عن الدور
تبحث بوپا العربية عن مدير أمان التطبيقات والذكاء الاصطناعي للإشراف على أمان التطبيقات والذكاء الاصطناعي عبر أنظمة المؤسسة والحلول المزوَّدة بالذكاء الاصطناعي. هذه وظيفة بدوام كامل مقرها في جدة أو مكة المكرمة، المملكة العربية السعودية، ضمن منطقة مكة المكرمة.
حوكمة أمان التطبيقات والذكاء الاصطناعي
- إنشاء وصيانة برامج أمان التطبيقات وأمان الذكاء الاصطناعي.
- تعريف معايير الأمان ومتطلبات الرقابة وإجراءات الحوكمة للتطبيقات والحلول القائمة على الذكاء الاصطناعي.
- ملاءمة ممارسات أمان التطبيقات والذكاء الاصطناعي مع متطلبات الأمن السيبراني والخصوصية وحماية البيانات والعمارة المؤسسية وإدارة المخاطر.
- الحفاظ على إرشادات التطوير الآمن للتطبيقات التقليدية وواجهات برمجة التطبيقات Application Programming Interfaces API والتطبيقات السحابية-native والحلول المعتمدة على الذكاء الاصطناعي.
تصميم آمن ودورة حياة التطوير
- إجراء نمذجة التهديدات لتطبيقات الأعمال وواجهات البرمجة والتطبيقات السحابية وحالات استخدام الذكاء الاصطناعي وتدفقات العمل المعتمدة على AI.
- مراجعة معماريات الحلول والتطبيقات لتحديد نقاط ضعف تصميم الأمان.
- تقييم المصادقة والتفويض وإدارة الجلسات وتدفقات البيانات ونُظُم الدمج وحدود الثقة.
- تحديد المخاطر مثل حقن الأوامر، تكاملات AI غير الآمنة، إساءة استخدام النماذج، الاستقلالية المفرطة، تسريبات البيانات، والوصول غير المصرّح إلى معلومات حساسة.
- إدراج متطلبات أمان التطبيقات والذكاء الاصطناعي عبر مراحل التصميم والتطوير والاختبار والإصدار ونشر الإنتاج.
- توجيه فرق التطوير حول هندسة البرمجيات الآمنة والبرمجة الآمنة وأمان API وإدارة الأسرار وإدارة الاعتماد والتدابير DevSecOps.
- تعريف بوابات أمان قبل نشر الإنتاج للتطبيقات والحلول المعتمدة على الذكاء الاصطناعي.
- تعزيز وعي المطورين بالأمان وممارسات البرمجة الآمنة العملية.
اختبار الأمان وإدارة الثغرات
- إدارة ومراجعة نتائج SAST وDAST واختبار أمان APIs والتحليل التركيبي للبرمجيات وفحص الحاويات والمراجعات الأمنية اليدوية.
- تحديد أولويات الثغرات بناءً على الشدة وقابلية الاستغلال والتعرّض والأهمية للأعمال وحساسية البيانات.
- تنسيق التصحيح مع التطوير والبنية التحتية ومالكي التطبيقات وفِرق الأمن السيبراني.
- تتبع إغلاق نتائج الأمان والتحقق من التصحيح قبل الإصدار أو التشغيل الحي للإنتاج.
أمان الذكاء الاصطناعي وحماية البيانات
- تقييم حالات استخدام AI فيما يتعلق بالأمن السيبراني والخصوصية والأطر القانونية والتنظيمية ومخاطر حماية البيانات.
- مراجعة تدفقات البيانات المرتبطة بـ AI وبيانات التدريب ومعالجة المدخلات والمخرجات والتحكم في الوصول والتسجيل والاحتفاظ ومخاطر تعرض البيانات الحساسة.
- تقييم خدمات AI من أطراف ثالثة ومنصات AI الداخلية وواجهات برمجة التطبيقات والإضافات والتكاملات مع أنظمة المؤسسة من منظور الأمان السيبراني.
- وضع ضوابط لحقن الأوامر وتسريب البيانات وسوء استخدام النماذج ومخرجات غير آمنة ووصول غير مصرح للبيانات وثغرات برمجية بمساعدة AI.
الاستشارات والتحسين المستمر
- رصد التهديدات والثغرات والتقنيات والأفضل في الصناعة المرتبطة بأمان التطبيقات وأمان الذكاء الاصطناعي.
- تقديم استشارات خبراء لفرق التطوير والبنية التحتية والأمن السيبراني والخصوصية والأعمال.
- دعم الاعتماد الآمن لتقنيات الذكاء الاصطناعي عبر المؤسسة مع تمكين الابتكار بشكل آمن.
- تقديم تقارير عن موقف أمان التطبيقات والذكاء الاصطناعي والمخاطر والتقدم في التصحيح والقياسات الرئيسية للإدارة.
- العمل على تحسين الأدوات والعمليات والمعايير وممارسات مراجعة الأمان بشكل مستمر.
الخبرة المطلوبة
يجب أن يمتلك المرشحون من 5 إلى 10 سنوات من الخبرة ذات الصلة في أمان التطبيقات والذكاء الاصطناعي.
About the Role
Bupa Arabia is seeking a Manager AI & Application Security to oversee and manage application and AI security across enterprise systems and AI-enabled solutions. This is a full-time position based in Jeddah or Makkah, Saudi Arabia, within the Makkah region.
Application and AI Security Governance
- Establish and maintain the Application Security and AI Security programs.
- Define security standards, control requirements, and governance processes for applications and AI-enabled solutions.
- Align application and AI security practices with cybersecurity, privacy, data protection, enterprise architecture, and risk management requirements.
- Maintain secure development guidelines for traditional applications, APIs, cloud-native applications, and AI solutions.
Secure Design and Development Lifecycle
- Conduct threat modeling for business applications, APIs, cloud applications, AI use cases, and AI-enabled workflows.
- Review application and AI solution architectures to identify security design weaknesses.
- Assess authentication, authorization, session management, data flows, integration patterns, and trust boundaries.
- Identify risks such as prompt injection, insecure AI integrations, model misuse, excessive agency, data leakage, and unauthorized access to sensitive information.
- Embed application and AI security requirements across design, development, testing, release, and production deployment stages.
- Advise development teams on secure software engineering, secure coding, API security, secrets management, dependency management, and DevSecOps practices.
- Define security gates before production deployment for applications and AI solutions.
- Promote developer security awareness and practical secure coding practices.
Security Testing and Vulnerability Management
- Manage and review findings from SAST, DAST, API security testing, software composition analysis, container scanning, and manual security reviews.
- Prioritize vulnerabilities based on severity, exploitability, exposure, business criticality, and data sensitivity.
- Coordinate remediation with development, infrastructure, application owners, and cybersecurity teams.
- Track closure of security findings and validate remediation before release or production go-live.
AI Security and Data Protection
- Assess AI use cases for cybersecurity, privacy, legal, regulatory, and data protection risks.
- Review AI-related data flows, training data, input/output handling, access controls, logging, retention, and sensitive data exposure risks.
- Evaluate third-party AI services, internal AI platforms, APIs, plugins, and AI integrations with enterprise systems from a cybersecurity perspective.
- Define controls for prompt injection, data leakage, model misuse, insecure outputs, unauthorized data access, and AI-assisted software vulnerabilities.
Advisory and Continuous Improvement
- Monitor emerging application security and AI security threats, vulnerabilities, attack techniques, and industry best practices.
- Provide expert advisory to development, infrastructure, cybersecurity, privacy, and business teams.
- Support secure adoption of AI technologies across the organization while enabling innovation safely.
- Report application and AI security posture, risks, remediation progress, and key metrics to management.
- Continuously improve tools, processes, standards, and security review practices.
Required Experience
Candidates should possess 5 to 10 years of relevant experience in application and AI security.