Key Responsibilities:
- Develop, implement, and maintain information security policies, procedures, standards, and guidelines.
- Monitor the organization’s information security posture and identify potential vulnerabilities, threats, and security risks.
- Conduct information security risk assessments and recommend appropriate mitigation and control measures.
- Ensure compliance with applicable UAE government cybersecurity requirements, regulatory frameworks, and recognized international standards.
- Support the implementation and monitoring of security controls across systems, applications, networks, and information assets.
- Coordinate vulnerability assessments, penetration testing, security audits, and remediation activities.
- Monitor security incidents and alerts, support incident investigation, and coordinate appropriate response and recovery actions.
- Develop and maintain the Information Security Incident Response Plan and contribute to business continuity and disaster recovery activities.
- Conduct security reviews for new systems, technologies, applications, and third-party solutions before implementation.
- Assess information security risks associated with vendors and third-party service providers.
- Work closely with IT and relevant departments to ensure security requirements are incorporated into technology projects and operations.
- Support data protection, access control, identity and access management, and information classification initiatives.
- Develop information security awareness programs and conduct awareness sessions for employees.
- Prepare information security reports, dashboards, risk registers, and performance indicators for management.
- Monitor emerging cybersecurity threats, technologies, and regulatory developments and recommend improvements to the organization’s security practices.
- Support internal and external audits and ensure timely closure of information security findings.
Qualifications & Experience:
Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
Master’s degree in a relevant field is an advantage.
Minimum 6 years of relevant experience in information security, cybersecurity, IT security, or a related field.
Experience within government, education, academic, or other regulated sectors is preferred.