Information Security Operations Lead
Job Description
Policy & Compliance:
Maintain IT IS policies aligned with NIST, ISO 27001, UAE CB, GDPR and PCI DSS; ensure audit readiness via periodic reviews.
Risk Management:
Lead enterprise risk assessments; maintain a dynamic cybersecurity risk framework; prioritize remediation by business impact.
Zero Trust & Network Security:
Design Zero Trust segmentation, mTLS, NDR, resilient perimeters, and secure remote access to block lateral movement and exfiltration.
VAPT:
Plan VAPT across OS, AI, cloud, apps, network, mobile; track remediation; coordinate external pen tests and integrate findings into vulnerability management.
Cloud & Container Security:
Embed DAST, SAST, container scanning, SCA into CI CD; enforce IaC scanning; image signing; runtime protections; CIS hardening; secrets management; runtime containment; secure environments in AWS, Azure, GCP.
Endpoint & Identity Protection:
Operate EDR, XDR; secure boot; immutable images; automated patching; PAM with JIT elevation; HSM encryption; tokenization; ephemer database credentials; DLP and data classification with retention/disposal.
- Security Ops:
Run SIEM, MDR, SOAR; threat hunting; incident response with lessons learned. - Third‑Party Governance:
Manage vendor due diligence, attestations, PIAs; act as primary liaison for audits and regulators. - Maintain IT IS policies aligned with NIST, ISO 27001, UAE CB and PCI DSS; conduct periodic reviews.
- Participate in enterprise risk assessments and maintain dynamic cybersecurity risk management framework.
- Design and operate Zero Trust segmentation, mTLS, NDR, resilient perimeters and secure remote access.
- Plan and oversee VAPT across all environments: OS, AI, cloud, apps, network, mobile; manage remediation tracking.
- Secure cloud container environments (AWS, Azure, GCP) by embedding SAST, DAST, container scanning, SCA, IaC scanning and runtime protections.
- Operate and review security controls: SIEM, EDR, Email Security Gateway, WAF, Antivirus; conduct regular security reviews.
- Regulatory compliance (NIST, ISO 27001, UAE CB, PCI DSS).
- Enterprise risk assessment.
- Zero Trust architecture.
- Network security: mTLS, NDR, segmentation.
- Secure remote access.
- VAPT (OS, AI, cloud, apps, network, mobile).
- Cloud/container security (AWS/Azure/GCP).
- CI/CD security: SAST, DAST, SCA, IaC.
- IAM, PAM, Patch Management, DLP, Endpoint protection (EDR/XDR, Antivirus).
- Security operations (SIEM, SOAR, threat hunting, incident response).
- Security controls review (WAF, Email Gateway, EDR, Antivirus).
- Third‑party governance & Dark web monitoring.
Bachelor or Master in Information Technology.
Experience6–10 years in Banking/Fintech.
Certifications- CISA
- ISO 27001
- CEH
- Risk management or CISSP
- CISM
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).