You will lead ISO 27001 and UAE compliance engagements for mid-market clients from scoping to audit, and act as the day-to-day security point of contact on vCISO retainers. There is real room to run here: within a few months you'll be chairing client governance meetings and presenting to management on CyberA's behalf. And you won't stop at the paperwork — when a control needs configuring in a client's Microsoft 365 tenant, you can do it yourself or validate it with the engineering team.
What you will do
Role summary
You will lead ISO 27001 and UAE compliance engagements for mid-market clients from scoping to audit, and act as the day-to-day security point of contact on vCISO retainers. There is real room to run here: within a few months you'll be chairing client governance meetings and presenting to management on CyberA's behalf. And you won't stop at the paperwork — when a control needs configuring in a client's Microsoft 365 tenant, you can do it yourself or validate it with the engineering team.
What you will do
- Deliver ISO/IEC 27001:2022 readiness and certification-support engagements end to end: scoping, gap and risk assessment, ISMS documentation, control implementation tracking, internal audit, and certification audit support.
- Assess clients against UAE and regional frameworks (UAE IA, ADHICS, PDPL, DESC ISR, CBUAE, NCA ECC, SAMA CSF) and produce gap reports and prioritised remediation roadmaps.
- Serve as the security point of contact on vCISO engagements: governance meetings, policy reviews, awareness programmes, management and board reporting.
- Translate framework controls into technical requirements, validate implementation with the Security Engineer, and configure or verify Microsoft 365 security controls (Entra ID, Intune, Defender) when the engagement calls for it.
- Produce client-ready deliverables: policies, procedures, risk registers, Statements of Applicability, assessment reports, executive summaries.
- Contribute to proposals, scoping and effort estimation, and to CyberA's internal control mappings and methodologies.
- Run two to three engagements in parallel and keep clients informed on progress, risks and dependencies.
Qualifications
REQUIRED
- 3-5 years in information security roles, with at least 2 years delivering GRC or compliance work
- Personally delivered at least one full-cycle engagement on ISO 27001 or a comparable framework (NCA ECC, SAMA CSF, NIST CSF, CIS Controls, SOC 2), from gap assessment through audit or certification
- Practical command of risk assessment methodology and control implementation, not documentation alone
- Working technical familiarity with an enterprise identity and endpoint environment (Active Directory, Entra ID, GCP or AWS IAM, Intune or equivalent) sufficient to validate controls and read configurations
- Fluent spoken and written English; strong report writing and confident presenting to client management
- Comfortable working across several clients at once and travelling to client sites in the UAE
- Willing to be based in Dubai on a CyberA-sponsored visa
PREFERRED
- Direct experience with UAE frameworks: UAE IA, ADHICS, PDPL, DESC ISR, CBUAE
- Hands-on Entra ID, Intune or Defender administration; familiarity with the Microsoft 365 Business Premium security baseline
- ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM, or Microsoft SC-series certification
- Consultancy or MSSP background serving multiple clients simultaneously
- Exposure to Acronis, WatchGuard or Fortinet, SIEM or MDR services
- Arabic speaking