Zum Hauptinhalt springen

Chief Information Security Officer (CISO)

Vor OrtVollzeitFührungskraft

Dubai, United Arab Emirates · Veröffentlicht vor 2 Tagen

Chief Information Security Officer

TheRole

Lead the organisation's cybersecurity and information security programme, ensuring the confidentiality, integrity,andavailabilityofinformationassetsacrossaregulatedfinancialservicesenvironment.Defineand execute security strategy, own and manage cyber risk within Board-approved appetite, and maintain regulatory compliance within a cloud-native payments and stored value facility (SVF) operation.
Theroleadvisesandrecommendsonsecurityrisk,withindependentauthoritytoescalateunresolvedriskto the CTO, CEO, and Board Risk Committee. Operates within an approved annual security budget; spend proposals require cost-benefit justification and are prioritised within the allocated envelope.
KeyResponsibilities

SecurityStrategy&Governance

  • Defineandmaintainamulti-yearcybersecuritystrategyalignedwithbusinessgrowth,riskappetite, and regulatory obligations.
  • Establishandmaintaintheinformationsecuritypolicyframework,reviewedatleastannually.
  • Maintainthecyberriskregisterandownthesecuritymaturityroadmapagainstarecognisedcontrol framework (NIST CSF, CIS Controls, or ISO 27001).
  • Ownthesecurityriskacceptanceandexceptionregister.
  • Providesecurityleadershipandadvisorytoexecutivemanagementandregulatorystakeholders.

Threat&VulnerabilityManagement

  • Directtheenterprisevulnerabilitymanagementprogramme,includingscanning,risk-based prioritisation, and remediation SLA enforcement.
  • Overseethepenetrationtestingprogrammeandensurefindingsareremediatedandretestedwithin defined timelines.
  • Maintainthreatintelligencecapabilityrelevanttofinancialservicesandpayments,andtranslateit into detection and control improvements.

SecurityOperations

  • Overseesecuritymonitoring,detection,andresponsecapabilitiesincludingSIEM,EDR/XDR,and SOC operations (internal or MSSP-managed).
  • Own incident responseend to end: maintain and test playbooks, run tabletop exercises, lead containmentandrecovery,andcoordinateregulatorynotificationwithinapplicabledeadlines.
  • ManageidentityandaccessgovernanceincludingRBACdesign,privilegedaccessmanagement, joiner/mover/leaver controls, and periodic access recertification.
  • Defineandenforcedatalosspreventionanddataclassificationstandardsacrossallplatforms.

Regulatory&Compliance(FirstLine)

  • MaintainoperationalcompliancewithPCIDSS,CBUAEtechnologyandinformationsecurityrisk requirements, UAE Information Assurance standards, and applicable payment scheme obligations.
  • Serveasprimarysecurityliaisontoexternalauditors,QSAs,andregulatoryexaminers.
  • Ensuresecuritycontrolsaredocumented,evidenced,tested,andaudit-readyatalltimes.
  • Trackandclosesecurity-relatedauditandexaminationfindingswithinagreedtimelines.

DataProtection&Privacy

  • ImplementandmaintainsecuritycontrolssupportingUAEPDPLandapplicablecross-borderdata transfer obligations, in coordination with Legal and the Data Protection Officer.
  • Supportprivacyimpactassessmentsanddatabreachassessmentandnotification.

SecurityArchitecture

  • Providesecurityinputtosystemdesign,changerequests,andnewinitiatives,andapprovesecurity architecture standards and baseline configurations.
  • Embedsecurity-by-designintheengineeringlifecycle,includingsecureSDLC,codereview, dependency scanning, secrets management, and CI/CD pipeline controls.
  • MaintaincloudsecurityposturestandardsfortheAWSestate.

CyberResilience

  • Ensurecyberscenariosarerepresentedinbusinesscontinuityanddisasterrecoveryplanningand testing.
  • Validatebackupintegrity,immutability,andrecoverycapabilityagainstdestructiveattack scenarios.

Third-PartySecurity

  • Assessthesecuritypostureofprospectiveandexistingthirdpartiesandoutsourcedproviders, proportionate to criticality and data exposure.
  • DefinesecurityrequirementsforvendorcontractsincoordinationwithLegalandProcurement.
  • Managesecurityserviceproviders(MSSP,penetrationtestingfirms,consultants)againstdefined SLAs.

People&Capability

  • Leadanddevelopthesecurityteam.
  • Drivesecurityawarenessthroughtrainingprogrammesandphishingsimulations.
  • Fosteraconstructivesecurityculturethatenablessafeescalationandreporting.

Reporting

  • Monthlysecurityreporting totheCTO.
  • StandingquarterlysecurityandcyberriskupdatetotheBoardRisk Committee.
  • ImmediatenotificationofmaterialincidentstotheCTO,CEO,andChiefRisk Officer.

Requirements

Experience

  • 10+yearsofprogressiveexperienceininformationsecurity,withatleast5yearsinaleadership role.
  • Demonstratedexperienceinaregulatedfinancialservicesenvironment(banking,payments, fintech, or SVF).
  • Hands-onexperiencewiththePCIDSScompliancelifecycleinapaymentenvironment.
  • Proventrackrecordofleadingincidentresponseduringlivesecurityevents.
  • ExperiencemanagingSOCoperations(internalorMSSP)includingSIEM,EDR/XDR,andthreat intelligence.
  • Strongunderstandingofcloudsecurity(AWSpreferred),containerandKubernetessecurity,and API security.
  • Experiencewithregulatoryframeworks:CBUAEtechnologyandinformationsecurityrisk circulars, UAE IA, or equivalent.
  • DemonstratedabilitytocommunicatesecurityrisktoexecutiveandBoard-levelaudiences.
  • Experiencemanagingthird-partysecurityvendorsandserviceproviders.
  • Experiencebuildinganddevelopingsecurityteams.
  • Demonstratedabilitytodeliversecurityoutcomeswithinconstrainedbudgets,prioritisingrisk reduction per unit of spend.

Leadership&SoftSkills

  • Strongstrategicthinkingwithabilitytotranslateriskintobusiness language.
  • Abilitytoinfluencewithoutauthorityacrossengineering,product,andbusinessteams.
  • Clearcommunicatorwhocanbriefexecutivesandregulatorsunderpressure.
  • CollaborativeapproachwithEngineering,Operations,GRC,andbusinessstakeholders.
  • Comfortableinfast-paced,scalingenvironmentswithevolvingpriorities.

Qualifications

  • Bachelor'sdegreeinComputerScience,Cybersecurity,InformationTechnology,orarelatedfield, or equivalent professional experience.
  • Industrycertificationsrequired(oneormore):CISSP,CISM,CISA,orISO27001LeadAuditor.
  • Additionalcertificationsvalued:PCIP,OSCP,CCSK,CRISC,AWSSecuritySpecialty.

TechnologyEnvironment

AWS(Lambda,ECS,EKS,RDS,CloudFront,WAF),Kubernetes,Kafka,PostgreSQL,Java/SpringBoot, React, React Native, Datadog, Microsoft 365/Entra ID, Terraform.

AdditionalConditions

  • Participationinanon-callescalationrotaforsecurityincidents.
  • Availabilityoutsidestandardhoursduringliveincidentsandmajorchangeevents.
  • Appointmentsubjecttoenhancedbackgroundscreeningappropriatetoaregulatedfinancial services control function.

Standorte
Dubai, United Arab Emirates
Ausbildung
bachelor degree
Berufserfahrung
10+ Jahre

Kategorien

Fähigkeiten

Wir verwenden Cookies

Wir verwenden Cookies, um die Nutzung dieses Boards zu verstehen und es zu verbessern. Analyse-Cookies laufen nur, wenn du zustimmst. Cookie-Richtlinie