Get more replies from employers
Send a job-specific resume in minutes.
Crescent Petroleum Company Inc. seeks an experienced information security professional to lead governance, risk, and compliance initiatives. You will monitor ISO27001 adherence, develop policies, and coordinate audits across the organization while driving data security and governance.
The ideal candidate brings 10–12 years in information security, with 5+ years in risk management, CISSP/CISA/CEH certification, and strong cloud security experience. On-site UAE operations are expected.
Monitor and Maintain ISO27001 adherance Conduct risk and gap assessments to identify gaps in existing security governanceDevelop maintain and review information security policies standards procedures and guidelines aligned with business objectives and regulatory requirements Maintaining and improving the security technologies deployed including creating use cases customizing or better configuring the tools based on past and current threats Develop and maintain data governance and data securityDevelop and conduct security awareness training programsCoordinate internal and external audits including evidence collection walkthroughs and remediation tracking Act as a liaison between security IT business units and auditors to ensure consistent understanding of security and compliance requirements Maintain documentation repositories for policies procedures risk assessments and audit artifacts Maintain the information security risk register and ensure risks are appropriately documented prioritized and tracked Bachelor’s degree in Computer Science, Information Technology, or Cybersecurity. Certifications required: CISSP, CISA and/or CEH. Technical knowledge of networking concepts and network infrastructure. Working knowledge of cloud security and data governance (eg., Azure). Solid understanding of network and computer security, software security Strong analytical, documentation, and communication skills. Knowledge of ISO27001, NIST controls and implementation Familiar with penetration and vulnerability testing. Familiar with antivirus, Firewall, IDS/IPS protocols. 10-12 years experience in Information Security with 5 or more years in risk management