Information Security Manager - Governance
Listed on 2026-09-29
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Key responsibilities
- Assist in the development of the information security strategy and roadmap across all security technology domains
- Manage end-to-end security projects including UAE IA NESA assessments PCI DSS SWIFT CSP controls and VAPT
- Verify and validate closure of gaps identified during regulatory assessments and audits recommending alternative solutions where needed
- Act as the Information Security lead for technology digital transformation cloud infrastructure application and business projects
- Manage multiple security and compliance projects simultaneously prioritising by business impact and risk
- Ensure information security requirements are addressed through project initiation planning design implementation testing and go-live
- Coordinate with PMO and business project managers to integrate security activities into project plans
- Maintain security governance frameworks - policies standards risk assessments risk registers risk acceptance exceptions and compliance
- Manage audit and regulatory findings through remediation and validated closure
- Establish risk-based processes for third-party due diligence onboarding assessment monitoring and offboarding
- Manage the development and delivery of security awareness and training programmes
- Advise IS management on information security risk issues in support of the bank s wider risk management programmes
- Strong information security experience within the banking financial sector - essential given exposure to banking systems regulatory requirements and volume of concurrent activities
- Around 10-12 years of relevant information cyber security experience with manager-level responsibilities
- Strong information security governance GRC experience covering policies standards risk assessments risk registers risk acceptance exceptions and compliance
- Hands‑on experience with UAE IA NESA - implementation assessments and policy control alignment
- Experience managing PCI DSS SWIFT CSP VAPT and regulatory security assessments
- Proven experience managing audit regulatory findings through remediation and validated closure
- Experience acting as information security lead on major technology digital cloud infrastructure and application projects
- Ability to manage multiple security regulatory projects simultaneously coordinating with IT Business Risk Audit Compliance PMO and external parties
- Professional certification CISM CRISC CISA and or CISSP preferred
- Bachelor s degree
- Strong communication skills - able to engage senior non-technical stakeholders without technical language
One-year contract with a leading UAE bank on-site in Dubai
Competitive all-inclusive monthly package - salary UAE visa Emirates medical insurance all covered
Full Employer of Record support throughout the engagement with end-of-service benefits accrued per UAE labour law
Strong information security experience within the banking/financial sector - essential, given exposure to banking systems, regulatory requirements and volume of concurrent activities
Around 10-12 years of relevant information/cyber security experience with manager-level responsibilities
Strong information security governance/GRC experience covering policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance
Hands-on experience with UAE IA/NESA - implementation, assessments and policy/control alignment
Experience managing PCI DSS, SWIFT CSP, VAPT and regulatory/security assessments
Proven experience managing audit/regulatory findings through remediation and validated closure
Experience acting as information security lead on major technology, digital, cloud, infrastructure and application projects
Ability to manage multiple security/regulatory projects simultaneously, coordinating with IT, Business, Risk, Audit, Compliance, PMO and external parties
Professional certification: CISM, CRISC, CISA and/or CISSP preferred
Bachelor's degree
Strong communication skills - able to engage senior non-technical stakeholders without technical language
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).