Information Security Manager - Governance (1-Year Contract)

CapitexSharjah, SharjahOn-siteContractNew grad, 0–1 yearsListed 4 days ago

Apply now

About this role

Capitex is engaging an Information Security Manager - Governance for a one-year contract with a leading UAE bank, based on-site in Dubai.

Working directly under the Head of Information Security, you will develop and implement the security measures that keep the bank's information assets safe - identifying gaps in existing IS policies, standards, guidelines and procedures, and bringing them into alignment with regulatory requirements and industry standards.

Key responsibilities:

- Assist in the development of the information security strategy and roadmap across all security technology domains
- Manage end-to-end security projects including UAE IA (NESA) assessments, PCI DSS, SWIFT CSP controls and VAPT
- Verify and validate closure of gaps identified during regulatory assessments and audits, recommending alternative solutions where needed
- Act as the Information Security lead for technology, digital transformation, cloud, infrastructure, application and business projects
- Manage multiple security and compliance projects simultaneously, prioritising by business impact and risk
- Ensure information security requirements are addressed through project initiation, planning, design, implementation, testing and go-live
- Coordinate with PMO and business project managers to integrate security activities into project plans
- Maintain security governance frameworks - policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance
- Manage audit and regulatory findings through remediation and validated closure
- Establish risk-based processes for third-party due diligence, onboarding, assessment, monitoring and offboarding
- Manage the development and delivery of security awareness and training programmes
- Advise IS management on information security risk issues in support of the bank's wider risk management programmes

Requirements

Strong information security experience within the banking/financial sector - essential, given exposure to banking systems, regulatory requirements and volume of concurrent activities

Around 10-12 years of relevant information/cyber security experience with manager-level responsibilities

Strong information security governance/GRC experience covering policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance

Hands-on experience with UAE IA/NESA - implementation, assessments and policy/control alignment

Experience managing PCI DSS, SWIFT CSP, VAPT and regulatory/security assessments

Proven experience managing audit/regulatory findings through remediation and validated closure

Experience acting as information security lead on major technology, digital, cloud, infrastructure and application projects

Ability to manage multiple security/regulatory projects simultaneously, coordinating with IT, Business, Risk, Audit, Compliance, PMO and external parties

Professional certification: CISM, CRISC, CISA and/or CISSP preferred

Bachelor's degree

Strong communication skills - able to engage senior non-technical stakeholders without technical language

Benefits

One-year contract with a leading UAE bank, on-site in Dubai

Competitive all-inclusive monthly package - salary, UAE visa, Emirates ID and medical insurance all covered

Full Employer of Record support throughout the engagement, with end-of-service benefits accrued per UAE labour law