Digital Security Engineer

5 days ago


Muscat, Muscat, Oman Tawteen Full time 60,000 - 120,000 per year

Job Purpose:

The Digital Security Engineer embeds security controls throughout the software development and deployment lifecycle, ensuring banking systems remain secure, compliant, and resilient. He/She implements automated security scanning, builds and maintains DevSecOps pipelines, and performs application security testing across internal and third-party platforms. The Digital Security Engineer collaborates with development teams to remediate vulnerabilities, supports secure integration with external partners, and ensures compliance with CBO regulations and internal cybersecurity frameworks.

Key Accountabilities:

  • Designs and implements CI/CD security pipelines in GitLab with automated security gates.
  • Configures and maintains security scanning tools including SonarQube, Snyk, and Burp Suite.
  • Performs application security testing on web and mobile applications (React Native, Flutter).
  • Conducts API security assessments for internal systems and partner integrations.
  • Reviews source code in JavaScript, TypeScript, Dart, and to identify vulnerabilities.
  • Performs penetration testing on digital banking applications and services.
  • Assesses mobile app security for iOS and Android, including reverse engineering and threat analysis.
  • Implements and manage secrets and key management using OCI Vault.
  • Configures Web Application Firewall (WAF) rules and policies in Oracle Cloud Infrastructure (OCI).
  • Ensures compliance with CBO cybersecurity regulations, PCI-DSS standards, and internal ISMS policies.
  • Conducts third-party security assessments for partner integrations and platforms.
  • Manages software license compliance and audits usage of open-source and commercial components.
  • Reviews and approves third-party libraries to ensure proper licensing and usage.
  • Guides developers in selecting properly licensed components or suggests compliant alternatives.
  • Manages the vulnerability disclosure lifecycle and coordinates remediation workflows.
  • Trains developers on secure coding practices aligned with OWASP Top 10 and industry standards.
  • Responds to application-layer security incidents and forensic investigations.
  • Uses AI tools to analyze vulnerabilities and generate automated remediation guidance.

Key Skills & Competencies:

  • Strong proficiency in React Native and Flutter security assessments
  • Advanced capability in software license compliance and audit processes
  • Good in open-source license management (MIT, Apache, GPL, etc.).
  • Hands on PCI-DSS compliance implementation
  • Excellent in securing Oracle Cloud Infrastructure (OCI) environments
  • Good skills in IBM API Connect security configurations
  • Good Temenos platform application security skills.
  • Profeicent in RASP technologies
  • Good skills in threat modeling using STRIDE and PASTA frameworks
  • Hands-on skill in binary analysis and reverse engineering techniques
  • Good in container security scanning and compliance skills.
  • SIEM tools (Splunk, ELK)
  • Excellent analytical and problem-solving skills
  • Strong interpersonal communication skills preferably in Arabic and English
Desired Candidate Profile

Qualifications and Experience:

  • Bachelor's degree in Cybersecurity, Computer Science, or related field
  • A professional certification in one of the cybersecurity or information security domains (e.g., CISSP, CEH, OSCP, GWAPT, GIAC, etc.)
  • Minimum of 5 years in application security, DevSecOps, or security engineering.
  • Proven track record of executing similar accountabilities in Banking, fintech, or a regulated industry.
  • Vast experience in web and mobile application security testing.
  • Familiarity with JavaScript/TypeScript OR Dart preferred.
  • Strong understanding of secure coding practices and OWASP Top 10.
  • Hands on experience in implementing security in CI/CD pipelines.
  • Clear understanding of CBO cybersecurity regulatory requirements.


  • Muscat, Muscat, Oman Vodafone Oman Full time 40,000 - 120,000 per year

    Role purpose:Vodafone is Oman's latest Network Operator. The presence of Vodafone in Oman will contribute to the development of all sectors, including the economic and educational sectors, and in line with Oman Vision 2040.Our purpose is to 'Connect for a Better Future 'which underpins everything we do. Our solutions will positively impact society as we...


  • Muscat, Muscat, Oman Tawteen Full time 80,000 - 120,000 per year

    Job Title -Digital Operations Engineer /Job PurposeThe Digital Operations Engineer manages the Bank s Oracle Cloud Infrastructure and Kubernetes environments to ensure stability, security, and scalability of digital banking services. He/She maintains 99.9%+ service uptime, optimizes infrastructure performance and cost, and enforces CI/CD best practices...


  • Muscat, Muscat, Oman Oman Investment Authority Full time 60,000 - 120,000 per year

    Key Accountabilities:Manages and optimizes the Oracle Cloud Infrastructure (OCI) environment to ensure stability, scalability, and cost-efficiency.Deploys and maintains Oracle Kubernetes Engine (OKE) clusters for containerized workloads.Implements infrastructure as code using Terraform to enable consistent and repeatable infrastructure provisioning.Builds...


  • Muscat, Muscat, Oman Oman Housing Bank | بنك الإسكان العُماني Full time 60,000 - 120,000 per year

    Job Purpose:The Head – Digital Delivery leads the execution and coordination of digital platform and application deliveries within the Strategy, Innovation & Digital Department. He/ She ensures timely and compliant release of platforms and ecosystem services in collaboration with internal stakeholders and third-party vendors. The Head – Digital Delivery...


  • Muscat, Muscat, Oman AWASR Full time 30,000 - 60,000 per year

    Job description:POSITION INFORMATIONDivision: Network & Digital Department:Security Role Designation: Cybersecurity SpecialistROLE PURPOSEThe Cybersecurity Specialist, under the supervision of the Manager Cybersecurity Operation, is in charge of developing, executing, and overseeing security measures to safeguard AWASR's infrastructure and data. This...


  • Muscat, Muscat, Oman Integrated Systems LLC Full time 40,000 - 80,000 per year

    Location:BowsherEmployment Type:Full-timeAbout the Role:We are seeking a motivatedNetwork & Security Engineerwith strong fundamentals in networking and security to join our team. The ideal candidate should have solid technical knowledge of Layer 2/3 networking, switching concepts, and firewall management, along with a willingness to learn and grow in a...


  • Muscat, Muscat, Oman Siemens Full time 60,000 - 120,000 per year

    We know that a business thrives only when its people are thriving. That's why we always put our people first. Our global and diverse team is eager to support you and challenge you to grow in many ways. Who knows where our joint journey will take you?Siemens strongly believes in the value of a Digital Portfolio. That's why Smart Infrastructure combines...


  • Muscat, Muscat, Oman Oman Investment Authority Full time $60,000 - $120,000 per year

    The Solution Consultant provides technical and domain expertise to design and validate digital solutions across ERP, CRM, IoT, AI/Analytics, and integrations.The role works closely with BOT partners in the initial phase to ensure solution feasibility and alignment with Onetech standards, while gradually buildinginternal capability for in-house solution...


  • Muscat, Muscat, Oman Ibex Globe Full time 100,000 - 120,000 per year

    Before sending your application please read the requirements carefully and make sure that you meet the EXACT requirements. If you can't answer with "YES" to the screening question, please please please do not submit your application. Else, you would be permanently blockedQualificationsBachelor's degree in Information Technology, or related field (Master's...


  • Muscat, Muscat, Oman AWASR Full time 40,000 - 80,000 per year

    Job description:POSITION INFORMATION :Division: Network & Digital Department:Security Role Designation: Specialist - Security Special Projects ROLE PURPOSE :The Security Special Projects Specialist, reporting to the Manager of Security Special Projects, is responsible for monitoring, deploying, and Managing security special projects solutions to ensure...