Company logo hidden

Cybersecurity Advisory & Assurance Lead

Unlock employer Dubai, United Arab Emirates Direct to Company Under an hour ago · 07 Oct 2026

Financial

  • Estimate: $120k - $180k*
  • Zero income tax location

Accessibility

  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional

Position

About the Role
The Cybersecurity Advisory & Assurance Lead is a senior role for a hands-on cybersecurity professional responsible for leading complex cybersecurity assessments, advisory engagements, and transformation programs for enterprise and government clients. This position requires independent execution of comprehensive framework-based assessments, including NIST CSF, NIST SP 800-series, ISO/IEC 27001, CIS Controls, and relevant UAE/GCC regulatory requirements. The Cybersecurity Advisory & Assurance Lead will manage engagements from initial customer workshops through various phases, including evidence collection, technical assessment, control testing, maturity evaluation, gap analysis, risk identification, and remediation planning, culminating in executive presentations. The candidate will serve as a technically credible adviser to CISOs, SOC teams, infrastructure, cloud, architecture teams, and senior management.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Duties & Responsibilities

  • Lead enterprise-wide cybersecurity maturity and capability assessments, covering governance and the Identify, Protect, Detect, Respond, and Recover functions based on NIST CSF.
  • Conduct control design and operational effectiveness assessments, ensuring technical controls are implemented effectively.
  • Review cybersecurity policies, standards, procedures, and operating models against established frameworks such as NIST CSF, ISO/IEC 27001/27002, CIS Critical Security Controls, and UAE Information Assurance requirements.
  • Assess and advise on defensive security and SOC capabilities, including SOC operating models, SIEM, security monitoring, detection engineering, incident response, and cyber crisis management.
  • Evaluate security architecture across enterprise infrastructure, cloud, and hybrid environments, including network, identity, endpoint, and application security.
  • Assess effectiveness and maturity of cybersecurity processes like risk, vulnerability, incident response, and security monitoring.
  • Interpret penetration testing and red-team assessments and support remediation processes in partnership with offensive-security specialists.
  • Conduct governance and cyber-risk assessments and map controls across regulatory frameworks.
  • Identify security gaps, risks, and control weaknesses and develop prioritized remediation roadmaps.
  • Develop maturity models, heatmaps, risk registers, and management dashboards; produce reports for executives and technical teams.
  • Present findings and recommendations to senior stakeholders, translating technical complexities into business risks and practical advice.
  • Lead customer workshops and interviews, define methodologies, and maintain evidence traceability.
  • Manage assessment workstreams and guide junior consultants, while challenging customer assumptions professionally.
  • Support proposals, statements of work, and customer presentations, assisting Account Managers in identifying cybersecurity opportunities.

Qualifications
Education

  • Required: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or Engineering (Electronics, Computer, or Telecom).
  • Desirable:
    • Master’s degree (e.g., MSc in Cybersecurity or Information Security, MBA with technology focus).
    • Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, CISA, CCSP, GIAC, or NIST-related certifications.
    • Technical/offensive certifications (e.g., OSCP, PNPT, CEH) or equivalent practical experience.

Experience

  • Required:
    • 8+ years of cybersecurity experience across multiple disciplines.
    • Proven experience leading enterprise cybersecurity assessments.
    • Experience in stakeholder interviews and evidence-based assessments.
    • Experience producing executive-level reports and presenting to senior stakeholders.
  • Desirable:
    • 12+ years of cybersecurity experience.
    • Experience in government, critical infrastructure, financial services, aviation, energy, or other highly regulated sectors.

Skills & Abilities

  • Required:
    • Strong practical knowledge of NIST CSF, ISO 27001, and cybersecurity control frameworks.
    • Strong understanding of SOC/security operations, security architecture, and enterprise controls.
    • Working knowledge of offensive-security methodology and major cybersecurity technology categories.
    • Excellent report writing, workshop facilitation, and executive communication skills.
    • Ability to work independently across technical, operational, and governance discussions.
  • Desirable:
    • Knowledge of UAE Information Assurance and GCC cybersecurity regulations.
    • Experience with PCI DSS, SWIFT CSP, and cloud security frameworks.
    • Exposure to OT/ICS security assessments.

Additional Information
Compliance with policies and procedures based on the ISO standards adopted by the organization.

Apply Direct

Jobs you might like   View all jobs

About Trading & Investment Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct