
Lead – Information Security Risk & Assurance
- دبي
- دائم
- دوام كامل
- Define and establish the Information Security Risk capabilities, including governance frameworks, policies, reporting lines, and operating model.
- Partner with Enterprise Risk and Internal Audit to embed security risk into the Group's Three Lines of Defence and Enterprise Risk Management (ERM) framework.
- Translate complex technical risks into clear, actionable business insights and recommendations, aligned to Group objectives and risk appetite.
- Deliver quarterly security risk briefings, dashboards, and thematic risk deep dives for Executive Leadership and Board-level committees as required.
- Design and implement a scalable, metrics-driven security risk management framework covering risk identification, assessment, treatment, monitoring, and reporting.
- Establish and maintain a centralised Information Security Risk Register, ensuring ownership, tracking, and oversight of key risks and mitigation plans.
- Ensure continual improvement, compliance and ISO/IEC 27001 certification, driving maturity across the ISMS and control environment.
- Lead annual PCI DSS assurance and compliance programmes across retail, payments, and commerce channels.
- Provide assurance and second-line oversight over security incident management, including root cause analysis, response effectiveness, and post-mortem controls evaluation.
- Champion a culture of risk ownership, continuous learning, and control improvement following security events.
- Lead the development and delivery of a Group-wide information security risk education and training programme, tailored by audience and risk level.
- Equip business and technology stakeholders with practical knowledge to identify, assess, and own security risks as part of day-to-day operations.
- Collaborate with Group Risk, Internal Audit, and People & Culture to embed risk responsibilities into role-based learning paths, onboarding, and manager training.
- Track effectiveness of training initiatives through KPIs and maturity assessments, continuously evolving content and engagement strategies.
- Actively support a culture of proactive risk awareness, clear accountability, and continuous improvement across the organisation.
- The ideal candidate will bring deep expertise in information security and enterprise risk management, with relevant qualifications such as CISA, CRISC, or ISO 27005, and proven experience embedding risk frameworks aligned to ISO 27001, NIST RMF, or FAIR in complex, multinational environments.
- Minimum 7 years of experience in Information Security or Technology Risk roles, with at least 5 years in a leadership capacity.
- Demonstrated experience building or maturing a Group-level security risk and assurance function in a complex, regulated or multinational environment.
- Proven leadership in achieving and maintaining ISO 27001 certification, PCI DSS compliance.
- Solid understanding of frameworks and standards such as ISO 27001/27005, NIST CSF/RMF, COBIT, FAIR, and the Three Lines of Defence model.
- Experience designing and delivering enterprise training or awareness programmes on risk and compliance topics is a distinct advantage.