.

5. AI Security, Privacy & Data Protection Risk Assessment

You will assess AI use cases for cybersecurity, privacy, legal, regulatory, and data protection risks, evaluating data flows, training data, input/output handling, access controls, logging, retention, and sensitive data exposure. This role involves scrutinizing third-party AI services, internal AI platforms, APIs, plugins, and AI integrations to identify and mitigate risks such as prompt injection, data leakage, model misuse, and insecure outputs. You will define and implement controls to safeguard against these risks while supporting the secure adoption of AI technologies across the organization.

6. Advisory, Monitoring & Continuous Improvement

You will serve as a trusted advisor to development, infrastructure, cybersecurity, privacy, and business teams, providing expert guidance on emerging threats, vulnerabilities, and industry best practices. By monitoring the evolving threat landscape, you will ensure that the organization remains ahead of potential risks. Your role will also involve reporting on application and AI security posture, risks, remediation progress, and key metrics to senior management, driving continuous improvement in tools, processes, standards, and security review practices.

Qualifications & Skills

  • Experience: Minimum of 4 years in application security, with hands-on experience in secure SDLC, threat modeling, API security, and code review. Exposure to AI/LLM technologies through implementation, governance, or security assessments is highly desirable. Experience supporting DevSecOps environments and assessing application security risks in regulated environments is preferred.
  • Certifications: Preferred certifications include Certified Secure Software Lifecycle Professional (CSSLP), GIAC Web Application Penetration Tester (GWAPT), CISSP, or vendor-specific AI security or governance certifications (e.g., Microsoft, AWS, Google).
  • Technical Skills: Proficiency in secure software engineering, threat modeling methodologies, vulnerability assessment tools, and AI security frameworks. Strong understanding of cloud security, container security, and API security best practices.
  • Soft Skills: Exceptional communication skills with the ability to articulate complex security concepts to technical and non-technical stakeholders. A risk-based approach to decision-making and a passion for driving continuous improvement in security practices.

يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.

المصدر: لينكد إن ↗ • 3 مشاهدة

ℹ️ إخلاء مسؤولية توظيف:

موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.

وظائف مشابهة

تقدم للوظيفة الآن