About the Role
In this leadership position, you will spearhead the organization’s cyber strategy, manage security investment portfolios, oversee third-party cyber risk, and enhance cyber resilience capabilities. Your primary objective is to align enterprise priorities and risk appetite with a funded multi-year roadmap that ensures critical services can prepare for, withstand, respond to, and recover from significant cyber disruptions.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Principal Duties and Responsibilities
1. Core Accountabilities
- Own the cyber strategy, target-state operating model, multi-year roadmap, and lead the annual strategy refresh cycle.
- Govern portfolio prioritization, business cases, benefits, dependencies, OpEx and CapEx, and provide executive-level performance reporting.
- Maintain the cyber resilience strategy and crisis-management framework and oversee exercises, cyber recovery readiness, and lessons learned.
- Oversee the first-line third-party cyber risk program and ensure supplier risks are assessed and treated through the procurement lifecycle.
- Establish central remediation governance, risk-based prioritization, and escalation for overdue or SLA-breaching security issues.
- Set objectives, service measures, and accountability across strategy, resilience, remediation, and third-party risk teams.
2. Governance Stakeholder and Reporting Responsibilities
- Maintain clear operating procedures, evidence, service metrics, and management reporting for the assigned security services.
- Coordinate with IT operations, architecture, application, risk, compliance, audit, and business stakeholders to resolve control gaps and delivery dependencies.
- Escalate material risks, incidents, SLA breaches, and control weaknesses through the approved governance and incident-management channels.
- Support regulatory examinations, internal and external audits, risk assessments, and management committees by providing accurate evidence and subject-matter input.
Personnel Specification
1. Education and Experience
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline; a relevant master’s degree is advantageous.
- 10-15 years of experience, including at least 5 years in cyber leadership, strategy, resilience, or portfolio governance.
- Demonstrated experience in a regulated, high-availability, or financial services environment is strongly preferred.
2. Technical Knowledge and Skills
- Cyber strategy, operating-model design, portfolio governance, and executive reporting.
- Cyber resilience, crisis management, Business Impact Analysis (BIA), IT disaster recovery, and cyber recovery.
- Financial planning, investment prioritization, supplier governance, and benefits realization.
- Enterprise risk management, third-party risk, and regulatory expectations for financial services.
- Working knowledge of NIST Cybersecurity Framework 2.0, ISO/IEC 27001, and the control lifecycle from design through operation and assurance.
- Ability to translate business, regulatory, and risk requirements into measurable security outcomes, procedures, and service metrics.
- Strong analytical, written communication, stakeholder-management, and evidence-management skills in a regulated environment.
3. Operational and Behavioral Skills
- Sound judgment, integrity, and the ability to handle sensitive information and high-pressure situations appropriately.
- Ability to prioritize risk, manage competing demands, and deliver clear decisions, actions, and escalation.
- Strong collaboration, influencing, and communication skills across technical, business, and executive audiences.
- Commitment to measurable service quality, continuous improvement, and disciplined documentation.
- Ability to work effectively with internal teams, external suppliers, auditors, and regulators.
Desired Certifications
- CISSP or CISM
- CRISC or CGEIT
- ISO 22301 Lead Implementer or CBCI/MBCI
- PMP or PRINCE2 Practitioner