Sr Security Analyst

Keka Inc.

Dubai

On-site

AED 320,000 - 520,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Keka Inc. seeks a Senior Security Analyst to own an end-to-end banking security compliance program, spanning gap assessment, risk treatment, ISO/IEC 27001 implementation, internal audit, and certification readiness.

The role requires deep expertise in banking security controls, regulatory compliance, and translating technical risk into executive-level reporting and action.

Qualifications

  • Bachelor's degree in cyber security, information security, computer science, IT or related discipline; master’s preferred.
  • ISO/IEC 27001 Lead Auditor certification with practical audit leadership.
  • Minimum one of CISA / CISSP / CISM / CRISC; ISO 27001 Lead Implementer, ISO 22301 or PCI DSS.

Responsibilities

  • Own and drive an end-to-end banking security compliance program including gap assessment and risk treatment.
  • Define scope, SoA, policies, evidence management, internal audits, and corrective actions.
  • Prepare for external certification readiness and executive reporting on risk and compliance.

Skills

ISO/IEC 27001 Lead Auditor
End-to-end banking security program
Regulatory compliance
Executive reporting
Banking security controls
Threat and risk management

Education

Bachelor's degree in cyber security
Master's degree preferred
ISO/IEC 27001 Lead Auditor certification
CISA / CISSP / CISM / CRISC
ISO 27001 Lead Implementer / PCI DSS

Tools

SIEM/SOC
Microsoft Sentinel/Defender
Azure/AWS security
GRC platforms
Vulnerability scanners

Job description

The Senior Security Analyst will own and drive an end-to-end banking security compliance program, spanning gap assessment, risk assessment and treatment, ISO/IEC 27001 implementation, internal audit, corrective action management, and certification readiness. The role requires deep expertise in banking security controls, regulatory compliance, and the ability to translate technical risk into executive-level reporting and action.

Technical Skills
  • ISO/IEC 27001 Lead Auditor certification with practical experience leading or managing ISMS audits.
  • Proven ability to manage an end-to-end banking security compliance program: gap assessment, scope definition, risk assessment and treatment, Statement of Applicability, policies, evidence management, internal audit, corrective actions, management review, and certification readiness.
  • Strong knowledge of banking security, data protection, third-party risk, business continuity, incident management, and regulatory compliance.
  • Good working understanding of SIEM/SOC, IAM/MFA/PAM, network and endpoint security, vulnerability management, cloud security, DLP, encryption, backup/DR, and secure SDLC.
  • Working knowledge of PCI DSS, ISO 22301, NIST CSF, CIS Controls, SWIFT CSP, or comparable banking frameworks.
  • Exposure to Microsoft Sentinel/Defender, Azure/AWS security, GRC platforms, vulnerability scanners, and audit/evidence automation preferred
Soft Skills
  • Strong ownership, judgement, and integrity, with the confidence to constructively challenge control gaps.
  • Clear written and verbal communication skills; able to translate technical risk into practical actions and management-level reporting.
  • Experience presenting to executives, audit committees, regulators, external auditors, and bank stakeholders.
  • Ability to coach junior analysts and coordinate control owners without relying on formal authority.
  • Comfortable working with multicultural and remote teams under tight audit deadlines.
  • Strong planning, stakeholder management, evidence discipline, and follow-through across distributed teams.
Qualifications (Education & Certifications)
  • Bachelor’s degree in cyber security, Information Security, Computer Science, IT, or related discipline. A master’s degree in cyber security, Information Security or Risk Management is preferred.
  • Valid ISO/IEC 27001 Lead Auditor certification from a recognized training/certification body.
  • Should have minimum one of the following certifications CISA, CISSP, CISM, CRISC,
  • ISO 27001 Lead Implementer, ISO 22301, or PCI DSS.
Experience
  • 5–8 years in information security, including at least 3 years in security governance, risk, compliance, or audit within banking or financial services.
  • Demonstrated experience managing an ISO 27001 program through implementation, internal audit, remediation, and external certification or surveillance audit.
  • Experience maintaining risk registers, compliance plans, audit evidence, corrective-action tracking, and executive reporting.
  • Experience with PCI DSS, central-bank requirements, privacy compliance, third-party assessments, BIA/BCP/DR, incident exercises, or regulatory reporting.
  • Practical involvement in SOC, vulnerability management, penetration testing, IAM, cloud-security, or architecture reviews.
Language Requirements
  • English – professional working proficiency, including formal reports, policies, and executive presentations. Arabic is an advantage
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information security Analyst
Senior Information security Analyst

K20s Kinetic Technologies Private LImited - India • Dubai Emirate

On-site
AED 240,000 - 360,000
Senior Information security Analyst
Senior Information security Analyst

K20s - Kinetic Technologies Private Limited • Dubai

On-site
AED 360,000 - 560,000
Security Analyst
Security Analyst

Crescent Petroleum Company • Sharjah

On-site
Confidential
Assistant Manager, Security Governance & Compliance (UAE National)
Assistant Manager, Security Governance & Compliance (UAE National)

Commercial Bank of Dubai • Dubai

On-site
AED 240,000 - 420,000
Sr Information Security Governance & Assurance Manager
Sr Information Security Governance & Assurance Manager

Michael Page • Abu Dhabi

On-site
AED 600,000 - 900,000
Security Engineer with experience in Banking Domain
Security Engineer with experience in Banking Domain

TAT IT Technolgies • Dubai

On-site
AED 300,000 - 540,000
Senior Analyst - Information And Cybersecurity Operations
Senior Analyst - Information And Cybersecurity Operations

RAKBANK • Ras Al Khaimah

On-site
AED 120,000 - 180,000
Information Security - Project Manager
Information Security - Project Manager

Dicetek LLC • Sharjah

On-site
AED 300,000 - 500,000
Associate Security Analyst
Associate Security Analyst

Keka Technologies Private Limited • Dubai Emirate

On-site
AED 60,000 - 90,000
Principal Security Engineer
Principal Security Engineer

Client of Forsyth Barnes • Abu Dhabi

On-site
AED 350,000 - 500,000