Chief Information Security Officer (CISO)
Dubai, United Arab Emirates | Posted on 08/11/2026
Leadthe organisation's cybersecurity and information security programme, ensuringthe confidentiality, integrity,andavailabilityofinformationassetsacrossaregulatedfinancialservicesenvironment.Defineand executesecurity strategy, own and manage cyber risk within Board-approved appetite,and maintain regulatory compliance within a cloud-native payments and storedvalue facility (SVF) operation.
Theroleadvisesandrecommendsonsecurityrisk,withindependentauthoritytoescalateunresolvedriskto the CTO, CEO, and Board Risk Committee.Operates within an approved annual security budget; spend proposals requirecost-benefit justification and are prioritised within the allocated envelope.
Key Responsibilities
- Defineandmaintainamulti-yearcybersecuritystrategyalignedwithbusinessgrowth,riskappetite, and regulatoryobligations.
- Establishandmaintaintheinformationsecuritypolicyframework,reviewedatleast annually.
- Directtheenterprisevulnerabilitymanagementprogramme,includingscanning,risk-based prioritisation, and remediationSLA enforcement.
- Overseethepenetrationtestingprogrammeandensurefindingsareremediatedandretestedwithin defined timelines.
- Maintainthreatintelligencecapabilityrelevanttofinancialservicesandpayments,andtranslateit into detection and controlimprovements.
Security Operations
- Overseesecuritymonitoring,detection,andresponsecapabilitiesincludingSIEM,EDR/XDR,and SOC operations(internal or MSSP-managed).
- Own incident responseendto end: maintain and test playbooks, run tabletop exercises, lead containmentandrecovery,andcoordinateregulatorynotificationwithinapplicabledeadlines.
- ManageidentityandaccessgovernanceincludingRBACdesign,privilegedaccessmanagement, joiner/mover/leaver controls,and periodic access recertification.
- Defineandenforcedatalosspreventionanddataclassificationstandardsacrossall platforms.
Regulatory&Compliance(First Line)
- MaintainoperationalcompliancewithPCIDSS,CBUAEtechnologyandinformationsecurityrisk requirements, UAE Information Assurance standards, and applicablepayment scheme obligations.
- Ensuresecuritycontrolsaredocumented,evidenced,tested,andaudit-readyatall times.
- Trackandclosesecurity-relatedauditandexaminationfindingswithinagreed timelines.
DataProtection& Privacy
- ImplementandmaintainsecuritycontrolssupportingUAEPDPLandapplicablecross-borderdata transfer obligations, in coordination with Legal and theData Protection Officer.
- Supportprivacyimpactassessmentsanddatabreachassessmentand notification.
- Providesecurityinputtosystemdesign,changerequests,andnewinitiatives,andapprovesecurity architecture standards andbaseline configurations.
- Embedsecurity-by-designintheengineeringlifecycle,includingsecureSDLC,codereview, dependency scanning, secretsmanagement, and CI/CD pipeline controls.
- MaintaincloudsecurityposturestandardsfortheAWS estate.
Cyber Resilience
- E n surecyberscenariosarerepresentedinbusinesscontinuityanddisasterrecoveryplanningand testing.
Third-Party Security
- Assessthesecuritypostureofprospectiveandexistingthirdpartiesandoutsourcedproviders, proportionate to criticality and data exposure.
- DefinesecurityrequirementsforvendorcontractsincoordinationwithLegaland Procurement.
- Managesecurityserviceproviders(MSSP,penetrationtestingfirms,consultants)againstdefined SLAs.
People& Capability
- Drivesecurityawarenessthroughtrainingprogrammesandphishing simulations.
- Fosteraconstructivesecurityculturethatenablessafeescalationand reporting.
Reporting
- Monthlysecurityreporting tothe CTO.
- StandingquarterlysecurityandcyberriskupdatetotheBoardRisk Committee.
- ImmediatenotificationofmaterialincidentstotheCTO,CEO,andChiefRisk Officer.
Requirements
Experience
- 10+yearsofprogressiveexperienceininformationsecurity,withatleast5yearsinaleadership role.
- Demonstratedexperienceinaregulatedfinancialservicesenvironment(banking,payments,fintech, or SVF).
- Hands-onexperiencewiththePCIDSScompliancelifecycleinapayment environment.
- Proventrackrecordofleadingincidentresponseduringlivesecurity events.
- Experiencewithregulatoryframeworks:CBUAEtechnologyandinformationsecurityrisk circulars, UAE IA, or equivalent.
- DemonstratedabilitytocommunicatesecurityrisktoexecutiveandBoard-level audiences.
- Demonstratedabilitytodeliversecurityoutcomeswithinconstrainedbudgets,prioritisingrisk reduction per unit of spend.
Leadership&Soft Skills
- Strongstrategicthinkingwithabilitytotranslateriskintobusiness language.
- Abilitytoinfluencewithoutauthorityacrossengineering,product,andbusiness teams.
- Clearcommunicatorwhocanbriefexecutivesandregulatorsunder pressure.
- CollaborativeapproachwithEngineering,Operations,GRC,andbusiness stakeholders.
- Comfortableinfast-paced,scalingenvironmentswithevolving priorities.
Qualifications
- Bachelor'sdegreeinComputerScience,Cybersecurity,InformationTechnology,orarelatedfield, or equivalent professional experience.
- Industrycertificationsrequired(oneormore):CISSP,CISM,CISA,orISO27001Lead Auditor.
- Additionalcertificationsvalued:PCIP,OSCP,CCSK,CRISC,AWSSecurity Specialty.
Additional Conditions
- Availabilityoutsidestandardhoursduringliveincidentsandmajorchange events.
- Appointmentsubjecttoenhancedbackgroundscreeningappropriatetoaregulatedfinancial services control function.