Information & Cybersecurity Risk Manager

Client of Salt

Dubai

On-site

AED 600,000 - 900,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Client of Salt seeks an experienced Information & Cybersecurity Risk Manager to lead the design governance and ongoing development of an enterprise-wide cyber-risk management framework. This senior role aims to move the organisation beyond compliance-led GRC toward proactive, data-driven risk management.

The role is based in Dubai, with responsibilities to establish risk methodologies, drive board-ready reporting, and collaborate with risk, audit, privacy and safety teams to mature a

Qualifications

  • 10+ years experience across cybersecurity, information security, technology risk or GRC.
  • Proven experience leading enterprise-wide cyber or information-risk programmes within a large, complex organisation.
  • Strong executive and board-level stakeholder management, with the ability to translate cyber risk into commercial and operational impact.
  • Genuine experience with cyber-risk quantification, data-led risk analysis or advanced risk modelling.
  • Strong knowledge of global cybersecurity, privacy and data-protection regulations.
  • Experience assessing risks across cloud, technology transformation, third parties and enterprise business processes.
  • CRISC certification is essential.
  • CISM, CISA or equivalent certifications are highly desirable.
  • Previous people-leadership and risk-function development experience.
  • Background in aviation, transport, financial services, government, consulting or another highly regulated environment would be advantageous.

Responsibilities

  • Lead and evolve the organisation s information and cybersecurity risk-management framework.
  • Establish consistent risk methodologies governance and reporting across a complex global business.
  • Drive accountability for information risk within business and technology teams.
  • Lead cyber-risk governance forums and provide clear board-ready reporting on key risks treatment plans and exposure.
  • Ensure material residual risks are appropriately escalated formally accepted and tracked.
  • Prioritise and coordinate risk assessments across critical technology environments business processes major programmes and third parties.
  • Introduce and mature quantitative risk practices including probabilistic assessment risk simulation and loss modelling.
  • Partner with Enterprise Risk Internal Audit Privacy Safety and senior technology stakeholders.
  • Support the assessment and management of emerging risks including AI and agentic AI.
  • Lead targeted cyber-awareness and behavioural-change initiatives.
  • Develop and upskill a high-performing cyber-risk function.

Skills

Cybersecurity risk management
Information security
GRC
Executive stakeholder management
Risk modelling

Job description

We are looking for an experienced Information amp Cybersecurity Risk Manager to lead the design governance and ongoing development of an enterprise-wide cyber-risk management framework This is a senior leadership position for someone who can move an organisation beyond traditional compliance-led GRC towards proactive business-owned and data-driven cyber-risk management


What you ll do


  • Lead and evolve the organisation s information and cybersecurity risk-management framework

  • Establish consistent risk methodologies governance and reporting across a complex global business

  • Drive accountability for information risk within business and technology teams

  • Lead cyber-risk governance forums and provide clear board-ready reporting on key risks treatment plans and exposure

  • Ensure material residual risks are appropriately escalated formally accepted and tracked

  • Prioritise and coordinate risk assessments across critical technology environments business processes major programmes and third parties

  • Introduce and mature quantitative risk practices including probabilistic assessment risk simulation and loss modelling

  • Partner with Enterprise Risk Internal Audit Privacy Safety and senior technology stakeholders

  • Support the assessment and management of emerging risks including AI and agentic AI

  • Lead targeted cyber-awareness and behavioural-change initiatives

  • Develop and upskill a high-performing cyber-risk function


What we re looking for:


  • 10+ years experience across cybersecurity, information security, technology risk or GRC.

  • Proven experience leading enterprise-wide cyber or information-risk programmes within a large, complex organisation.

  • Strong executive and board-level stakeholder management, with the ability to translate cyber risk into commercial and operational impact.

  • Genuine experience with cyber-risk quantification, data-led risk analysis or advanced risk modelling.

  • Strong knowledge of global cybersecurity, privacy and data-protection regulations.

  • Experience assessing risks across cloud, technology transformation, third parties and enterprise business processes.

  • CRISC certification is essential.

  • CISM, CISA or equivalent certifications are highly desirable.

  • Previous people-leadership and risk-function development experience.

  • Background in aviation, transport, financial services, government, consulting or another highly regulated environment would be advantageous.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Risk Manager
Information Security Risk Manager

Salt • Dubai

On-site
AED 400,000 - 700,000
Enterprise Cyber Risk Leader: Data-Driven & Board-Ready
Enterprise Cyber Risk Leader: Data-Driven & Board-Ready

Client of Salt • Dubai

On-site
AED 600,000 - 900,000
Corporate Policy & Governance Specialist
Corporate Policy & Governance Specialist

YOSH • Abu Dhabi

On-site
AED 240,000 - 420,000
Strategic Cyber Risk Leader – Board-Ready GRC
Strategic Cyber Risk Leader – Board-Ready GRC

Salt • Dubai

On-site
AED 400,000 - 700,000
Cybersecurity Program Manager (Governance, Risk & Compliance)
Cybersecurity Program Manager (Governance, Risk & Compliance)

VINCI • United Arab Emirates

On-site
AED 367,000 - 515,000
Personalized onboarding journey
Opportunities for growth and training
Close and supportive management
+2
Cybersecurity GRC Manager
Cybersecurity GRC Manager

TASC Outsourcing • Abu Dhabi

On-site
AED 200,000 - 300,000
Enterprise Risk Manager
Enterprise Risk Manager

High Street Resources • United Arab Emirates

On-site
AED 180,000 - 240,000
AVP, InfoSec Risk Management
AVP, InfoSec Risk Management

Network International • United Arab Emirates

On-site
AED 300,000 - 540,000
Cyber Security Lead
Cyber Security Lead

Good co India • United Arab Emirates

On-site
AED 420,000 - 840,000
Cyber Operations Manager
Cyber Operations Manager

VHR Global Technical Recruitment • Dubai

On-site
AED 400,000 - 700,000