
Information Security Manager - Governance (1-Year Contract)
At a Glance
- Category
- 🏦 Finance & Banking
- Level
- Mid-Level
- Type
- Contract
Quick CV Check
- Get your ATS score for Capitex in 30 seconds
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
Capitex is engaging an Information Security Manager - Governance for a one-year contract with a leading UAE bank, based on-site in Dubai.
Working directly under the Head of Information Security, you will develop and implement the security measures that keep the bank's information assets safe - identifying gaps in existing IS policies, standards, guidelines and procedures, and bringing them into alignment with regulatory requirements and industry standards.
Key responsibilities:
• Assist in the development of the information security strategy and roadmap across all security technology domains
• Manage end-to-end security projects including UAE IA (NESA) assessments, PCI DSS, SWIFT CSP controls and VAPT
• Verify and validate closure of gaps identified during regulatory assessments and audits, recommending alternative solutions where needed
• Act as the Information Security lead for technology, digital transformation, cloud, infrastructure, application and business projects
• Manage multiple security and compliance projects simultaneously, prioritising by business impact and risk
• Ensure information security requirements are addressed through project initiation, planning, design, implementation, testing and go-live
• Coordinate with PMO and business project managers to integrate security activities into project plans
• Maintain security governance frameworks - policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance
• Manage audit and regulatory findings through remediation and validated closure
• Establish risk-based processes for third-party due diligence, onboarding, assessment, monitoring and offboarding
• Manage the development and delivery of security awareness and training programmes
• Advise IS management on information security risk issues in support of the bank's wider risk management programmes
Strong information security experience within the banking/financial sector - essential, given exposure to banking systems, regulatory requirements and volume of concurrent activities
Around 10-12 years of relevant information/cyber security experience with manager-level responsibilities
Strong information security governance/GRC experience covering policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance
Hands-on experience with UAE IA/NESA - implementation, assessments and policy/control alignment
Experience managing PCI DSS, SWIFT CSP, VAPT and regulatory/security assessments
Proven experience managing audit/regulatory findings through remediation and validated closure
Experience acting as information security lead on major technology, digital, cloud, infrastructure and application projects
Ability to manage multiple security/regulatory projects simultaneously, coordinating with IT, Business, Risk, Audit, Compliance, PMO and external parties
Professional certification: CISM, CRISC, CISA and/or CISSP preferred
Bachelor's degree
Strong communication skills - able to engage senior non-technical stakeholders without technical language
One-year contract with a leading UAE bank, on-site in Dubai
Competitive all-inclusive monthly package - salary, UAE visa, Emirates ID and medical insurance all covered
Full Employer of Record support throughout the engagement, with end-of-service benefits accrued per UAE labour law
Requirements
- •Strong information security experience within the banking/financial sector
- •Around 10-12 years of relevant information/cyber security experience with manager-level responsibilities
- •Strong information security governance/GRC experience (policies, standards, risk assessments, risk registers)
- •Hands-on experience with UAE IA/NESA - implementation, assessments and policy/control alignment
- •Experience managing PCI DSS, SWIFT CSP, VAPT and regulatory/security assessments
- •Proven experience managing audit/regulatory findings through remediation and validated closure
- •Experience acting as information security lead on major technology, digital, cloud, infrastructure and application projects
- •Ability to manage multiple security/regulatory projects simultaneously
Nice to Have
- •Professional certification: CISM, CRISC, CISA and/or CISSP preferred
Responsibilities
- •Assist in the development of the information security strategy and roadmap across all security technology domains
- •Manage end-to-end security projects including UAE IA (NESA) assessments, PCI DSS, SWIFT CSP controls and VAPT
- •Verify and validate closure of gaps identified during regulatory assessments and audits
- •Act as the Information Security lead for technology, digital transformation, cloud, infrastructure, application and business projects
- •Ensure information security requirements are addressed through project initiation, planning, design, implementation, testing and go-live
- •Coordinate with PMO and business project managers to integrate security activities into project plans
- •Maintain security governance frameworks - policies, standards, risk assessments, risk registers, risk acceptance/exceptions and compliance
- •Manage the development and delivery of security awareness and training programmes
Related Jobs4 similar jobs
Browse Similar
- Get your ATS score for Capitex in 30 seconds
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
Capitex provides a global financial services platform. It focuses on investment opportunities and financial solutions for its clients.


