Assistant Manager, Security Governance & Compliance (UAE National)

Commercial Bank of Dubai

Dubai

On-site

AED 240,000 - 420,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Commercial Bank of Dubai is seeking an Information Security Governance & Compliance professional to lead the design and ongoing improvement of the bank's information security governance framework. You will monitor policy adherence and drive risk-based decision making.

The role requires 5–7 years of experience, CISSP/CISM or similar, and a deep understanding of ISO 27001, NIST, PCI-DSS, UAE regulations. You will coordinate audits, manage risk registers, and deliver management reporting to protect

Qualifications

  • Minimum 5–7 years of information security governance and compliance experience.
  • Experience in audit coordination, control testing, and remediation tracking.
  • Strong understanding of ISO 27001, NIST, PCI-DSS, and UAE regulatory requirements.
  • Ability to design and implement security policies, standards, and metrics.

Responsibilities

  • Design and enhance an information security governance framework aligned with regulatory obligations.
  • Develop dashboards and reporting on control effectiveness and risk posture.
  • Lead policy development, reviews, and enforcement across the bank.
  • Drive security awareness programs and training.
  • Oversee third-party security governance and supplier risk.
  • Coordinate audit activities and regulatory deliverables.

Skills

Information security governance
Risk management
Regulatory compliance
Audit coordination
Threat modelling
Policy management
Security controls
Stakeholder engagement

Education

Bachelor’s degree in Information Security / Cybersecurity / IT
CISSP / CISM / CISA / CRISC / ISO 27001 Lead Implementer Lead Auditor

Tools

ISO 27001
NIST
PCI-DSS
UAE regulatory requirements (NESA / UAE IA)
SWIFT CSP

Job description

Job Purpose:

To support the implementation, monitoring, and continuous improvement of the Bank’s information security governance and compliance framework. The role assists in maintaining security policies, standards, controls, risk registers, regulatory compliance deliverables, audit coordination, third-party security governance, awareness activities, and management reporting to ensure that the Bank’s information assets, systems, and processes remain protected and aligned with internal requirements, regulatory obligations, and industry best practices.

Key Accountabilities:
Security Governance & Compliance
  • Strategic Framework Development: Design, implement, and continuously enhance a comprehensive information security governance framework that aligns with the bank’s strategic goals, regulatory obligations, and risk appetite.
  • Security Metrics & Reporting: Develop and maintain dashboards and reporting mechanisms that aggregate security control effectiveness, risk posture, and compliance status across the organization.
  • Policy Management: Establish, review, and enforce enterprise-wide security policies, standards, and procedures to ensure consistent implementation and adherence.
  • Awareness & Training: Lead the development and delivery of targeted security awareness programs, including phishing simulations, role-based training, and executive briefings to foster a culture of security.
  • Regulatory Compliance: Ensure ongoing compliance with international and UAE-specific regulatory frameworks and standards such as ISO/IEC 27001, NIST, PCI-DSS, NESA, UAE IA, SWIFT CSP, and others.
Security Assurance
  • Risk & Vulnerability Management: Conduct comprehensive risk assessments and vulnerability analyses across various domains including ISMS, projects, change initiatives, thematic reviews, and third-party engagements.
  • Threat Modelling & DevSecOps Integration: Implement threat modelling practices within the software development lifecycle and change management processes to proactively identify and mitigate risks.
  • Third-Party Risk Management: Oversee a robust third-party security assessment program that spans the entire supplier lifecycle—from onboarding and due diligence to ongoing monitoring and offboarding.
Collaboration & Strategic Engagement
  • Cross-Functional Integration: Partner with business units, IT, legal, compliance, and risk teams to embed security into business processes, digital transformation initiatives, and strategic projects.
  • Security Advocacy & Thought Leadership: Stay abreast of emerging threats, technologies, and industry trends. Share insights with internal stakeholders and contribute to the bank’s strategic security roadmap.
Requirements:
Experience & Academic Qualifications:
  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Risk Management, or a related discipline.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer / Lead Auditor, or equivalent are preferred.
  • Minimum 5–7 years of experience in information security, cybersecurity governance, IT risk, technology compliance, audit, or related functions, preferably within banking or financial services.
  • Good understanding of information security governance frameworks, regulatory requirements, risk management practices, security controls, and internal policy management.
  • Experience in audit coordination, compliance monitoring, control testing, evidence management, policy review, risk registers, management reporting, and remediation tracking.
  • Knowledge of cybersecurity standards and frameworks such as ISO 27001, NIST, PCI-DSS, SWIFT CSP, UAE regulatory requirements, and data protection principles is preferred.
  • Experience of Threat Modelling (MITRE ATT@CK, STRIDE, OWASP etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate Information Security- Emirati
Senior Associate Information Security- Emirati

Fisher Human Resource Consultancy • Dubai

On-site
AED 180,000 - 300,000
Cybersecurity Consultant
Cybersecurity Consultant

Mada Media • Dubai

On-site
AED 300,000 - 600,000
Manager Information Security - Emirati Talent
Manager Information Security - Emirati Talent

Commercial Bank International • Sharjah

On-site
AED 180,000 - 240,000
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services

Jobsatdubai • Dubai

On-site
AED 334,800 - 502,200
Assistant Manager, Security Operation & Incident Management (UAE National)
Assistant Manager, Security Operation & Incident Management (UAE National)

Commercial Bank of Dubai • Dubai

On-site
AED 420,000 - 660,000
Cybersecurity Consultant
Cybersecurity Consultant

Dubai Careers - A Smart Dubai Initiative • Dubai

On-site
AED 300,000 - 420,000
Security Admin (UAE National)
Security Admin (UAE National)

Dicetek LLC • Dubai

On-site
AED 260,000 - 520,000
Information Security Consultant
Information Security Consultant

United Al Saqer Group • Abu Dhabi

On-site
AED 180,000 - 260,000
Assistant Analyst - Data Security
Assistant Analyst - Data Security

ADIB - Abu Dhabi Islamic Bank • Abu Dhabi

On-site
AED 180,000 - 240,000
Executive - Information Security
Executive - Information Security

Dubai Chambers • Dubai

On-site
AED 89,000 - 156,000