OT Cybersecurity Lead at Vinci
Dubai, Dubai, United Arab Emirates -
Full Time


Start Date

Immediate

Expiry Date

16 Dec, 26

Salary

75000.0

Posted On

17 Sep, 26

Experience

10 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services

Description

Key Responsibilities


  • Lead the strategy, roadmap, and day-to-day operation of continuous cyber security control validation.
  • Direct automated testing across cloud platforms, enterprise infrastructure, AI applications, large-language-model use cases, and model supply chains.
  • Translate second-line-approved threat scenarios into a structured coverage matrix and maintain alignment with business risk.
  • Manage the ingestion of MITRE ATLAS and OWASP LLM threat intelligence, using Jira automation to meet the seven-day service-level agreement for new techniques.
  • Turn emerging attack methods into practical validation test cases and ensure they are deployed within the agreed operational timeframe.
  • Oversee the aggregation, deduplication, ownership, and lifecycle management of findings through platforms such as DefectDojo and Attestation.
  • Set severity-based remediation targets and enforce mean-time-to-remediate gates before re-deployment approval.
  • Partner with engineering, architecture, risk, and technology teams to resolve material weaknesses and improve control effectiveness.
  • Maintain Power BI reporting for open findings, remediation performance, pipeline-gate pass rates, threat coverage, and prompt-injection block rates.
  • Provide concise management information on exposure, trends, exceptions, overdue actions, and deployment assurance.
  • Establish quality standards for validation evidence, test repeatability, scenario traceability, and audit readiness.
  • Keep first-line control validation clearly separated from second-line independent red teaming, escalation, and challenge activities.


Responsibilities

Key Responsibilities


  • Lead the strategy, roadmap, and day-to-day operation of continuous cyber security control validation.
  • Direct automated testing across cloud platforms, enterprise infrastructure, AI applications, large-language-model use cases, and model supply chains.
  • Translate second-line-approved threat scenarios into a structured coverage matrix and maintain alignment with business risk.
  • Manage the ingestion of MITRE ATLAS and OWASP LLM threat intelligence, using Jira automation to meet the seven-day service-level agreement for new techniques.
  • Turn emerging attack methods into practical validation test cases and ensure they are deployed within the agreed operational timeframe.
  • Oversee the aggregation, deduplication, ownership, and lifecycle management of findings through platforms such as DefectDojo and Attestation.
  • Set severity-based remediation targets and enforce mean-time-to-remediate gates before re-deployment approval.
  • Partner with engineering, architecture, risk, and technology teams to resolve material weaknesses and improve control effectiveness.
  • Maintain Power BI reporting for open findings, remediation performance, pipeline-gate pass rates, threat coverage, and prompt-injection block rates.
  • Provide concise management information on exposure, trends, exceptions, overdue actions, and deployment assurance.
  • Establish quality standards for validation evidence, test repeatability, scenario traceability, and audit readiness.
  • Keep first-line control validation clearly separated from second-line independent red teaming, escalation, and challenge activities.


Loading...