{bc}

Information Security Risk & Compliance Manager

emaratechDubai, UAE1 months agoMid-Seniorparttime
Generate Resume for this Job
Via Indeed·

About This Role

Role Overview

The Information Security Risk and Compliance (Governance, Risk, and Compliance) Manager implements and maintains frameworks to manage security risks, ensure regulatory compliance, and enforce security policies. He / She is responsible to:

  • oversee audits, manage third-party risks, and report to senior management on the security posture.
  • ensuring the effective implementation and continuous improvement of the Information Security Management System (ISMS), PCI DSS compliance, and UAE Central Bank (CBUAE) regulatory requirements.

The role is responsible for strengthening security governance, managing enterprise security risks, maintaining regulatory compliance, and supporting executive oversight of cybersecurity programs across all group entities.

Key Responsibilities

Governance, Policy & ISMS

  • Responsible for overseeing the execution of the GRC program in collaboration with the executive team as well as maintaining the group’s library of security controls.
  • Lead the implementation, maintenance, and continuous improvement of the Group ISMS aligned with ISO/IEC 27001 standards.
  • Develop, update, implement, and maintain information security policies, standards, and procedures.
  • Ensure consistent implementation of information security governance across the group.
  • Develop goals for data privacy based on legal regulations and other compliance needs, designs and implement privacy policies and practices, and assess these practices for effectiveness.
  • Update security controls and provide support to all stakeholders on security controls covering internal assessments, laws, and regulations.

PCI DSS Compliance

  • Manage the organization’s PCI DSS compliance program, including scope definition, risk assessments, and coordination with Qualified Security Assessors (QSAs).
  • Track remediation activities and ensure continuous compliance with PCI DSS requirements.

CBUAE Regulatory Compliance

  • Ensure compliance with UAE Central Bank (CBUAE) information security and risk management regulations.
  • Monitor regulatory updates and assess their impact on the organization.

Risk Management

  • Identify, assess, evaluate, and mitigate IT Security risks by conducting information security risk assessments and maintain centralized risk registers.
  • Track risk mitigation actions and report the security risk posture to management.

Audit & Compliance Management

  • Ensure compliance with legal, regulatory, and contractual requirements.
  • Coordinate internal audits, external certification audits, and regulatory assessments (ISO 27001, ISO 27005, NIST, PCI DSS, etc.).
  • Track audit findings and ensure timely remediation and closure.

Security Awareness & Training

  • Oversee organization-wide security awareness and compliance training programs.

Requirements* Bachelor’s degree in:

o Engineering

o Information Security

o Computer Science

o IT Risk Management or a related discipline.

Experience & Skills

  • 8–12 years of experience in Cybersecurity, Information Security Governance, Risk Management and Compliance Audit.
  • Deep understanding of frameworks like ISO 27001, PCI-DSS, DESC ISR, etc.

Preferred Certifications

  • CISSP
  • CISM
  • CISA
  • CRISC
  • ISO 27001 Lead Implementer / Lead Auditor

Similar Jobs

Assistant Professor - Information Security Engineering Technology

Institute of Applied Technology · Abu Dhabi

Mid-Senior

We are seeking to appoint an Assistant **Professor** holding a **PhD** with teaching experience in this area. **This is an Open Rank** subject to the relevant working experience \& publications in the reputable journals

GitExcel

Information Security Specialist | ICT and IT Security

American University of Sharjah · Sharjah

Mid-Senior

The **Information Security Specialist** , part of the Information Security team in the IT Department, is responsible for supporting the team in protecting computer assets by establishing and enforcing system access contr

SwiftProject Management

Enterprise Security Architect (Information Security Specialist)

Omnix International · Dubai

Mid-Senior

1. Design and maintain enterprise security architecture based on industry frameworks (SABSA, TOGAF, NIST, Zero Trust). 2. Develop and document security models, including conceptual, logical, and physical architecture dia

AWSAzureDevOps

Senior Analyst, Information Security and Governance

Abu Dhabi Telemedicine Centre · Abu Dhabi

Senior

**Overview** M42 delivers comprehensive healthcare services across the full continuum of care; from primary care to advanced specialty treatments. Leveraging cutting\-edge health technologies and precision medicine, we e

Information SecurityIT GovernanceHealthcare

Senior Analyst, Information Security

M42 Health · Abu Dhabi

Mid-Senior

**Overview** M42 is a global health champion powered by artificial intelligence (AI), technology and genomics to advance innovation in health for people and the planet. Headquartered in Abu Dhabi, M42 combines its specia

VAT

Application Administrator ( Information Security ) (UAE National)

Dubai Health Authority · Dubai

Entry

Functional and technical responsibilities:* Actively participates in and is accountable to assigned work teams. * Perform initial analysis of the end\-users application requests. * Acts as the IT technical support person

Information Security Analyst

Insight ·

**Location:** UAE (on\-site as required) \+ remote (hybrid) **Engagement:** Contract / fixed\-term (project\-based) **About The Role** Insight is delivering a sovereign private cloud programme for a major UAE financial\-

VAT

Information Security Engineer

Dicetek LLC · Dubai

Senior

Ensure secure digital systems with risk-based controls, manage information security projects, and enhance user awareness in compliance with cybersecurity standards.

Network Security EngineerRisk AssessmentData Protection Engineer

Manager – Business Information Security (UAE National)

Aldar Education · Abu Dhabi

Mid-Senior

**Job Description** Aldar Education is currently seeking a **UAE National Manager – Information Security** for an **immediate** start in Abu Dhabi to support our growing family of owned and operated schools in the UAE. T

AI Job Platform

Stop applying blindly. Start getting hired.

Base Career automates the hardest parts of job searching — apply smarter, not harder.

AI Resume in 60s

Your resume rewritten for this exact role using the job description as the brief.

ATS-Optimized

Get past automated screening filters with the right keywords matched to each job.

Application Tracker

Track every job, follow-up, and interview in one visual kanban board.

Start Today for Free

Free plan · No credit card required