About this Information Security Manager - Governance (1-Year Contract) role at Capitex
Capitex is engaging an Information Security Manager - Governance for a one-year contract with a leading UAE bank, based on-site in Dubai.
Working directly under the Head of Information Security, you will develop and implement the security measures that keep the bank's information assets safe - identifying gaps in existing IS policies, standards, guidelines and procedures, and bringing them into alignment with regulatory requirements and industry standards.
Key responsibilities:
- Assist in the development of the information security strategy and roadmap across all security technology domains
- Manage end-to-end security projects including UAE IA (NESA) assessments, PCI DSS, SWIFT CSP controls and VAPT
- Verify and validate closure of gaps identified during regulatory assessments and audits, recommending alternative solutions where needed
- Act as the Information Security lead for technology, digital transformation, cloud, infrastructure, application and business projects
- Manage multiple security and compliance projects simultaneously, prioritising by business impact and risk
- Ensure information security requirements are addressed through project initiation, planning, design, implementation, testing and go-live
- Coordinate with PMO and business project managers to integrate security activities into project plans
- Maintain security governance frameworks - policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance
- Manage audit and regulatory findings through remediation and validated closure
- Establish risk-based processes for third-party due diligence, onboarding, assessment, monitoring and offboarding
- Manage the development and delivery of security awareness and training programmes
- Advise IS management on information security risk issues in support of the bank's wider risk management programmes
Requirements
Strong information security experience within the banking/financial sector - essential, given exposure to banking systems, regulatory requirements and volume of concurrent activities
Around 10-12 years of relevant information/cyber security experience with manager-level responsibilities
Strong information security governance/GRC experience covering policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance
Hands-on experience with UAE IA/NESA - implementation, assessments and policy/control alignment
Experience managing PCI DSS, SWIFT CSP, VAPT and regulatory/security assessments
Proven experience managing audit/regulatory findings through remediation and validated closure
Experience acting as information security lead on major technology, digital, cloud, infrastructure and application projects
Ability to manage multiple security/regulatory projects simultaneously, coordinating with IT, Business, Risk, Audit, Compliance, PMO and external parties
Professional certification: CISM, CRISC, CISA and/or CISSP preferred
Bachelor's degree
Strong communication skills - able to engage senior non-technical stakeholders without technical language
Benefits
One-year contract with a leading UAE bank, on-site in Dubai
Competitive all-inclusive monthly package - salary, UAE visa, Emirates ID and medical insurance all covered
Full Employer of Record support throughout the engagement, with end-of-service benefits accrued per UAE labour law