
Head of Security Design and Engineering
At a Glance
- Category
- 💻 Technology
- Level
- C-Level
- Experience
- 10-15 years
- Type
- Full-time
Check Your CV
- See if your CV layout works for Bank Muscat
- Get every weak line rewritten
- Download a CV written for the Gulf
Free check in 60 seconds. Fixes $5.88 one-time, only if you want them.
Job Title: Head of Security Design and Engineering
Department: IT Department
Reporting to: Head of Cyber Security
Main Role: Lead the design and engineering phase of the security-control lifecycle by translating control objectives and minimum-security standards into secure architectures, engineering patterns, integrated platforms and automated controls across infrastructure, applications, cloud and identity.
Principal Duties and Responsibilities
1. Core Accountabilities
- Own security architecture principles, guardrails, patterns and reference architectures.
- Direct engineering and integration of platform, infrastructure, cloud, application and identity security capabilities.
- Embed security into SDLC and DevSecOps, including SAST, DAST, SCA, secrets, API, container and Kubernetes security.
- Maintain the security-technology inventory, lifecycle, ownership, licensing, use cases and technical roadmap.
- Establish security-by-design, threat-modelling and architecture-review services for projects and material changes.
- Drive policy-as-code, orchestration and automation to improve control consistency, speed and evidence.2. Governance Stakeholder and Reporting Responsibilities
- Maintain clear operating procedures, evidence, service metrics and management reporting for the assigned security services.
- Coordinate with IT operations, architecture, application, risk, compliance, audit and business stakeholders to resolve control gaps and delivery dependencies.
- Escalate material risks, incidents, SLA breaches and control weaknesses through the approved governance and incident-management channels.
- Support regulatory examinations, internal and external audits, risk assessments and management committees by providing accurate evidence and subject-matter input.Personnel Specification
1. Education and Experience
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline; a relevant master’s degree is advantageous.
- 10-15 years, including at least 5 years leading security architecture or engineering teams.
- Demonstrated experience in a regulated, high-availability or financial-services environment is strongly preferred.2. Technical Knowledge and Skills
- Enterprise security architecture and control engineering.
- Cloud, infrastructure, application, API, container, network and identity security.
- Security technology lifecycle, integration architecture, automation and engineering assurance.
- Secure SDLC, DevSecOps, threat modelling and architecture governance.
- Working knowledge of NIST Cybersecurity Framework 2.0, ISO/IEC 27001 and the control lifecycle from design through operation and assurance.
- Ability to translate business, regulatory and risk requirements into measurable security outcomes, procedures and service metrics.
- Strong analytical, written communication, stakeholder-management and evidence-management skills in a regulated environment.3. Operational and Behavioral Skills
- Sound judgement, integrity and the ability to handle sensitive information and high-pressure situations appropriately.
- Ability to prioritize risk, manage competing demands and deliver clear decisions, actions and escalation.
- Strong collaboration, influencing and communication skills across technical, business and executive audiences.
- Commitment to measurable service quality, continuous improvement and disciplined documentation.
- Ability to work effectively with internal teams, external suppliers, auditors and regulators.Desired Certifications
- CISSP, preferably ISSAP
- SABSA Chartered Security Architect or TOGAF
- CCSP or recognised cloud security certification
- CISM
Requirements
- •Bachelor’s degree in Information Security, Cybersecurity, Computer Science, IT, Engineering or related discipline
- •Master’s degree is advantageous
- •10-15 years of experience in cybersecurity
- •At least 5 years leading security architecture or engineering teams
- •Experience in regulated, high-availability, or financial-services environments
- •Knowledge of NIST Cybersecurity Framework 2.0 and ISO/IEC 27001
- •Strong analytical, written communication, and stakeholder-management skills
Responsibilities
- •Own security architecture principles, guardrails, patterns, and reference architectures
- •Direct engineering and integration of platform, infrastructure, cloud, application, and identity security capabilities
- •Embed security into SDLC and DevSecOps (SAST, DAST, SCA, secrets, API, container, and Kubernetes security)
- •Maintain security-technology inventory, lifecycle, ownership, licensing, and technical roadmap
- •Establish security-by-design, threat-modelling, and architecture-review services
- •Drive policy-as-code, orchestration, and automation
- •Maintain operating procedures, evidence, service metrics, and management reporting
- •Coordinate with IT operations, architecture, risk, compliance, and audit stakeholders
Related Jobs4 similar jobs
- See if your CV layout works for Bank Muscat
- Get every weak line rewritten
- Download a CV written for the Gulf
Free check in 60 seconds. Fixes $5.88 one-time, only if you want them.
Bank Muscat is the leading financial services provider in Oman. It offers corporate banking, retail banking, investment banking, and Islamic banking services to individuals and businesses.



