Staff Security Engineer

🏢 Digitalzone
📍 United Arab EmiratesFull-timeOn-site
📅 Posted: 4d ago🔄 Updated: 4d ago
CV%
✨ AI Summary
Digitalzone is seeking a Staff Security Engineer to set the technical direction for security across their platform, encompassing application, cloud, payment, and identity flows. This senior individual-contributor role requires hands-on expertise in tackling complex security challenges and improving the engineering organization's security posture. The responsibilities include designing and maturing the secure SDLC, leveraging automation for vulnerability identification and remediation, implementing supply chain security solutions, and integrating scalable infrastructure and cloud security measures. The role also involves running vulnerability management, coordinating penetration tests, defining secure-by-design patterns, and acting as a liaison with security vendors. The ideal candidate will have 8+ years of experience in software or security engineering with a strong background in application security, cloud/infra security, and detection/response, along with expertise in threat modeling and securing sensitive financial data systems. Fluency in AWS security, modern authentication/authorization patterns, and knowledge of relevant frameworks like PCI DSS and ISO 27001 are essential.
Required Skills
Information Technology
AuthenticationThreat ModelingDatabase Security
Other
SOC 2
🎁 Benefits & Perks
Immediate, large-scale impact on a high-growth business, Top-of-the-market compensation packages, Work alongside top regional talent, with team members from Talabat, Careem, Etisalat, and more
Requirements
8+ years in software or security engineering with deep hands-on depth across application security, cloud/infra security, and detection and response. Strong track record threat modeling and securing systems that handle payments or sensitive financial and PII data. Strong engineering fundamentals: fluency in AWS security, modern authentication and authorisation patterns, and at least one of our core languages. Working knowledge of relevant frameworks (PCI DSS, ISO 27001, OWASP, SOC 2) and how to operationalize them without slowing delivery. Apply judgment on risk tradeoffs and direct, clear and practical communication with engineers and leadership.
Description
You will set the technical direction for security across DigitalZone's platform, from application and cloud security to the payment and identity flows at the core of the business. This is the most senior individual-contributor security role: you own the hardest problems, do the hands-on work, and raise the bar for the whole engineering org. You can read the code, build the tooling, and fix the issue, not just file it.What you'll do:Design and mature the secure SDLC, to support engineers in prioritising and remediating findings: Application Security: Leverage deterministic and LLM assisted automation to identify and remediate vulnerabilities across code developed within DigitalZoneSupply Chain Security: Design and implement solutions to mitigate the risks of vulnerable and compromised 3rd party dependencies. Including, the verification of feature and release integrityInfrastructure & Cloud Security: Integrate scalable solutions to identify and patch vulnerabilities across the container and cloud infrastructure delivery process, including scanning, signing, admission control and runtime securityRun vulnerability management and coordinate penetration tests, and defining and tracking key vulnerability metricsDefine secure-by-design patterns and success criteria for authentication and authorization, cloud networking, secrets management, and IAMAct as the primary liaison between customers and security vendors, driving alignment on security findings, remediation priorities, risk acceptance decisions, and strategic security outcomesRequirementsWhat you'll bring8+ years in software or security engineering with deep hands-on depth across application security, cloud/infra security, and detection and responseStrong track record threat modeling and securing systems that handle payments or sensitive financial and PII dataStrong engineering fundamentals: fluency in AWS security, modern authentication and authorisation patterns, and at least one of our core languagesWorking knowledge of relevant frameworks (PCI DSS, ISO 27001, OWASP, SOC 2) and how to operationalize them without slowing deliveryApply judgment on risk tradeoffs and direct, clear and practical communication with engineers and leadershipBenefitsImmediate, large-scale impact on a high-growth businessTop-of-the-market compensation packagesWork alongside top regional talent, with team members from Talabat, Careem, Etisalat, and more
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00