Security Assessorpresent
Apr 2026 — Present
Emirates NBD, Dubai
- Review firewall change requests (port, service, protocol, source, destination, justification) on least-privilege and segmentation principles, assess wireless requests, and troubleshoot Linux and infrastructure issues across pre-production and production.
- Assess banking applications end to end — container and proxy through the BFF to core services — covering API security (authentication, authorization, data exposure, input validation) and the internal API gateways routing traffic across the organization.
- Perform application security testing and secure code review with development and risk teams, review CI/CD pipeline changes, code and dependency upgrades, and give the security sign-off on code, pipelines and releases before go-live.
Show 3 moreShow less
- Review Kafka topics for access control, data sensitivity and secure transport; cover the database lifecycle through encryption at rest and in transit; define secrets management rules and check storage configurations against baselines with the storage team.
- Review third-party integrations for data flow, API exposure and vendor risk, security-test LLMs before AI integration, analyze organization-level AI risk (data leakage, prompt injection, model misuse) and run package and malware analysis.
- Run pre-production security reviews against the bank baseline, verify ELK logging and monitoring, confirm scans are remediated or risk-accepted, and give the final go-live sign-off; investigate P1 incidents, support hotfixes and document on Confluence.