Stand out for this role — generate a tailored resume and cover letter in about a minute.
CNS Middle East is seeking a senior Cybersecurity Advisory & Assurance Lead to drive enterprise-wide maturity assessments and advisory engagements for enterprise and government clients in the UAE. You will independently lead framework-based assessments, translate technical findings into business risk, and guide remediation programmes with senior management.
Key responsibilities include managing end-to-end assessments across Identify/Protect/Detect/Respond/Recover, reviewing controls, and
The Cybersecurity Advisory amp Assurance Lead is a senior hands-on cybersecurity professional responsible for leading complex cybersecurity assessments advisory engagements and transformation programmes for enterprise and government customers The role independently leads comprehensive framework-based assessments NIST CSF NIST SP 800-series ISO IEC 27001 CIS Controls and applicable UAE GCC regulatory requirements taking engagements from initial customer workshops and evidence collection through technical assessment control testing maturity evaluation gap analysis risk identification target-state design remediation planning and executive presentation Drawing on broad expertise across defensive security offensive security governance risk and compliance GRC security architecture and security operations the jobholder acts as a technically credible adviser to CISOs SOC infrastructure cloud and architecture teams and senior management
Lead enterprise-wide cybersecurity maturity and capability assessments including NIST CSF-based current-state and target-state assessments covering governance and the Identify Protect Detect Respond and Recover functions
Conduct control design and operating-effectiveness assessments evaluating whether technical controls are effectively implemented rather than relying solely on policy documentation
Review cybersecurity policies standards procedures and operating models and evaluate them against NIST CSF NIST SP 800-series ISO IEC 27001 27002 CIS Critical Security Controls UAE Information Assurance requirements UAE GCC cybersecurity regulations PCI DSS SWIFT CSP cloud security frameworks and sector-specific requirements
Assess and advise on defensive security and SOC capabilities including SOC operating models SIEM and security monitoring EDR XDR detection engineering threat intelligence threat hunting security logging incident response vulnerability management IAM PAM network endpoint email and web security ransomware resilience cyber crisis management and business continuity and cyber recovery
Assess security architecture across enterprise infrastructure cloud and hybrid environments network identity endpoint data application security security monitoring and where applicable OT ICs environments
Assess the effectiveness and maturity of cybersecurity processes including asset risk vulnerability patch and change management identity lifecycle and privileged access management security monitoring incident response third-party risk secure development threat management security architecture governance data protection business continuity and cyber recovery
Scope challenge and interpret penetration-testing and red-team assessments review vulnerability and penetration-testing results and assess vulnerability management and remediation processes
Validate whether technical findings represent material business risks and work with offensive-security specialists to translate them into risk and remediation programmes supporting purple-team and control-validation activities where required
Conduct cybersecurity governance and cyber-risk assessments assess governance structures and accountability evaluate cyber-risk management methodologies support regulatory and compliance readiness and map controls across multiple regulatory frameworks
Identify security gaps risks control weaknesses and capability deficiencies and develop prioritised remediation roadmaps and cybersecurity improvement programmes
Develop maturity models heatmaps risk registers and management dashboards and produce executive management and detailed technical assessment reports
Present findings and recommendations to CISOs CIOs executives and governance committees translating highly technical issues into business-risk language and practical remediation recommendations
Lead customer workshops and stakeholder interviews define assessment methodologies and evidence requirements and maintain evidence traceability between findings and conclusions
Manage assessment workstreams and guide junior consultants challenging customer assumptions professionally and constructively
Support proposals RFP responses statements of work and customer presentations and assist Account Managers in identifying follow-on cybersecurity opportunities
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems or Engineering (Electronics, Computer or Telecom). Desirable: Master's degree such as an MSc in Cybersecurity or Information Security, or an MBA with a technology focus. For a lead role this is a plus, not usually a must. Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, CISA, CCSP, GIAC or NIST-related training/certification Technical/offensive certifications such as OSCP, PNPT or CEH (or equivalent practical experience)
8 years of cybersecurity experience spanning multiple disciplines Demonstrable experience leading enterprise cybersecurity assessments Experience conducting stakeholder interviews and evidence-based assessments Experience producing executive-level reports and presenting to senior customer stakeholders Desirable: 12+ years of cybersecurity experience Experience in government, critical infrastructure, financial services, aviation, energy or other highly regulated sectors