Director of Information Security
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
About the Role
Position: Director of InfoSec Location: Abu Dhabi (on-site) ⸻ About the Client We are sourcing on behalf of a client, a technology company delivering API-driven solutions for financial clients in the Middle East.
Key Skills for This Role
Full Job Posting
Position
Director of InfoSec
Abu Dhabi (on-site)
⸻
About the Client
We are sourcing on behalf of a client, a technology company delivering API-driven solutions for financial clients in the Middle East.
The platform supports multiple deployment models, including on-premises, client-managed cloud, and managed SaaS.
Security expectations are set by highly regulated customers.
The culture is fast-paced and execution-oriented.
Leaders are expected to be directly involved in delivery and results.
Role overview
A practical security leader to manage a lean, experienced team (currently a small group, expanding thoughtfully in line with company growth) and take full ownership of security and compliance across the organisation.
This is a working leadership role where you define the direction and personally implement the systems that support it.
Your responsibilities will range from designing cloud security architecture and guiding engineers through threat modelling, to leading incident response and overseeing ISO 27001 surveillance reviews..
Key Focus Areas
- Develop and implement security architecture and strategy, covering cloud, infrastructure, application, identity, and detection/response.
- Act as the senior technical authority for security, leading reviews, threat modeling, VAPT, and hands-on remediation.
- Oversee governance, risk, and compliance programs, including ISO 27001 and SOC 2 Type II, ensuring they are active and continuously improved.
- Lead audit preparation and execution, resolving findings efficiently.
- Manage security assurance for clients, including responding to detailed security assessments and maintaining strong posture across all environments.
- Build and maintain incident response plans, lead drills, and manage live incidents.
- Oversee IT and workforce security, including identity, endpoints, and onboarding/offboarding processes.
- Foster a security-first culture through practical tools and collaboration with engineering.
What You’ll Tackle in Your First Year
- Take charge of external security certifications and compliance cycles, ensuring successful outcomes (ISO 27001, SOC 2).
- Assess and strengthen security across all infrastructure and deployment models, closing priority risks.
- Streamline client security reviews and due diligence processes.
- Enhance detection and response capabilities, including running live incident simulations.
- Integrate security best practices into engineering workflows to support scale.
Who Will Succeed in This Role
- You are currently a Security Architect or senior technical IC ready to step up to your first Director-level role.
- You are hands-on and want to remain close to the work, not a CISO or people manager looking to delegate.
- You have direct, practical experience across the full information security spectrum: governance, risk, and compliance (GRC), platform and cloud security, vulnerability assessment and penetration testing (VAPT), and SOC 2.
- You have built and secured products in a product-led company or highly regulated environment, and you thrive in fast-paced, ambiguous environments.
- You are proactive, anticipate problems, and act before they become issues.
Who Should Not Apply
- You prefer to focus on strategy and delegate all technical execution.
- You haven’t worked hands-on with cloud or security tools in recent years.
- Your background is primarily in large, process-heavy organizations or big banks, unless you are hands-on and thrive in fast-paced environments.
- You are most comfortable in highly structured environments and prefer to delegate technical execution
- You are looking for a traditional CISO or high-level management role focused on strategy and reporting lines.
Qualifications
- 10+ years of experience in security or infrastructure, with strong technical skills kept current.
- Experience leading a small security team or as a senior technical expert ready to step into leadership.
- Demonstrated expertise in cloud security (AWS, Azure, or GCP), application security, IAM, VAPT, and incident response.
- Proficiency with security tools such as SIEM, EDR/XDR, IAM/SSO, secrets management, infrastructure-as-code security, and CI/CD pipeline security.
- Direct experience managing ISO 27001 and SOC 2 Type II programs and audits.
- Ability to read and review code, script in languages like Python, and communicate clearly with both technical and non-technical stakeholders.
- Strongly preferred
- Experience in financial services, fintech, or regulated sectors (outside of large banks).
- Knowledge of regional regulatory frameworks or willingness to learn quickly.
- Background in securing both on-premises and client-managed environments.
- Relevant technical certifications (e.g., OSCP, cloud security credentials, CISSP/CISM with hands-on experience).
- *By applying to this position, you are granting us permission to process your CV and keep your profile on file for consideration for this and future opportunities.*
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Professional.me
Tech Lead
Abu Dhabi Emirate, UAE
⸻ About the Client We are sourcing on behalf of Alpheya, a B2B WealthTech startup based in Abu Dhabi and backed by BNY Mellon and Lunate. The company has raised $300M to build a state of the art wealth technology platfor
Inventory Controller
Abu Dhabi Emirate, UAE
Location: Abu Dhabi, UAE About the Client We are sourcing on behalf of an innovative organization in Abu Dhabi, UAE. Join a dynamic environment that values collaborative problem-solving, encourages continuous learning, a
Inventory Controller
Dubai, UAE
Location: Abu Dhabi, UAE About the Client We are sourcing on behalf of an innovative organization in Abu Dhabi, UAE. Join a dynamic environment that values collaborative problem-solving, encourages continuous learning, a
Inventory Controller
Dubai, UAE
Location: Abu Dhabi, UAE About the Client We are sourcing on behalf of an innovative organization in Abu Dhabi, UAE. Join a dynamic environment that values collaborative problem-solving, encourages continuous learning, a
Inventory Controller
Abu Dhabi Emirate, UAE
Location: Abu Dhabi, UAE About the Client We are sourcing on behalf of an innovative organization in Abu Dhabi, UAE. Join a dynamic environment that values collaborative problem-solving, encourages continuous learning, a
Head of Financial Planning & Reporting (FP&R)
Dubai, UAE
Location: Dubai, UAE, on-site About the client We are sourcing on behalf of a prominent financial institution in Dubai, UAE operating across a broad and varied investment portfolio, with exposure to multiple sectors. Abo
Inventory Controller
, UAE
Location: Abu Dhabi, UAE About the Client We are sourcing on behalf of an innovative organization in Abu Dhabi, UAE. Imagine working in a beautiful location where you can focus on building state-of-the-art software solut
Principal AI Engineer
Abu Dhabi Emirate, UAE
Position: Principal AI Engineer Location: Abu Dhabi (on-site) ⸻ About the Client We are sourcing on behalf of Alpheya, a B2B WealthTech startup based in Abu Dhabi backed by BNY Mellon and Lunate (a $100B AUM alternative
Tech Lead
Abu Dhabi Emirate, UAE
Inventory Controller
Abu Dhabi Emirate, UAE
Inventory Controller
Dubai, UAE
Inventory Controller
Dubai, UAE
Inventory Controller
Abu Dhabi Emirate, UAE
Head of Financial Planning & Reporting (FP&R)
Dubai, UAE
Inventory Controller
, UAE
Principal AI Engineer
Abu Dhabi Emirate, UAE