Senior Associate Information Security- Emirati

We are seeking Associate – Information Security who manages and monitors the organization’s information security framework, ensuring compliance with internal policies, regulatory standards, and industry best practices. The role supports enterprise security, data governance, risk management, and business continuity initiatives; conducts security assessments and risk reviews; monitors cybersecurity controls and KPIs; and identifies and mitigates security risks across systems & vendors

  • Contribute to the development, implementation, and continuous enhancement of the organization's information security governance framework, standards, and operating procedures.
  • Assess the effectiveness of security controls and recommend improvements to strengthen the overall cybersecurity posture across technology environments and third-party engagements.
  • Perform regular security reviews, control assessments, and compliance evaluations to identify risks, vulnerabilities, and opportunities for improvement.
  • Support the governance and oversight of information security initiatives, ensuring alignment with organizational objectives and regulatory expectations.
  • Review security configurations, user privileges, network controls, and infrastructure settings to verify compliance with security best practices and identify potential weaknesses.
  • Establish and monitor security performance indicators and risk metrics, providing meaningful reporting to support informed decision-making.
  • Participate in technology initiatives and transformation programs by performing security reviews, identifying potential risks, and recommending practical mitigation strategies throughout the project lifecycle.
  • Develop, maintain, and periodically test cybersecurity incident response capabilities to ensure effective preparation, response, and recovery from security events.
  • Support compliance activities related to information security, data protection, and regulatory obligations, including internal and external audit engagements.
  • Monitor the effectiveness of cybersecurity platforms and privileged access controls while supporting the implementation of new security technologies and continuous improvement initiatives.
  • Review business resilience, disaster recovery, and continuity arrangements to ensure appropriate planning, testing, and operational readiness.
  • Work closely with risk management and assurance functions to identify emerging cyber risks, evaluate their impact, and support the implementation of effective mitigation measures.
  • Evaluate security-related operational processes and internal controls, recommending enhancements to reduce exposure to cyber threats, data compromise, and operational risk.
  • Maintain risk documentation and follow up on mitigation plans, ensuring identified actions are tracked, monitored, and completed within agreed timelines.
  • Support enterprise risk, data governance, and fraud prevention initiatives by promoting consistent implementation of security and governance controls across the organization.
  • Deliver cybersecurity awareness sessions and promote a security-first culture through ongoing education and engagement initiatives.
  • Assist with maintaining compliance against recognized industry standards and regulatory frameworks, coordinating assessments, certifications, and remediation activities where required.
  • Stay up to date with emerging cybersecurity threats, new technologies, and industry best practices, and recommend improvements to strengthen the organization's overall security posture.

Requirements

Education & Skills

  • Bachelor’s degree in a related field
  • Master’s or specialization in Computer Science, Engineering, or IT (Preferred)
  • Professional cybersecurity certification (e.g., CISSP, CCSP, CISM)
  • Proficient in English

Experience & Knowledge

  • 3-5 years of hands-on experience in Information Security GRC, including architecture, review, and deployment of next-generation firewalls, WAFs, DLP, PAM, IAM solutions
  • 3+ years implementing ISO standards, NIST frameworks, CIS benchmarking, and developing KPIs/KRIs
  • Experience with enterprise-level integrations, DevSecOps lifecycle, and Cloud platforms (Azure, AWS, GCP), API management, and microservices architecture
  • Ability to align information security strategies with technical projects and mitigate risks for digital transformation initiatives

Abilities & Specific Requirements

  • Must be Emirati with Family Book
  • Able to manage multiple priorities under pressure and meet deadlines
  • Works effectively and responsibly without supervision
  • Can execute clear strategies and corporate requirements
  • Adaptable to start-up or fast-paced environments; flexible and agile thinker (Preferred)
  • Applies a structured, analytical approach to challenges
  • Demonstrates critical thinking and problem-solving capabilities

Senior Associate Information Security- Emirati

Information Technology / Software Development / IT Support

Dubai

Experience: 3-5 years

Similar roles you might like

Associate Principal - Digital Application Operations

Information Technology / Software Development / IT Support

Dubai

Director of Technology-Emirati

Information Technology / Software Development / IT Support

Dubai

Senior Specialist – Cyber Security

Information Technology / Software Development / IT Support

Dubai