Infosec and Threat Assessment Manager (Bengaluru)

Infosec and Threat Assessment Manager (Bengaluru)

04 Aug
|
Emirates NBD
|
Bengaluru

04 Aug

Emirates NBD

Bengaluru

ABOUT EMIRATES NBD:

Emirates NBD is a market leader across the MENAT (Middle East, North Africa and Türkiye) region with a presence in 13 countries, serving over 9 million customers. Emirates NBD is the leading financial services brand in the Emirates with a Brand value of approximately USD 4 billion.

We serve our customers and help them realize their financial objectives through a range of banking products and services including retail banking, corporate & institutional banking, Islamic banking, investment banking, private banking, asset management, global markets and treasury, and brokerage operations.

We are a key participant in the global digital banking industry, with 97% of all financial transactions and requests conducted outside of our branches. We also operate Liv, the lifestyle digital bank by Emirates NBD. With over half a million users, it continues to be the fastest-growing digital bank in the region.

JOB PURPOSE The Infosec and Threat Assessment Manager will conduct testing for Emirates NBD infosec assets through focused threat-based methodologies, to identify, expose and exploit vulnerabilities to improve Cyber readiness and review security controls and system configurations across IT systems across the group to ensure their security posture and compliance.

We are seeking a hands-on security assurance manager to lead a technical team responsible for end-to-end security validation of applications, APIs, Infrastructure, Network and logging. This role will ensure security assurance activities are not only thorough and repeatable, but also aligned with business risk, regulatory expectations and our internal security baselines.

KEY RESPONSIBILITIES

- Develop and manage the Security Assessment program, ensuring alignment with internal policies, audit, compliance, and regulatory requirements.
- Maintain the organization's security assessment service portfolio and related service catalogue.
- Develop and operationalize the Threat Modelling framework to support security assessment activities.
- Plan and conduct cyber security assessments across systems, installations, applications, infrastructure, networks, APIs, and controls.
- Review security controls and system configurations to ensure they are effective, optimized, and compliant.
- Identify, track, and report IT risks, vulnerabilities, gaps, and threat activity across technology assets.
- Engage with technology leadership and stakeholders to plan, schedule, report, and govern security assessment activities.
- Present threats, vulnerabilities, compliance posture, and remediation progress through governance forums and stakeholder read-outs.
- Assess AI, Generative AI, LLM, Agentic AI, and Machine Learning use cases for security, privacy, resilience, compliance, and governance risks.
- Conduct AI security reviews, including security architecture assessment, threat modelling, adversarial testing, prompt injection, model poisoning, data leakage, excessive privileges, and AI supply chain risks.
- Develop AI security methodologies, control baselines,



and assurance frameworks aligned with industry standards and regulatory expectations.
- Use AI-assisted security tools and automation to improve threat modelling, control validation, vulnerability identification, and security testing.
- Assess blockchain, cryptocurrency, digital asset, and Web3 technologies for security, operational, regulatory, AML, sanctions, and financial crime risks.
- Perform security assessments of wallet architectures, custody platforms, key management controls, smart contracts, tokenization platforms, DeFi integrations, blockchain infrastructure, and cross-chain interoperability.
- Review risks related to smart contract logic, protocol design, bridges, oracles, consensus mechanisms, and cross-chain asset transfers.
- Ensure security assessments are conducted in a controlled way without causing business impact.
- Ensure assessment reports are accurate, relevant, and properly scoped.
- Define and report appropriate threat, vulnerability, and risk metrics aligned with the bank's risk appetite.
- Work with technical stakeholders and leadership to agree remediation plans and ensure vulnerabilities are mitigated.
- Maintain accurate threat register entries, including mitigation actions, compliance dates, and threat ratings.

KEY REQUIREMENTS

Education & Certification

- Bachelors or Master's degree in Computer Science, Mathematics or equivalent discipline
- Master's degree in Business Management or equivalent
- Certifications such as CISSP, OSCP(preferable), OSEP, GPEN

Skills & Experiences

- 5-8 years of experience in technical Cyber Security, Security Assessments, Threat Modelling, Penetration Testing, Security Architecture Reviews and Technology Risk Assessments.
- Hands-on experience conducting or managing:

> OWASP top 10- and API top 10 testing

> WAF Review

> Threat Modelling

> Source Code Analysis

> Network Pen testing

- Experience assessing up-to-date technology platforms including cloud-native architectures, APIs, microservices, containerization platforms, AI/ML systems, Generative AI solutions and emerging digital technologies.
- Experience conducting security reviews of Artificial Intelligence (AI), Machine Learning (ML), Generative AI and Agentic AI implementations, including threat modelling, security architecture assessments, adversarial testing and governance control validation.
- Experience leveraging AI-based technologies, automation and advanced analytics to improve security assurance, vulnerability management, control testing and threat assessment outcomes.
- Experience assessing blockchain, cryptocurrency, digital asset and Web3 technologies, including:
- Digital asset custody platforms and wallet security
- Key management and cryptographic controls




- Smart contract security assessments
- DeFi protocol security reviews
- Cross-chain bridge and interoperability security reviews
- Blockchain infrastructure and node security
- Tokenization platforms and digital asset ecosystems
- Financial crime, AML, sanctions and digital asset regulatory compliance considerations
- Experience with Python
- Experience with code development.
- Experience with malware scanning tools
- Experience with mobile and digitization platforms
- Ability to perform threat modelling and security assessments for AI and decentralized technologies using frameworks such as STRIDE, PASTA, MITRE ATT&CK; and MITRE ATLAS.
- Strong technical background covering heterogeneous technologies and multiple security domains
- Deep knowledge of the gaps and weaknesses of a typical heterogeneous banking environment including the toolsets required for security assessments (Technical)
- Deep experience in depicting vulnerabilities, accurate threat assessment and mitigation recommendation.
- Deep experience in evaluating threats as per the latest threat environment affecting the region (Asia Pacific, EMEA & North Africa) and the world
- Knowledge of regulatory expectations associated with AI adoption and digital asset technologies in banking and financial services environments.
- Deep knowledge and skills in policies, standards and required controls (both technical and compliance based)
- Extensive experience with Security scanning solutions for use cases in the SDLC lifecycle such as SAST, IAST, DAST and the infrastructure security posture management lifecycle and can quickly use all functionality within the solutions to interact with systems, through existing content (e.g. plugins), published baselines and custom developed content
- Integrate Open-source frameworks and solutions into the Threat and Vulnerability solution environment to enable unified reporting.
- Superior verbal & written communication skills; should be able to simply and effectively explain security observations to technical personnel and to business personnel
- Security Ninja with Analytical Thinking ability that thinks 3-4 steps ahead of an attacker and anticipates various attack / threat vectors
- Is transparent, accepts responsibility and takes accountability; accepts mistakes and learns from them.
- Team Player who believes in working together; listen to other's ideas; communicate accurately and concisely

There's never been a better time to join Emirates NBD.

We're one of the region's most recognizable brands. We're banking innovation leaders. We're growing across both the UAE and our global offices. We offer a huge range of professional development opportunities to accelerate your career.

It also goes without saying that we provide extremely competitive rewards, benefits and perks too, like our flexible work policy so you can work from home whenever it suits.

At ENBD, we encourage interested candidates to review the key responsibilities and qualifications for each role and apply for positions that match their skills and capabilities.

📌 Infosec and Threat Assessment Manager (Bengaluru)
🏢 Emirates NBD
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: infosec and threat assessment manager (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: infosec and threat assessment manager (bengaluru) / bengaluru