
Cyber Security Lead
At a Glance
- Category
- 🏦 Finance & Banking
- Level
- Senior
- Type
- Full-time
Are You Getting Through?
- Find out if Goodman Masson Muscat's ATS is filtering your CV
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.

Goodman Masson is partnering with a new financial markets infrastructure venture under formation in Oman. Backed by prominent institutional investors, the business is building a greenfield platform from the ground up, and is now hiring at the build stage. This is a rare chance to help stand up critical market infrastructure from a blank sheet and then run what you have built.
The role
As Cyber Security Lead you keep the platform safe from attack and make sure it stays that way. In the build phase you design the security architecture from the ground up. In the run phase you operate that estate, watch it around the clock, and lead the response to any incident.
What you will do
• Design the security architecture from a blank sheet: identity and access, encryption at rest and in transit, network and endpoint controls, and the monitoring and detection stack
• Build and run security monitoring and threat detection, set and tune detection rules, and run threat-hunting exercises
• Own identity, privileged access, and encryption to the standard a regulated financial platform requires
• Run the vulnerability management cycle, coordinate penetration testing, and drive remediation to close
• Own security incident response end to end, from detection through containment, recovery, and review
• Design the run-phase security operating model, author the playbooks, and build and lead the security team
What you will bring
- Degree in computer science, engineering, information security, or a related field
- At least ten years in cyber and information security, with real time owning the security of a mission-critical platform end to end
- Direct experience designing and standing up the security capability of a mission-critical regulated platform from a blank sheet, not only running one built by others
- Direct experience as a senior security authority in financial services or a comparable mission-critical regulated setting such as capital markets, banking, payments, or financial market infrastructure
- Deep expertise in security monitoring, threat detection, and incident response, including running or directing a SOC or managed security service
- Strong grasp of identity and access management, privileged access, and encryption for a regulated platform
- Hands-on technical credibility and sound judgement under a live incident
- Fluent English, written and spokenAlso of interest
• Experience with financial market infrastructure such as a central securities depository, central counterparty, exchange, or payment system
• Familiarity with the CPMI-IOSCO Principles for Financial Market Infrastructures, especially the operational and cyber resilience principles
• Experience securing connectivity to industry networks and market data services such as SWIFT, Bloomberg, and the international central securities depositories
• Relevant certifications such as CISSP, CISM, CEH, or GIAC
Location and terms
Based in Muscat, Oman.
Permanent for Omani nationals; two-year fixed-term contract for expatriate hires.
If this is your kind of build, apply through this posting or message me directly for a confidential conversation.
Requirements
- •Degree in computer science, engineering, information security, or a related field
- •At least ten years in cyber and information security
- •Experience owning security of a mission-critical platform end to end
- •Direct experience designing and standing up security capability from a blank sheet
- •Senior security authority experience in financial services or regulated settings (banking, payments, etc.)
- •Deep expertise in security monitoring, threat detection, and incident response
- •Strong grasp of IAM, privileged access, and encryption for regulated platforms
- •Fluent English, written and spoken
Nice to Have
- •Experience with financial market infrastructure (CSD, CCP, exchange, or payment systems)
- •Familiarity with CPMI-IOSCO Principles for Financial Market Infrastructures
- •Experience securing connectivity to SWIFT, Bloomberg, and international central securities depositories
- •Relevant certifications such as CISSP, CISM, CEH, or GIAC
Responsibilities
- •Design security architecture from a blank sheet (IAM, encryption, network, endpoint controls)
- •Build and run security monitoring and threat detection
- •Set and tune detection rules and run threat-hunting exercises
- •Own identity, privileged access, and encryption to regulated standards
- •Run the vulnerability management cycle and coordinate penetration testing
- •Own security incident response end to end (detection, containment, recovery, review)
- •Design the run-phase security operating model and author playbooks
- •Build and lead the security team
Related Jobs2 similar jobs
Browse Similar
- Find out if Goodman Masson Muscat's ATS is filtering your CV
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.

