About the Job:
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Job Purpose
This role exists to lead the first-line-of-defense "operate" pillar across all markets, ensuring the day-to-day protection, detection, response, and offensive-testing capability that maintains the operations of a systemically important payments processor. The Deputy Group CISO will provide continuity of leadership in the absence of the Group CISO, ensuring that the function's 24/7 resilience commitments to regulators, card schemes, and merchant clients are upheld without reliance on a single point of failure.
The role integrates Protect, Detect & Respond, Identify (Red Team and vulnerability management), Identity & Access operations, and Secure Transaction Processing under a single leader, managing a blend of in-house staff, Centre-of-Excellence resources in Jordan and Egypt, and managed security service partners. Success is gauged by the organization's capability to swiftly detect and respond to threats while assuring the Board and regulators of the integrity of the control environment.
Job Responsibilities
- Lead the Cyber Resilience Operations pillar end-to-end, encompassing Protect (endpoint, email, DLP/Netskope, network security, cloud security posture management, secure configuration and hardening, secure transaction processing), Identify (vulnerability identification, continuous threat exposure management), Detect & Respond (security monitoring, threat hunting, threat intelligence, incident response), and Identify/Red Team (penetration testing, red teaming, offensive security).
- Ensure first-line accountability for identity and access operations, overseeing the operational implementation of zero-trust security principles and the transition of IDAM to the Centre of Excellence in Jordan.
- Govern managed security service provider relationships, focusing on detection, response, and offensive-testing capabilities at scale, including SLA performance and service review cadence.
- Maintain 24/7 security operations resilience across all market footprints, ensuring continuous monitoring, detection, and incident-response coverage.
- Act as Major-Incident Commander during severe security events, directing resolution efforts alongside the Group Incident Response Lead and stakeholders.
- Deputize for the Group CISO on operational matters in their absence, ensuring leadership continuity in key governance committees while preserving segregation of duties.
- Oversee the internal Red Team and vulnerability management function, ensuring independent delivery of PCI DSS testing, threat-led penetration testing, and compliance with regulatory resilience-testing requirements.
- Establish and monitor operational KRIs and KPIs for the pillar, transparently reporting performance to the Group CISO and governance committees.
- Manage the Cyber Resilience Operations budget and commercial governance, focusing on business-case development, investment prioritization, contract oversight, and value realization from security service providers.
- Ensure security monitoring and effectiveness extend to emerging technologies, including AI-enabled systems adopted by the Group.
- Collaborate with Business Continuity Management and IT Disaster Recovery on recovery testing, incorporating cyber-incident scenarios into organization-wide resilience testing.
- Lead, coach, and develop the leadership team within the pillar, reinforcing bench strength and succession depth.
- Represent Cyber Resilience Operations in engagements with external stakeholders, including regulators, card schemes, auditors, and clients, to provide operational resilience assurance.
Experience / Skills Required
Education & Certifications
- Bachelor’s degree in computer science, information security, engineering, or a related discipline; a relevant master’s degree is advantageous.
- Essential certifications include CISSP (Certified Information Systems Security Professional) and CISM (Certified Information Security Manager).
- Preferred certifications include GIAC GCIH or equivalent incident-response certification, CCISO, CCSP (Certified Cloud Security Professional), ISO/IEC 27001 Lead Auditor or Lead Implementer, and relevant offensive-security certification (e.g., OSCP, CRTO) to support Red Team operations.
Experience
- Over 15 years of progressive experience in cyber security operations, with a minimum of 8 years in senior leadership roles directing security operations, incident response, or offensive security functions.
- Solid experience operating within banking, fintech, or critical infrastructure environments.
- Proven background in governing outsourced/managed security service providers (MSSPs) at scale, including SLA management and service governance.
- Familiarity with MEA regulatory environments, including CBUAE, SAMA, and related central bank cybersecurity frameworks.
- Experience leading major-incident command during high-severity cyber events, coordinating with executive leadership, legal, and communications teams.
- History of building and leading multi-site, multi-cultural security teams using Centres of Excellence and managed service models.
Competencies — Functional Skills (Cyber Security)
- Cyber Defense — Mastery
- Cyber Incident Response — Mastery
- Cyber Resilience — Advanced
- Cyber Risk — Mastery
- Threat Detection — Mastery
- Vulnerability Management — Mastery
- Identity and Access Management — Advanced
- AI Governance and Security — Mastery
Competencies — Leadership & Behavioural
- Collaborate to Win — Advanced
- Set High Ambitions and Build Clear Plans — Advanced
- Lead with Clarity & Context — Advanced
- Adapt & Accelerate — Advanced
- Empower & Grow Talent — Advanced
Working Conditions:
- Primarily office-based with occasional travel required for meetings, conferences, and training sessions.
- Fast-paced and dynamic work environment.