Head of Security Design and Engineering
Bank Muscat · Mascate
Job description
About the role
Lead the design and engineering phase of the security‑control lifecycle, translating control objectives and minimum‑security standards into secure architectures, engineering patterns, integrated platforms and automated controls across infrastructure, applications, cloud and identity.
Key responsibilities
- Own security architecture principles, guardrails, patterns and reference architectures, and direct engineering of platform, infrastructure, cloud, application and identity security capabilities.
- Embed security into SDLC and DevSecOps, including SAST, DAST, SCA, secrets, API, container and Kubernetes security.
- Maintain security‑technology inventory, lifecycle, licensing and technical roadmap.
- Establish security‑by‑design, threat‑modelling and architecture‑review services for projects and material changes.
- Drive policy‑as‑code, orchestration and automation to improve control consistency, speed and evidence.
- Maintain operating procedures, evidence, service metrics and reporting; coordinate with IT, risk, compliance, audit and business stakeholders.
Required profile
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Engineering or related field; master’s degree advantageous.
- 10‑15 years of experience, including at least 5 years leading security architecture or engineering teams, preferably in a regulated, high‑availability or financial‑services environment.
- Strong analytical, written communication and stakeholder‑management skills in a regulated environment.
- Sound judgement, integrity and ability to handle sensitive information and high‑pressure situations.
Required skills
- Enterprise security architecture and control engineering.
- Cloud, infrastructure, application, API, container, Kubernetes, network and identity security.
- Security technology lifecycle, integration architecture, automation and engineering assurance.
- Secure SDLC, DevSecOps, threat modelling and architecture governance.
- Working knowledge of NIST Cybersecurity Framework 2.0 and ISO/IEC 27001.
- Experience with SAST, DAST, SCA, secrets management and policy‑as‑code.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Oman.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 5 days ago
Expires 1 month from now
23 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Bank Muscat
Mascate