Information Security Risk Manager

Salt

Dubai

On-site

AED 360,000 - 600,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Salt in Dubai seeks an Information Security Risk Manager to lead the design and governance of an enterprise-wide cyber-risk framework. This senior role moves beyond compliance into proactive, data-driven risk management for a global business.

You will drive risk governance, partner with Enterprise Risk and Internal Audit, and report to senior leadership on key risks, treatment plans and exposure, while nurturing a high-performing cyber-risk function.

Qualifications

  • CRISC certification mandatory.
  • Proven track record in enterprise-wide cyber/information risk programmes.
  • Strong ability to translate cyber risk into business impact.

Responsibilities

  • Lead and evolve the enterprise cyber-risk management framework.
  • Establish consistent risk methodologies, governance and reporting.
  • Drive accountability for information risk across business and tech teams.
  • Provide board-ready reporting on risks, treatment plans and exposure.
  • Escalate material residual risks and ensure formal acceptance.
  • Coordinate risk assessments across critical tech, processes and partners.
  • Develop quantitative risk practices including loss modelling.
  • Partner with Enterprise Risk, Internal Audit and other stakeholders.
  • Support assessment of emerging risks including AI.)
  • Lead cyber-awareness and risk culture initiatives.

Skills

CRISC certification
Executive stakeholder mgmt
Cyber risk quantification
Risk governance
Cloud/third-party risk

Job description

Information Security Risk Manager
Dubai

We are looking for an experienced Information & Cybersecurity Risk Manager to lead the design, governance and ongoing development of an enterprise-wide cyber-risk management framework.

This is a senior leadership position for someone who can move an organisation beyond traditional compliance-led GRC towards proactive, business-owned and data-driven cyber-risk management.

What you’ll do
  • Lead and evolve the organisation’s information and cybersecurity risk-management framework.
  • Establish consistent risk methodologies, governance and reporting across a complex global business.
  • Drive accountability for information risk within business and technology teams.
  • Lead cyber-risk governance forums and provide clear, board-ready reporting on key risks, treatment plans and exposure.
  • Ensure material residual risks are appropriately escalated, formally accepted and tracked.
  • Prioritise and coordinate risk assessments across critical technology environments, business processes, major programmes and third parties.
  • Introduce and mature quantitative risk practices, including probabilistic assessment, risk simulation and loss modelling.
  • Partner with Enterprise Risk, Internal Audit, Privacy, Safety and senior technology stakeholders.
  • Support the assessment and management of emerging risks, including AI and agentic AI.
  • Lead targeted cyber-awareness and behavioural-change initiatives.
  • Develop and upskill a high-performing cyber-risk function.
What we’re looking for
  • 10+ years’ experience across cybersecurity, information security, technology risk or GRC.
  • Proven experience leading enterprise-wide cyber or information-risk programmes within a large, complex organisation.
  • Strong executive and board-level stakeholder management, with the ability to translate cyber risk into commercial and operational impact.
  • Genuine experience with cyber-risk quantification, data-led risk analysis or advanced risk modelling.
  • Strong knowledge of global cybersecurity, privacy and data-protection regulations.
  • Experience assessing risks across cloud, technology transformation, third parties and enterprise business processes.
  • CRISC certification is essential.
  • CISM, CISA or equivalent certifications are highly desirable.
  • Previous people-leadership and risk-function development experience.
  • Background in aviation, transport, financial services, government, consulting or another highly regulated environment would be advantageous.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information & Cybersecurity Risk Manager
Information & Cybersecurity Risk Manager

Client of Salt • Dubai

On-site
AED 600,000 - 900,000
Cybersecurity GRC Manager
Cybersecurity GRC Manager

TASC Outsourcing • Abu Dhabi

On-site
AED 200,000 - 300,000
Cyber Security Project Manager
Cyber Security Project Manager

Client of AIQU • Dubai

On-site
AED 320,000 - 520,000
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services

Jobsatdubai • Dubai

On-site
Senior Cyber Risk Leader — Quantitative & Board‑Ready
Senior Cyber Risk Leader — Quantitative & Board‑Ready

Salt • Dubai

On-site
AED 360,000 - 600,000
Enterprise Cyber Risk Leader: Data-Driven & Board-Ready
Enterprise Cyber Risk Leader: Data-Driven & Board-Ready

Client of Salt • Dubai

On-site
AED 600,000 - 900,000
Senior GRC Risk Specialist
Senior GRC Risk Specialist

TASC Outsourcing • Abu Dhabi

On-site
Risk & Compliance Director
Risk & Compliance Director

Carter Knight FZ LLC • United Arab Emirates

On-site
AED 350,000 - 500,000
Consultant - Enterprise Risk Management
Consultant - Enterprise Risk Management

Aventus • Dubai

On-site
AED 250,000 - 400,000
Information Security Professional / Information Security Expert
Information Security Professional / Information Security Expert

Raqmiyat • Abu Dhabi

On-site
AED 200,000 - 300,000