About Us
Established in Abu Dhabi in 1985, our client provides personal and business banking services across retail banking, wealth management, commercial banking, corporate finance, investment banking and cash management. Its broad financial services platform supports customers and institutions through a complex, highly regulated operating environment where resilient technology, secure digital delivery and disciplined risk management are essential. The organisation continues to depend on strong cybersecurity practices to protect information, enable innovation and maintain regulatory confidence across its banking operations.
Job Description
The Executive Manager will lead the technical delivery of a cybersecurity squad responsible for strengthening application security, AI governance, continuous security validation and compliance evidence across a major banking environment. This role combines strategic direction with technical oversight, translating approved security policies into practical controls, measurable service levels and reliable delivery outcomes.
Success will involve creating a coherent operating model across DevSecOps, cloud security, AI and LLM security, governance and assurance. The position will also oversee the cybersecurity tooling ecosystem, guide integration and vendor-consolidation decisions, and ensure that evidence can be traced from identified defects through remediation, attestation and executive reporting. As a first-line-of-defence leader, you will work closely with second-line risk stakeholders and the AI centre of excellence while providing clear prioritisation, governance and technical leadership to the squad.
Based in Abu Dhabi, the role carries visible accountability for regulatory readiness, delivery quality and stakeholder confidence. Strong performance will be demonstrated through effective execution across multiple workstreams, credible assurance evidence, improved control maturity and transparent reporting through the monthly DevSecOps Governance Dashboard.
Key Responsibilities
- Set the technical direction and delivery priorities for application security, AI governance, continuous security validation and compliance-trail workstreams.
- Convert approved second-line policies into operational controls, measurable service-level outcomes and repeatable delivery practices.
- Maintain ongoing readiness for supervisory review, including evidence quality, control traceability and timely remediation of identified gaps.
- Own the architecture, performance and lifecycle of the consolidated cybersecurity tooling environment, including SonarQube, Snyk, ServiceNow IRM, Security Agent, Claude, Codex, OPA, Microsoft Defender for Cloud and AWS Security Hub where relevant.
- Evaluate vendor consolidation opportunities and define integration patterns that improve visibility, efficiency and control consistency.
- Design and manage the evidence flow from DefectDojo through attestation and into Power BI governance reporting.
- Serve as the first-line-of-defence technical counterpart to second-line risk, assurance teams and the AI centre of excellence.
- Lead the Security Champions Guild, strengthening secure engineering awareness and adoption across delivery teams.
- Resolve competing demands across the squad and make prioritisation decisions aligned with risk, regulatory obligations and business impact.
- Present the monthly DevSecOps Governance Dashboard, explaining trends, exceptions, remediation progress and emerging risks to senior stakeholders.
Requirements
- Substantial experience leading cybersecurity engineering, security architecture or comparable technical security functions.
- Strong practical command of DevSecOps, secure software delivery and security engineering across Azure and AWS environments.
- Demonstrable expertise in AI security, LLM security, AI governance or the implementation of controls for emerging technologies.
- Professional experience within banking, financial services or another closely regulated industry.
- Working knowledge of CBUAE Decree-Law 6/2025, the Enabling Technologies Guidelines and the AI/ML Guidance Note, with evidence of applying relevant requirements in practice.
- Familiarity with the NIST AI Risk Management Framework and ISO/IEC 42001, including their implications for governance, risk and control design.
- Experience operating effectively within a three-lines-of-defence model and delivering controls from a first-line-of-defence mandate.
- Confidence engaging second-line stakeholders on policy interpretation, risk acceptance, assurance activity, independent testing and remediation evidence.
Benefits
- A senior leadership mandate with direct influence over cybersecurity engineering, AI governance and technology-control maturity within a diversified banking institution.
- Exposure to complex regulatory, cloud, application-security and emerging-technology challenges across personal and business banking operations.
- The opportunity to shape tooling strategy, evidence architecture and governance reporting rather than managing isolated security activities.
- Meaningful visibility with senior risk, technology and assurance stakeholders through structured governance and executive reporting.
- Access to enterprise security platforms and a broad technical environment spanning DevSecOps, Azure, AWS, AI governance and compliance automation.
- Professional development through ownership of high-impact security transformation and regulatory-readiness initiatives.
- A competitive package aligned with the scope, accountability and seniority of the position.
- A central Abu Dhabi location within an established financial institution serving a wide range of customers and corporate stakeholders.
Other
This appointment suits a technically credible security leader who can move comfortably between engineering detail, governance requirements and executive decision-making. The successful candidate will be expected to establish clarity across competing priorities, strengthen the connection between control design and operational evidence, and build confidence in the organisation’s ability to manage cyber and AI-related risk.
Applications are particularly relevant from professionals who have delivered comparable outcomes in regulated banking, financial services, government or other environments with demanding assurance expectations. Experience should demonstrate not only subject-matter knowledge, but also the ability to make controls work consistently at scale.
Charlie Day
Recruitment Consultant
ETail Specialist
- charlie.day@forsythbarnes.com
My Other Roles
- Senior Manager - Cyber Security Engineers (Ref: 197823)
Abu Dhabi, United Arab Emirates
- Senior Manager - AI Security Product Owner (Ref: 197825)
Abu Dhabi, United Arab Emirates
- Principal Security Engineer (Ref: 197828)
Abu Dhabi, United Arab Emirates
- Agentic AI Developer (Ref: 197687)
Dubai, United Arab Emirates