Chief Information Security Officer (CISO)

myZoi

Dubai

On-site

AED 1,000,000 - 1,500,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

myZoi is seeking a Chief Information Security Officer (CISO) to lead the organisation's cybersecurity and information security programme in a cloud-native payments and SVF environment. You will define and execute security strategy, own cyber risk, and ensure regulatory compliance with Board-approved budgets.

You will advise on security risk to CTO/CEO and Board Risk Committee, oversee vulnerability management, incident response, data protection, and third-party security across the enterprise.

Qualifications

  • 10+ years of information security experience, with at least 5 years in a leadership role.
  • Experience in a regulated financial services environment (banking, payments, fintech, or SVF).
  • Hands-on experience with PCI DSS lifecycle in a payment environment.
  • Proven track record leading incident response during live security events.
  • Experience with regulatory frameworks: CBUAE technology and information security risk circulars, UAE IA, or equivalent.
  • Ability to communicate security risk to executives and board-level audiences.
  • Ability to deliver security outcomes within constrained budgets, prioritising risk reduction per spend.

Responsibilities

  • Define and maintain a multi-year cybersecurity strategy aligned with business growth, risk appetite, and regulatory obligations.
  • Establish and maintain the information security policy framework, reviewed at least annually.
  • Direct the enterprise vulnerability management programme, including scanning, risk-based prioritisation, and remediation SLA enforcement.
  • Oversee the penetration testing programme and ensure findings are remediated and retested within defined timelines.
  • Maintain threat intelligence capability relevant to financial services and payments, translate into detection and control improvements.
  • Oversee security monitoring, detection and response including SIEM, EDR/XDR, and SOC operations.
  • Own incident response end to end: playbooks, tabletop exercises, containment and recovery, regulatory notification within deadlines.
  • Manage identity and access governance including RBAC design, privileged access management, joiner/mover/leaver controls, recertification.
  • Define and enforce data loss prevention and data classification standards across platforms.
  • Maintain cloud security posture standards for the AWS estate.
  • Embed security-by-design in the engineering lifecycle, secure SDLC, code reviews, and CI/CD controls.
  • Maintain data protection and privacy controls, cross-border transfer obligations.

Skills

Leadership
Strategic thinking
Risk communication
Budgeting

Education

Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field
Certifications: CISSP, CISM, CISA, ISO27001 Lead Auditor

Tools

SIEM
Incident response tools

Job description

Chief Information Security Officer (CISO)

Dubai, United Arab Emirates | Posted on 08/11/2026

Leadthe organisation's cybersecurity and information security programme, ensuringthe confidentiality, integrity,andavailabilityofinformationassetsacrossaregulatedfinancialservicesenvironment.Defineand executesecurity strategy, own and manage cyber risk within Board-approved appetite,and maintain regulatory compliance within a cloud-native payments and storedvalue facility (SVF) operation.

Theroleadvisesandrecommendsonsecurityrisk,withindependentauthoritytoescalateunresolvedriskto the CTO, CEO, and Board Risk Committee.Operates within an approved annual security budget; spend proposals requirecost-benefit justification and are prioritised within the allocated envelope.

Key Responsibilities

  • Defineandmaintainamulti-yearcybersecuritystrategyalignedwithbusinessgrowth,riskappetite, and regulatoryobligations.
  • Establishandmaintaintheinformationsecuritypolicyframework,reviewedatleast annually.
  • Directtheenterprisevulnerabilitymanagementprogramme,includingscanning,risk-based prioritisation, and remediationSLA enforcement.
  • Overseethepenetrationtestingprogrammeandensurefindingsareremediatedandretestedwithin defined timelines.
  • Maintainthreatintelligencecapabilityrelevanttofinancialservicesandpayments,andtranslateit into detection and controlimprovements.
Security Operations
  • Overseesecuritymonitoring,detection,andresponsecapabilitiesincludingSIEM,EDR/XDR,and SOC operations(internal or MSSP-managed).
  • Own incident responseendto end: maintain and test playbooks, run tabletop exercises, lead containmentandrecovery,andcoordinateregulatorynotificationwithinapplicabledeadlines.
  • ManageidentityandaccessgovernanceincludingRBACdesign,privilegedaccessmanagement, joiner/mover/leaver controls,and periodic access recertification.
  • Defineandenforcedatalosspreventionanddataclassificationstandardsacrossall platforms.
Regulatory&Compliance(First Line)
  • MaintainoperationalcompliancewithPCIDSS,CBUAEtechnologyandinformationsecurityrisk requirements, UAE Information Assurance standards, and applicablepayment scheme obligations.
  • Ensuresecuritycontrolsaredocumented,evidenced,tested,andaudit-readyatall times.
  • Trackandclosesecurity-relatedauditandexaminationfindingswithinagreed timelines.
DataProtection& Privacy
  • ImplementandmaintainsecuritycontrolssupportingUAEPDPLandapplicablecross-borderdata transfer obligations, in coordination with Legal and theData Protection Officer.
  • Supportprivacyimpactassessmentsanddatabreachassessmentand notification.
  • Providesecurityinputtosystemdesign,changerequests,andnewinitiatives,andapprovesecurity architecture standards andbaseline configurations.
  • Embedsecurity-by-designintheengineeringlifecycle,includingsecureSDLC,codereview, dependency scanning, secretsmanagement, and CI/CD pipeline controls.
  • MaintaincloudsecurityposturestandardsfortheAWS estate.
Cyber Resilience
  • E n surecyberscenariosarerepresentedinbusinesscontinuityanddisasterrecoveryplanningand testing.
Third-Party Security
  • Assessthesecuritypostureofprospectiveandexistingthirdpartiesandoutsourcedproviders, proportionate to criticality and data exposure.
  • DefinesecurityrequirementsforvendorcontractsincoordinationwithLegaland Procurement.
  • Managesecurityserviceproviders(MSSP,penetrationtestingfirms,consultants)againstdefined SLAs.
People& Capability
  • Drivesecurityawarenessthroughtrainingprogrammesandphishing simulations.
  • Fosteraconstructivesecurityculturethatenablessafeescalationand reporting.
Reporting
  • Monthlysecurityreporting tothe CTO.
  • StandingquarterlysecurityandcyberriskupdatetotheBoardRisk Committee.
  • ImmediatenotificationofmaterialincidentstotheCTO,CEO,andChiefRisk Officer.
Requirements
Experience
  • 10+yearsofprogressiveexperienceininformationsecurity,withatleast5yearsinaleadership role.
  • Demonstratedexperienceinaregulatedfinancialservicesenvironment(banking,payments,fintech, or SVF).
  • Hands-onexperiencewiththePCIDSScompliancelifecycleinapayment environment.
  • Proventrackrecordofleadingincidentresponseduringlivesecurity events.
  • Experiencewithregulatoryframeworks:CBUAEtechnologyandinformationsecurityrisk circulars, UAE IA, or equivalent.
  • DemonstratedabilitytocommunicatesecurityrisktoexecutiveandBoard-level audiences.
  • Demonstratedabilitytodeliversecurityoutcomeswithinconstrainedbudgets,prioritisingrisk reduction per unit of spend.
Leadership&Soft Skills
  • Strongstrategicthinkingwithabilitytotranslateriskintobusiness language.
  • Abilitytoinfluencewithoutauthorityacrossengineering,product,andbusiness teams.
  • Clearcommunicatorwhocanbriefexecutivesandregulatorsunder pressure.
  • CollaborativeapproachwithEngineering,Operations,GRC,andbusiness stakeholders.
  • Comfortableinfast-paced,scalingenvironmentswithevolving priorities.
Qualifications
  • Bachelor'sdegreeinComputerScience,Cybersecurity,InformationTechnology,orarelatedfield, or equivalent professional experience.
  • Industrycertificationsrequired(oneormore):CISSP,CISM,CISA,orISO27001Lead Auditor.
  • Additionalcertificationsvalued:PCIP,OSCP,CCSK,CRISC,AWSSecurity Specialty.
Additional Conditions
  • Availabilityoutsidestandardhoursduringliveincidentsandmajorchange events.
  • Appointmentsubjecttoenhancedbackgroundscreeningappropriatetoaregulatedfinancial services control function.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

myZoi | Financial Inclusion Technologies • Dubai

On-site
AED 700,000 - 1,500,000
Cybersecurity Consultant
Cybersecurity Consultant

Mada Media • Dubai

On-site
AED 300,000 - 600,000
Cybersecurity Consultant
Cybersecurity Consultant

Dubai Careers - A Smart Dubai Initiative • Dubai

On-site
AED 300,000 - 420,000
Senior Architect - Information Security ( UAE National )
Senior Architect - Information Security ( UAE National )

Roads and Transport Authority • Dubai

On-site
AED 260,000 - 340,000
Information Security Consultant
Information Security Consultant

United Al Saqer Group • Abu Dhabi

On-site
AED 180,000 - 260,000
Assistant Manager, Security Governance & Compliance (UAE National)
Assistant Manager, Security Governance & Compliance (UAE National)

Commercial Bank of Dubai • Dubai

On-site
AED 240,000 - 420,000
Assistant Manager, Security Operation & Incident Management (UAE National)
Assistant Manager, Security Operation & Incident Management (UAE National)

Commercial Bank of Dubai • Dubai

On-site
AED 420,000 - 660,000
Chief Specialist - information Security (UAE National Only )
Chief Specialist - information Security (UAE National Only )

Roads and Transport Authority • Dubai

On-site
AED 300,000 - 550,000
Executive Manager - Squad Cyber Technical Lead
Executive Manager - Squad Cyber Technical Lead

Dicetek LLC • Abu Dhabi

On-site
AED 420,000 - 640,000
Senior Officer - Compliance And Assurance Outsource
Senior Officer - Compliance And Assurance Outsource

ADIB - Abu Dhabi Islamic Bank • Abu Dhabi

On-site
AED 240,000 - 360,000