Chief Information Security Officer (CISO)

myZoi Financiallusion Technologies

Dubai

On-site

AED 600,000 - 900,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

myZoi Financiallusion Technologies in Dubai seeks a Chief Information Security Officer to lead the cybersecurity and information security programme across a regulated financial services environment. You will define and execute security strategy, own cyber risk, and ensure regulatory compliance within cloud-native payments and SVF operations.

Leading the security function, you will advise on risk, escalate to the CTO/CEO and Board Risk Committee, manage a defined annual security budget, and drive

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • Industry certifications such as CISSP, CISM, CISA, ISO27001 Lead Auditor.
  • 10+ years in information security with at least 5 years in leadership.
  • Experience in regulated financial services (banking, payments, fintech, or SVF).

Responsibilities

  • Define multi-year cybersecurity strategy aligned with business growth and regulatory obligations.
  • Maintain information security policy framework and annual reviews.
  • Oversee vulnerability management, scanning, prioritisation, and remediation SLAs.
  • Direct penetration testing programme and ensure timely remediation and retests.
  • Maintain threat intelligence relevant to financial services and translate into controls.

Skills

Cybersecurity leadership
Risk management
Regulatory compliance
Incident response
Cloud security
Executive communication

Education

Bachelor's degree in Computer Science / Cybersecurity / IT

Tools

SIEM
EDR/XDR
Vulnerability management tools

Job description

Chief Information Security Officer (CISO)

Dubai, United Arab Emirates | Posted on 08/11/2026

Leadthe organisation's cybersecurity and information security programme, ensuringthe confidentiality, integrity,andavailabilityofinformationassetsacrossaregulatedfinancialservicesenvironment.Defineand executesecurity strategy, own and manage cyber risk within Board-approved appetite,and maintain regulatory compliance within a cloud-native payments and storedvalue facility (SVF) operation.

Theroleadvisesandrecommendsonsecurityrisk,withindependentauthoritytoescalateunresolvedriskto the CTO, CEO, and Board Risk Committee.Operates within an approved annual security budget; spend proposals requirecost-benefit justification and are prioritised within the allocated envelope.

Key Responsibilities

  • Defineandmaintainamulti-yearcybersecuritystrategyalignedwithbusinessgrowth,riskappetite, and regulatoryobligations.
  • Establishandmaintaintheinformationsecuritypolicyframework,reviewedatleast annually.
  • Directtheenterprisevulnerabilitymanagementprogramme,includingscanning,risk-based prioritisation, and remediationSLA enforcement.
  • Overseethepenetrationtestingprogrammeandensurefindingsareremediatedandretestedwithin defined timelines.
  • Maintainthreatintelligencecapabilityrelevanttofinancialservicesandpayments,andtranslateit into detection and controlimprovements.
Security Operations
  • Overseesecuritymonitoring,detection,andresponsecapabilitiesincludingSIEM,EDR/XDR,and SOC operations(internal or MSSP-managed).
  • Own incident responseendto end: maintain and test playbooks, run tabletop exercises, lead containmentandrecovery,andcoordinateregulatorynotificationwithinapplicabledeadlines.
  • ManageidentityandaccessgovernanceincludingRBACdesign,privilegedaccessmanagement, joiner/mover/leaver controls,and periodic access recertification.
  • Defineandenforcedatalosspreventionanddataclassificationstandardsacrossall platforms.
Regulatory&Compliance(First Line)
  • MaintainoperationalcompliancewithPCIDSS,CBUAEtechnologyandinformationsecurityrisk requirements, UAE Information Assurance standards, and applicablepayment scheme obligations.
  • Ensuresecuritycontrolsaredocumented,evidenced,tested,andaudit-readyatall times.
  • Trackandclosesecurity-relatedauditandexaminationfindingswithinagreed timelines.
DataProtection& Privacy
  • ImplementandmaintainsecuritycontrolssupportingUAEPDPLandapplicablecross-borderdata transfer obligations, in coordination with Legal and theData Protection Officer.
  • Supportprivacyimpactassessmentsanddatabreachassessmentand notification.
  • Providesecurityinputtosystemdesign,changerequests,andnewinitiatives,andapprovesecurity architecture standards andbaseline configurations.
  • Embedsecurity-by-designintheengineeringlifecycle,includingsecureSDLC,codereview, dependency scanning, secretsmanagement, and CI/CD pipeline controls.
  • MaintaincloudsecurityposturestandardsfortheAWS estate.
Cyber Resilience
  • E n surecyberscenariosarerepresentedinbusinesscontinuityanddisasterrecoveryplanningand testing.
Third-Party Security
  • Assessthesecuritypostureofprospectiveandexistingthirdpartiesandoutsourcedproviders, proportionate to criticality and data exposure.
  • DefinesecurityrequirementsforvendorcontractsincoordinationwithLegaland Procurement.
  • Managesecurityserviceproviders(MSSP,penetrationtestingfirms,consultants)againstdefined SLAs.
People& Capability
  • Drivesecurityawarenessthroughtrainingprogrammesandphishing simulations.
  • Fosteraconstructivesecurityculturethatenablessafeescalationand reporting.
Reporting
  • Monthlysecurityreporting tothe CTO.
  • StandingquarterlysecurityandcyberriskupdatetotheBoardRisk Committee.
  • ImmediatenotificationofmaterialincidentstotheCTO,CEO,andChiefRisk Officer.
Requirements
Experience
  • 10+yearsofprogressiveexperienceininformationsecurity,withatleast5yearsinaleadership role.
  • Demonstratedexperienceinaregulatedfinancialservicesenvironment(banking,payments,fintech, or SVF).
  • Hands-onexperiencewiththePCIDSScompliancelifecycleinapayment environment.
  • Proventrackrecordofleadingincidentresponseduringlivesecurity events.
  • Experiencewithregulatoryframeworks:CBUAEtechnologyandinformationsecurityrisk circulars, UAE IA, or equivalent.
  • DemonstratedabilitytocommunicatesecurityrisktoexecutiveandBoard-level audiences.
  • Demonstratedabilitytodeliversecurityoutcomeswithinconstrainedbudgets,prioritisingrisk reduction per unit of spend.
Leadership&Soft Skills
  • Strongstrategicthinkingwithabilitytotranslateriskintobusiness language.
  • Abilitytoinfluencewithoutauthorityacrossengineering,product,andbusiness teams.
  • Clearcommunicatorwhocanbriefexecutivesandregulatorsunder pressure.
  • CollaborativeapproachwithEngineering,Operations,GRC,andbusiness stakeholders.
  • Comfortableinfast-paced,scalingenvironmentswithevolving priorities.
Qualifications
  • Bachelor'sdegreeinComputerScience,Cybersecurity,InformationTechnology,orarelatedfield, or equivalent professional experience.
  • Industrycertificationsrequired(oneormore):CISSP,CISM,CISA,orISO27001Lead Auditor.
  • Additionalcertificationsvalued:PCIP,OSCP,CCSK,CRISC,AWSSecurity Specialty.
Additional Conditions
  • Availabilityoutsidestandardhoursduringliveincidentsandmajorchange events.
  • Appointmentsubjecttoenhancedbackgroundscreeningappropriatetoaregulatedfinancial services control function.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

myZoi • Dubai

On-site
AED 1,000,000 - 1,500,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

myZoi | Financial Inclusion Technologies • Dubai

On-site
AED 700,000 - 1,500,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

myZoi | Financial Inclusion Technologies • Dubai

On-site
AED 900,000 - 1,300,000
Information Security Operations Lead
Information Security Operations Lead

Star Services LLC • Abu Dhabi

On-site
Assistant Manager, Security Operation & Incident Management (UAE National)
Assistant Manager, Security Operation & Incident Management (UAE National)

Commercial Bank of Dubai • Dubai

On-site
AED 420,000 - 660,000
Information Security Consultant
Information Security Consultant

United Al Saqer Group • Abu Dhabi

On-site
AED 180,000 - 260,000
Cyber Security Project Manager
Cyber Security Project Manager

Client of AIQU • Dubai

On-site
AED 320,000 - 520,000
Cyber Security Lead
Cyber Security Lead

Good co India • United Arab Emirates

On-site
AED 420,000 - 840,000
Senior IT Security Analyst (Banking /Financial services exp)
Senior IT Security Analyst (Banking /Financial services exp)

Confidential Company • Dubai

On-site
AED 350,000 - 500,000
Cybersecurity GRC Manager
Cybersecurity GRC Manager

TASC Outsourcing • Abu Dhabi

On-site
AED 200,000 - 300,000