More stories

  • in

    Application security Consultant: | Almawarid Group

    Employment:

    Full Time

    The systems security development specialist is responsible for evaluating the security of the software and applications. He/she should be involved in the complete software development lifecycle.• Determine the required security controls. • Assist in software design reviews. • Identify functional and/or performance test cases. • Conduct a risk assessment when a system, software or application undergoes a change. • Conduct secure code reviews. • Identify and implement security mechanisms to resolve issues in software development. • Perform software quality assurance testing. • Implement security measures for solving issues identified during software acceptance phase. • Conduct vulnerability assessment activities prior to deploying the application. • Evaluate and communicate the software testing results with the design team and stakeholders. • Develop documentation for software programming and development, and secure software / system testing and validation. • Develop and implement an application security program across the organization with periodic reviews to assess effectiveness. • Develop secure coding standards and procedures, derived from leading security practices and industry standards, across all platforms. • Develop a process for project risk rating to drive and inform SDLC rigor (e.g. threat modelling), which will be part of the SDLC process. • Conduct security assessments on applications when in staging mode and provide risk assessment report for application owners before deploying them in production.• Define an IT/OT application testing framework where regular reviews and mandatory checkpoints are conducted against defined standards prior to design completion.• Develop a code integrity process where code signing is performed consistently & integrated in SDLC process and code obfuscation is applied wherever applicable. • Conduct security assessments on applications in production. • Review the IT/OT security controls for applications targeted with cyber threats. • Maintain a centralized repository for SDLC processes integrated with regular tracking processes. • Document a list of requirements where all intellectual property and production code are held in escrow. • Develop guidelines to include application security testing and for mobile applications.• Train testers on coding process using security test cases. • Identify and assign personnel responsible for application security. • Develop a process for conducting SAST and DAST activities on all developed applications• Implement Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools to identify vulnerabilities and weaknesses in applications before deploying into production. • Develop a platform to allow users to report bugs/issues in the applications. • Implement a WAF to ensure protection of critical and externally facing the company applications. • Ensure WAF logs are captured, archived and integrated to the SIEM solution. • Create and maintain an inventory of all IT/OT applications including criticality and sensitivity ratings, reviewed at least once a year. • Maintain a whitelist of IT/OT applications and application components authorized to be active on a host along with a list of trusted applications from vendors. • Perform periodic scans to detect deviations from the baseline configuration standards.• Develop schedule to periodically review Web Application Firewall (WAF) signatures based on the changes to application use cases and design changes. • Develop training materials and implement training on application hardening relevant to all stakeholders.

    Knowledge: • Network components, their operation and appropriate network security controls and methods. • Cybersecurity and privacy principles as they apply to software development. • Programming language structures and logic. • Interpreted and compiled computer languages. • Critical information systems that were designed with limited technical cybersecurity controls. • Data security standards relating to the sector in which the company operates. • Embedded systems and how cybersecurity controls can be applied to them. • Intrusion detection and prevention system tools and applications. • Complex data structures. • Local and wide area networking principles and concepts including bandwidth management.• Secure configuration management techniques. • Software debugging principles. • Software development models.• Software engineering. • System design tools, methods and techniques, including automated systems analysis and design tools. • Knowledge of web services. • Secure coding techniques. • Software quality assurance process. • Developing software in high-level languages.• Developing software for UNIX or Linux.Qualifications: • Bachelor’s degree in computer science, information systems, or related field. • 10+ years of experience in information security. • 7+ years of experience in security testing of software. • ISTQB certifications, or equal certifications• Bachelor’s degree in computer science, information systems, or related field. • 10+ years of experience in information security. • 7+ years of experience in security testing of software. • ISTQB certifications, or equal

    We are a national group formed on the foundations of social responsibility and building the acquired value with hard work and quality of outputs that contribute to creating a fertile production environment for our esteemed customers so that they can present their work in accordance with standards of balanced performance that ensures continuity and reduces the expected risk. More

  • in

    Software Architect | Air Arabia

    Employment:

    Full Time

    • Owns delivery of software products and components for ISA; provides technology expertise and contributes to the management of technology life cycle. Investigates and analyses application architecture, technology stack, design, development, deployment and automated testing.• In collaboration with product team, project managers, and IT solutions managers, translates business needs into technical requirements and recommends cost-effective solutions/alternatives in line with the architectural principles laid down for ISA products. • Manages testing and implementation of technical solutions; reviews technical documentation- user guides, training manuals, and system specifications ensuring adequacy from a knowledge management and compliance with customer expectations perspectives.• Reviews specifications and information of the architectural design to create the product backlog , identify additional requirements, and highlight gaps (if any); recommends additional requirements to the Product Team as needed. • Identifies and decides on the technical tools and languages needed for the design execution in line with the adopted technical and quality standards.• Establishes/enforces efficient continuous delivery and production operations processes; creates deployment architecture based on open source technology stack for automation. Ensures the User Interfaces used for the product are in line with requirements and rightly implemented• Conducts market researches to keep up with, identify, and implement best practices, new trends, and emerging technologies that bring best value to ISA clients; partners with cross-functional teams to explore ways and means to adopt/monitor such technologies.• Assists in the evaluation of external vendors and products and provides input to business managers on business cases. • Co-manages the implementation of agreed remedies and preventative measures. Ensures compliance of the implementation with the architecture. Assists ISA teams to ensure agreed service levels are met; provides needed status reports to specialists, users and managers.• Assists in the identification and assessment of potential risks to technology infrastructure and their impact on the business; anticipates, identifies and resolves issues relating to client facing architecture and assists in developing mitigation and backup plans.• Installs and maintains security patches in production and non-production environments and provides technical governance and sign off on engineering team deliverables.• Leads and guides other technology experts internally; ensures there is proper, sufficient and continuous knowledge sharing within ISA.• Cultivates and maintains effective working relationships with a variety of stakeholders, including project managers, product, operations, governance and enterprise development teams. • Initiates and Influences thinking and decision-making with respect to technology to the best of ISA.• Performs any additional duties as directed by the line manager.

    • Bachelor’s degree in IT Engineering/Computer Science/Information Technology.• Agile development certifications.• Architectural certifications such as TOGAF, AWS, etc.• Security certifications.• Fluent in English Language.• Minimum 8 years in IT Infrastructure design and management out of which at least 2 years in a “DevOps Architect” position responsible for managing infrastructure operations and application support.• DevOps principles and stages of CICD process from source code management, to build, deployment and test automation, finishing with production deployment• Hands-on designing solutions for IaaS, PaaS and SaaS based set-ups, managing vendors and service providers.• Experienced in core system configuration and systems testing.• Holistic IT Knowledge of heterogeneous technology environments – experienced with different types of end-to-end technology stacks.• Skilled in networking concepts: Routing, Web Application Firewalls, Load Balancing & VPC in a cloud environment.• Hands-on production operations and site reliability engineering principles;• Capable of conducting cost-benefit analysis for IT investments.• Hands on technical leadership, technical solution design, and architecture.• Proven skills in analyzing data, identifying pitfalls and recommending cost-effective solutions.• Cost-oriented, possesses effective persuasive, negotiation, problem solving and decision-making skills.• Employs technical interpersonal skills to achieve company’s objectives.• Demonstrates the ability to contribute and successfully deliver against business strategy and set KPIs.

    Air Arabia (PJSC), listed on the Dubai Financial Market, is the Middle East and North Africa’s first and leading low-cost carrier flying to over 100 destinations across the world. Air Arabia was the first airline to introduce the low-cost carrier concept in the region and is on a mission to serve all Arab countries and beyond, constantly undergoing aggressive route expansion, taking advantage of its ideally located hubs in the United Arab Emirates, Morocco, Egypt and Jordan. Over the past thirteen years, Air Arabia, through continuous market research and customer feedback, provides a range of value added services to millions of passengers who chose to fly with Air Arabia’s fleet of A320 aircraft. The airline commenced operations in October 2003 and achieved financial break-even from its very first year of services and has been profitable ever since. More

  • in

    Compliance Officer – MLRO – SAMA | Venture Search

    Employment:

    Full Time

    As the compliance officer you will be responsible for assisting in ensuring the overall regulatory compliance as required by global laws and regulations. As the Compliance Officer, you must ensure the Company abides the international AML conventions and the relevant laws and the new payment regulations issued by SAMA. Reporting to the Senior, you will operate independently and work closely with all relevant stakeholders, internationally.Responsibilities:• Be the person in working with internal and external stakeholders for PI/EMI license application in KSA.• Be the Recognized Person to implement the AML policies, procedures, systems and controls and day-to-day oversight of its compliance with the Rules in AML and any relevant anti-money laundering Rules, to meet Regulators’ expectations and to mitigate in-house compliance risks.• Be responsible in AML risk assessment, clients onboarding, payment channels onboarding, ongoing monitoring, AML/fraud-related transactions monitoring, record keeping and staff trainings.• Cooperating with the Financial Intelligence Units and all applicable Regulators in the KSA, including but not limited to routine liaison and any submission of documentation upon regulatory requests.• Assisting in undergoing multiple compliance inspections and enquiries by our globally recognized commercial banks and regulated payment channel partners.• Reporting regularly to the Senior Management on the licensing status and any regulatory compliance matters.• Monitor any changes of regulatory developments that would potentially impact the company and providing timely updates to the relevant functions.• Ensuring the regulatory requirements are promptly implemented to a satisfactory level.• Assisting in ad-hoc compliance reviews.

    • +5 years relevant experience in AML and regulatory compliance, with proven track records in securing regulatory licenses is a strong plus• Proven track records in dealing with SAMA and deep knowledge about the guidelines for PSP in KSA.• Professional qualification(s) is required to demonstrate sufficient knowledge of relevant AML requirements e.g. CAMS• Experience in incorporation of entities with SAMA and application submission for securing PI/EMI licenses.• Strong proficiency in English• Residency in the KSA

    Venture Search is an international banking & financial services search firm, combining technology and human skill to enhance all aspects of the hiring process.
    By combining advanced search technology and a market-leading team, we are able to attract the most talented candidates in the banking and financial services sector.
    Here at Venture Search, we are passionate about building world-class teams and delivering long-term recruitment solutions. Venture’s focus spans multiple facets of the global Financial Services industry, including Banking, Non-Banking Financial Institutions, Buyside, Fintechs, and Advisory firms. More

  • in

    Group CFO – Chief Financial Officer | Guildhall

    Employment:

    Full Time

    Guildhall is looking for a Group CFO to work within one of the most successful groups in Qatar.We require a CFO who is experienced in managing finances for organisations with over 2000 staff across a wide rage of subsidiaries and regions.This is a long term opportunity for the right person with the right background and personality to succeed with this organisations aims for the FIFA World Cup and 2030 Vision for Qatar. We are looking for someone commercially astute.A generous family package is on offer with fights, schooling and vehicle all provided.

    Candidates should be able to demonstrate the following skills and experience:- 20+ years financial management experience- Worked as a CFO for a group of businesses – Experienced in organisations with over 2000 staff- Strong personality and able to build relationships vertically through the business

    Guildhall is the most respected HR & Headhunting Consultancy in the MENA Region.

    With deep, extensive knowledge of HR & Recruiting in the region, Guildhall has become a trusted partner of choice for candidates and clients. Starting from an exclusive recruitment agency in Dubai – UAE, Guildhall has grown into an elite service with the ability to cover vacancies in across MENA and Asia-pacific.

    Offering tailored Career Sessions and an innovative industry-first membership program designed to save money on core services.

    Guildhall is the partner of choice. More

  • in

    Operations Officer | Venture Search

    Employment:

    Full Time

    • You will be responsible for managing the office administration and coordinating with the global admin and finance team for maintaining and proper functioning of the ADGM office.• You will be responsible for facilitating/ attending any customer issues and raising to the concerned team in UAE or the global headquarters.• You will be coordinating with the relevant stakeholders and contributing to the development of weekly and monthly reports and dashboards.• Supporting the team with the review and development of template documents, emails, processes and process maps• Ensuring requests to the team are responded to in an efficient, accurate and timely manner.• You will be responsible to rectify any systems issues locally in UAE and coordinating with the global IT team for providing immediate solutions.• Taking lead on automation of reporting activities including providing user requirements and IT issues any other risk related projects.• Monitoring and approving petty cash payments, including ensuring disbursements are captured.

    • +5 years relevant experience in Operations, Customer complaints in financial services company or Fintech• Familiarity in dealing with ADGM/DIFC/CBUAE and knowledge a bout the local laws in UAE.• Graduate qualification(s) is required to demonstrate sufficient knowledge in IT, systems management, networking.• The role also requires that the candidate is able to collaborate with colleagues across different competences within the organization• Strong proficiency in English• Resident in the UAE and presently based in UAE;

    Venture Search is an international banking & financial services search firm, combining technology and human skill to enhance all aspects of the hiring process.
    By combining advanced search technology and a market-leading team, we are able to attract the most talented candidates in the banking and financial services sector.
    Here at Venture Search, we are passionate about building world-class teams and delivering long-term recruitment solutions. Venture’s focus spans multiple facets of the global Financial Services industry, including Banking, Non-Banking Financial Institutions, Buyside, Fintechs, and Advisory firms. More

  • in

    Risk Officer | Venture Search

    Employment:

    Full Time

    • You will be responsible for ensuring risk identification, assessment and responses are properly collected and recorded, supporting Risk analyzing and reporting information pertaining to the risk management process.• You will be responsible for facilitating Risk Reviews to elicit information and record it and maintaining and updating Risk information in the risk registers.• You will be liaising with the appropriate stakeholders and contributing to the development of weekly and monthly reports.• You will be responsible for conducting risk assessment, gap analysis and implementation of preventive measures.• You will be responsible for monitoring risk appetite and risk limits, design and implement risk measurement model, monitor transactions, stress testing, and scenario analysis tests.• Taking lead on automation of reporting activities including providing user requirements, specifications and design inputs, particularly with regard to risk recognition, measurement and any other risk related projects.

    • +5 years relevant experience in Risk Management in financial services company or any big four or Fintech companies.• Familiarity in dealing with ADGM/DIFC/CBUAE and deep knowledge about the local laws in UAE.• Professional qualification(s) is required to demonstrate sufficient knowledge of risk management skills• Strong proficiency in English• Resident in the UAE and presently based in UAE;

    Venture Search is an international banking & financial services search firm, combining technology and human skill to enhance all aspects of the hiring process.
    By combining advanced search technology and a market-leading team, we are able to attract the most talented candidates in the banking and financial services sector.
    Here at Venture Search, we are passionate about building world-class teams and delivering long-term recruitment solutions. Venture’s focus spans multiple facets of the global Financial Services industry, including Banking, Non-Banking Financial Institutions, Buyside, Fintechs, and Advisory firms. More

  • in

    Cloud Value Representative | Oracle

    Employment:

    Full Time

    Sells a subset of product or services directly or via partners to a large number of named accounts/non-named accounts/geographical territory (mainly Tier 3 accounts).Primary job duty is to sell technology software products and related services in a defined territory. Identifies, qualifies and closes new opportunities. Manages accounts including the entire sales process from business development prospecting and specifications through contract negotiations, signing, and post-sales support. Leverages the Oracle sales model to maximize revenue growth and increase local market share. Builds and expands business partner revenue and self sufficiency.

    Job duties are varied and complex, needing independent judgment. May have project lead role. 5 years field sales experience including technology sales experience. Ability to forecast, manage sales expenses, and successfully close new Oracle business. Business development, prospecting and presentation skills. Excellent communication skills and problem solving ability. Proven track record of exceeding sales objective and territory/account development. Experience as the focal point for clients for all sales and related issues. Oracle knowledge and/or knowledge of Oracle*s competitors. Travel may be needed. Bachelor degree or equivalent.As part of Oracle’s employment process candidates will be required to successfully complete a pre-employment screening process. This will involve identity and employment verification, professional references, education verification and professional qualifications and memberships (if applicable).

    Oracle offers an integrated array of applications, databases, servers, storage, and cloud technologies to empower modern business. For most companies, flexibility is critical. Oracle provides a wide choice of software, systems, and cloud deployment models – including public, on-premises, and hybrid clouds – to ensure that technology flexes to the unique needs of a business.

    Oracle Cloud is a complete, integrated stack of platform, infrastructure, and application services. With advanced scalability and security, Oracle Cloud enables technical agility across the enterprise, connects people to information for clearer insights, and fosters efficiency through simplified workflows.

    More than 420,000 customers across 145 countries have harnessed Oracle technology to accelerate their digital transformation. More

  • in

    Access & Security Support Manager | VHR Recruitment

    Employment:

    Full Time

    Access & Security Support Manager – RiyadhSupport of the Information Technology Business Systems and Technologies, within the company.This role acts as the company governance and intermediary between the Production Systems and the supporting Application Partners, Technology Partners, and company Business Functions.Provide support in provisioning, de-provisioning and assigningadequate access for user accounts / Groups in Active Directory/Privilege Access Management System. The Role includes managing user accounts, groups, file / folder permissions, manage process around identity life cycle management.To ensure separation of access to data, to mitigate suppliers’ access to only those functions and those times as required to enable delivery of management, maintenance, and support.Job Specific • Experience in technologies such as Java, LDAP, and Linux • Working knowledge of web / application servers (IIS, WebSphere, WebLogic, and Apache)• Experience in development / configuration of standard / custom IAM integrations using Java, .Net or other major scripting languages• Experience in implementing Identity and Access Management projects.• Experience in carrying out application integrations with the IAM solution dealing with provisioning (e.g. Workflows), single sign-on (WIA, Forms, HTTP) and PKI concepts• Day to day business as usual support of the Identity and Access Management platform• Technical administration of PAM System• Contributing to the long-term iAM architecture roadmap• Assisting with the management of key Enterprise Systems (including but not limited to; SharePoint, Risk Systems, Office 365/Azure and many more)• Engaging with stakeholders, analyzing requirements, and prioritizing work pipelines• Identifying, communicating, and managing risk.• Excellent knowledge of Microsoft, Virtual IT Architectures and Systems and systems engineering from hardware through to application development.• Production support, processes, procedures, and best practices. Production/administration support with a major Airline, Utility or Financial Organization with production access and migration controls.• Strong functional and technical IT knowledge.• Strong knowledge of IT Governance and best practices.• Proficiency in English (must) and any additional language would be desirable.• Regulatory and Compliance awareness.Desired Experience:• Extensive experience (5 – 10 years) in a senior IT management role, 5 years production support.• Experience in the management of large, outsourced arrangements.• Specific in-depth knowledge and operational experience in two or more of the following:• Airline operations, engineering, and corporate systems• Midrange server virtualization architectures.• Production access controls and migration toolsets.• Business Technology architectures, email office, collaboration.• IT Security standards.Familiarity with current Information Technology trends.Minimum Qualifications:Bachelor’s degree in Information Technology or Computer Science/Engineering or similar discipline from a reputable university.

    Desired Experience:• Extensive experience (5 – 10 years) in a senior IT management role, 5 years production support.• Experience in the management of large, outsourced arrangements.• Specific in-depth knowledge and operational experience in two or more of the following:• Airline operations, engineering, and corporate systems• Midrange server virtualization architectures.• Production access controls and migration toolsets.• Business Technology architectures, email office, collaboration.• IT Security standards.Familiarity with current Information Technology trends.Minimum Qualifications:Bachelor’s degree in Information Technology or Computer Science/Engineering or similar discipline from a reputable university.

    Created in 2003 by technical engineers and experienced recruiters, VHR delivers a partner-orientated approach. We are passionate about the industries where we operate, the career-enhancing support we provide and the people with whom we work.

    Whether one permanent vacancy or a team of contract specialists, VHR strives to deliver the best possible staffing solutions.

    As a recruitment company, we see our clients as our partners and our services as an extension of our clients’ businesses. We operate with a set of core values at the heart of everything we do. More