About the Role
We are seeking an Information Security Manager - Governance for a one-year contract with a leading UAE bank, based on-site in Dubai. In this role, you will work directly under the Head of Information Security, developing and implementing security measures to protect the bank's information assets. Your primary responsibility will be identifying gaps in existing information security policies, standards, guidelines, and procedures, and ensuring alignment with regulatory requirements and industry standards.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Key Responsibilities
- Assist in the development of the information security strategy and roadmap across all security technology domains
- Manage end-to-end security projects including UAE IA (NESA) assessments, PCI DSS, SWIFT CSP controls, and VAPT
- Verify and validate closure of gaps identified during regulatory assessments and audits, recommending alternative solutions where needed
- Act as the Information Security lead for technology, digital transformation, cloud, infrastructure, application, and business projects
- Manage multiple security and compliance projects simultaneously, prioritising by business impact and risk
- Ensure information security requirements are addressed through project initiation, planning, design, implementation, testing, and go-live
- Coordinate with PMO and business project managers to integrate security activities into project plans
- Maintain security governance frameworks including policies, standards, risk assessments, risk registers, risk acceptance/exceptions, and compliance
- Manage audit and regulatory findings through remediation and validated closure
- Establish risk-based processes for third-party due diligence, onboarding, assessment, monitoring, and offboarding
- Manage the development and delivery of security awareness and training programmes
- Advise Information Security management on information security risk issues in support of the bank's wider risk management programmes
Requirements
- Strong information security experience within the banking/financial sector is essential, given exposure to banking systems, regulatory requirements, and the volume of concurrent activities.
- Approximately 10-12 years of relevant information/cyber security experience with manager-level responsibilities.
- Strong information security governance/GRC experience covering policies, standards, risk assessments, risk registers, risk acceptance/exceptions, and compliance.
- Hands-on experience with UAE IA/NESA including implementation, assessments, and policy/control alignment.
- Experience managing PCI DSS, SWIFT CSP, VAPT, and regulatory/security assessments.
- Proven experience managing audit/regulatory findings through remediation and validated closure.
- Experience acting as information security lead on major technology, digital, cloud, infrastructure, and application projects.
- Strong ability to manage multiple security/regulatory projects simultaneously, coordinating with IT, Business, Risk, Audit, Compliance, PMO, and external parties.
- Professional certification such as CISM, CRISC, CISA, and/or CISSP is preferred.
- A Bachelor's degree is required.
- Strong communication skills with the ability to engage senior, non-technical stakeholders without using technical jargon.
Contract and Benefits
- One-year contract with a leading UAE bank, on-site in Dubai.
- Competitive all-inclusive monthly package, including salary, UAE visa, Emirates ID, and medical insurance coverage.
- Full Employer of Record support throughout the engagement, with end-of-service benefits accrued per UAE labour law.