Threat Intelligence Manager

ABU DHABI

Contract

Related Jobs

Role : Threat Intelligence Manager
Role Type : Contract (Yearly Renewable)

ROLE PURPOSE
Own the bank’s cyber threat intelligence function end to end, with particular focus on threats arising from open finance — API-based data sharing, third-party fintech integrations, and consent-driven access models.
KEY RESPONSIBILITIES
• Run the full CTI lifecycle: collection, processing, analysis, dissemination
• Monitor threats specific to open finance / open banking APIs — third-party and fintech partner risk, consent and data-sharing exposure, API-based attack patterns
• Build and maintain threat actor profiles relevant to regional banking (APT groups, financially motivated actors, ransomware operators)
• Deliver strategic, operational, and tactical intel to SOC, IR, fraud, and executive stakeholders
• Feed threat intel into SIEM/SOAR/EDR platforms; map findings to MITRE ATT&CK
• Support red/purple team exercises with threat-informed scenarios
• Track CBUAE regulatory advisories and coordinate response
• Manage relationships with external intel vendors and ISACs (e.g. FS-ISAC)
MUST-HAVE SKILLSET
• 10+ years total cybersecurity experience, with demonstrated CTI leadership (banking/BFSI preferred)
• Hands-on with threat intel platforms — Recorded Future, ThreatConnect, Anomali, or MISP
• Strong grasp of MITRE ATT&CK, cyber kill chain, IOC/IOA management
• Dark web / OSINT monitoring and malware/APT analysis experience
• Working knowledge of CBUAE cybersecurity regulations and UAE IA/NESA standards
• SIEM/SOAR exposure (Splunk, QRadar, Microsoft Sentinel)
• Exposure to open banking/open finance security models — API security, OAuth/consent frameworks, third-party risk — a strong plus given the environment
• Strong stakeholder skills — able to translate technical intel into business risk language for CISO/exec audiences
NICE TO HAVE
• Working awareness of the AI/ML threat landscape — adversarial ML, GenAI-enabled fraud, deepfake-enabled social engineering
• Any AI security exposure (not yet a common cert path, but a differentiator)
PREFERRED CERTIFICATIONS
GCTI, CTIA, CISSP, CEH (SANS FOR578 a plus)