About the Role
As a Senior Consultant/Manager specializing in Cyber Performance Management, you will play a pivotal role in designing and implementing cybersecurity performance management frameworks. This position allows you to demonstrate and develop your capabilities in areas such as defining success metrics for cybersecurity functions, working closely with governance teams, measuring services and program performance, building dashboards and reports, and driving improvements across the cybersecurity domain.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Key Responsibilities
-
Design the Performance Framework
- Create the cybersecurity performance management framework, including objectives, KPIs, KRIs, SLAs, targets, thresholds, data sources, ownership, collection frequency, and reporting lines.
- Write and maintain supporting methodology, procedures, and SOPs for data collection, validation, calculation, review, and sign-off.
- Ensure alignment of metrics with cybersecurity strategy, NCA ECC requirements, and NIST CSF 2.0, focusing on measuring outcomes and risk reduction rather than just activity.
- Regularly review and refine metrics, retiring those that no longer support decision-making.
-
Define Success Metrics for Cybersecurity Functions and Roles
- Collaborate with domain leads to define clear success metrics for each cybersecurity function, such as:
- Strategy and architecture: roadmap milestones delivered, maturity uplift, designs reviewed before go-live, architecture exceptions open.
- Vulnerability management and penetration testing: scan coverage, remediation within SLA, ageing of critical vulnerabilities, retest closure rate, repeat findings.
- Application and OT security: applications onboarded to secure SDLC, critical code findings fixed prior to release, OT assets inventoried and monitored.
- Risk and compliance: risks assessed and treated on time, overdue treatment plans, NCA ECC compliance score and trend.
- Third-party and supply chain: critical suppliers assessed prior to onboarding, reassessments conducted on time, high-risk findings addressed.
- Governance and awareness: approved policies, committee actions closed, training completion.
- Define how each metric is measured, including formula, data source, baseline, target, frequency, owner, and evidence for audit consistency.
- Set measures at three levels: programme outcomes, function performance, and role/team contributions, ensuring visibility of how individual efforts contribute to results.
- Assist domain leads in employing metrics for team objectives and performance evaluations.
-
Work with the Governance Team
- Collaborate with the Governance & PMO team to understand governance implementation requirements, including approved policies and committee decisions.
- Translate requirements into measurable indicators related to policy implementation and adherence.
- Monitor the implementation of governance decisions and report any gaps to the Governance team and steering committee.
- Provide performance evidence for ISMS management reviews and NCA compliance reporting.
-
Measure Services and the Program
- Monitor service levels and performance of managed security services and key vendors, conducting monthly service reviews with actionable outcomes.
- Track programme delivery and benefits against plans alongside the PMO.
- Measure cybersecurity maturity and NCA compliance trends over time in collaboration with Strategy and Compliance teams.
-
Build Dashboards and Reports
- Create and maintain dashboards and scorecards for the CISO, steering committee, and board, utilizing tools such as Power BI.
- Automate data collection from various sources like security tools, GRC, TPRM, and ticketing platforms for timely reports.
- Generate monthly and quarterly performance reports in clear, executive-friendly language explaining changes, their causes, and necessary actions moving forward.
-
Drive Improvement
- Identify negative trends and missed targets early, analyzing root causes and agreeing on improvement actions.
- Track improvement actions to completion and illustrate their impacts in later reports.
- Validate data quality and question figures that do not align.
Qualifications
- 4-8 years of total professional experience.
- Bachelor's degree in IT, cybersecurity, business, data analytics, or a related field.
- Experience in designing or managing KPI/KRI or SLA performance frameworks across multiple functions.
- Familiarity with cybersecurity domains, including third-party and supply chain risk.
- Proficient in data skills: Excel and Power BI (or Tableau), including data modelling.
- Knowledge of managing SLAs and service performance (ITIL).
- Strong capability in written English for executive-level reporting.
- Proficient in SQL or Python for data extraction and automation.
- Experience in linking organizational KPIs to team and individual objectives.
- Existing experience with managed security services (MSSP) contracts and service reviews.
- Familiarity with maturity assessment models.
- Knowledge of ISO/IEC 27004 and NIST SP 800-55.
- Proficiency in Arabic is a plus.
- At least one of the following certifications: ITIL 4, CISM, Microsoft Power BI Data Analyst (PL-300) is preferred.
- Awareness of NIST CSF 2.0, NIST SP 800-55, ISO/IEC 27004, NCA ECC-2:2024, ITIL 4, COBIT 2019, and Balanced Scorecard.
Leadership Capabilities
- Builds understanding of purpose and values; seeking opportunities for impact.
- Displays a strong commitment to personal learning and development; acts as a brand ambassador to attract top talent.
- Understands expectations and takes personal accountability to keep performance on track.
- Actively focuses on developing effective communication and relationship-building skills.
- Recognizes how daily work contributes to team and business priorities.