Back to search
myZoi | Financial Inclusion Technologies Linkedin · Posted 21d ago

Chief Information Security Officer (CISO)

United Arab Emirates

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Chief Information Security Officer
The Role
Lead the organisation's cybersecurity and information security programme, ensuring the confidentiality, integrity, and availability of information assets across a regulated financial services environment. Define and execute security strategy, own and manage cyber risk within Board-approved appetite, and maintain regulatory compliance within a cloud-native payments and stored value facility (SVF) operation.
The role advises and recommends on security risk, with independent authority to escalate unresolved risk to the CTO, CEO, and Board Risk Committee. Operates within an approved annual security budget; spend proposals require cost-benefit justification and are prioritised within the allocated envelope.


Key Responsibilities

Security Strategy & Governance

  • Define and maintain a multi-year cybersecurity strategy aligned with business growth, risk appetite, and regulatory obligations.
  • Establish and maintain the information security policy framework, reviewed at least annually.
  • Maintain the cyber risk register and own the security maturity roadmap against a recognised control framework (NIST CSF, CIS Controls, or ISO 27001).
  • Own the security risk acceptance and exception register.
  • Provide security leadership and advisory to executive management and regulatory stakeholders.

Threat & Vulnerability Management

  • Direct the enterprise vulnerability management programme, including scanning, risk-based prioritisation, and remediation SLA enforcement.
  • Oversee the penetration testing programme and ensure findings are remediated and retested within defined timelines.
  • Maintain threat intelligence capability relevant to financial services and payments, and translate it into detection and control improvements.

Security Operations

  • Oversee security monitoring, detection, and response capabilities including SIEM, EDR/XDR, and SOC operations (internal or MSSP-managed).
  • Own incident response end to end: maintain and test playbooks, run tabletop exercises, lead containment and recovery, and coordinate regulatory notification within applicable deadlines.
  • Manage identity and access governance including RBAC design, privileged access management, joiner/mover/leaver controls, and periodic access recertification.
  • Define and enforce data loss prevention and data classification standards across all platforms.

Regulatory & Compliance (First Line)

  • Maintain operational compliance with PCI DSS, CBUAE technology and information security risk requirements, UAE Information Assurance standards, and applicable payment scheme obligations.
  • Serve as primary security liaison to external auditors, QSAs, and regulatory examiners.
  • Ensure security controls are documented, evidenced, tested, and audit-ready at all times.
  • Track and close security-related audit and examination findings within agreed timelines.

Data Protection & Privacy

  • Implement and maintain security controls supporting UAE PDPL and applicable cross-border data transfer obligations, in coordination with Legal and the Data Protection Officer.
  • Support privacy impact assessments and data breach assessment and notification.

Security Architecture

  • Provide security input to system design, change requests, and new initiatives, and approve security architecture standards and baseline configurations.
  • Embed security-by-design in the engineering lifecycle, including secure SDLC, code review, dependency scanning, secrets management, and CI/CD pipeline controls.
  • Maintain cloud security posture standards for the AWS estate.

Cyber Resilience

  • Ensure cyber scenarios are represented in business continuity and disaster recovery planning and testing.
  • Validate backup integrity, immutability, and recovery capability against destructive attack scenarios.

Third-Party Security

  • Assess the security posture of prospective and existing third parties and outsourced providers, proportionate to criticality and data exposure.
  • Define security requirements for vendor contracts in coordination with Legal and Procurement.
  • Manage security service providers (MSSP, penetration testing firms, consultants) against defined SLAs.

People & Capability

  • Lead and develop the security team.
  • Drive security awareness through training programmes and phishing simulations.
  • Foster a constructive security culture that enables safe escalation and reporting.

Reporting

  • Monthly security reporting to the CTO.
  • Standing quarterly security and cyber risk update to the Board Risk Committee.
  • Immediate notification of material incidents to the CTO, CEO, and Chief Risk Officer.
Requirements

Experience

  • 10+ years of progressive experience in information security, with at least 5 years in a leadership role.
  • Demonstrated experience in a regulated financial services environment (banking, payments, fintech, or SVF).
  • Hands-on experience with the PCI DSS compliance lifecycle in a payment environment.
  • Proven track record of leading incident response during live security events.
  • Experience managing SOC operations (internal or MSSP) including SIEM, EDR/XDR, and threat intelligence.
  • Strong understanding of cloud security (AWS preferred), container and Kubernetes security, and API security.
  • Experience with regulatory frameworks: CBUAE technology and information security risk circulars, UAE IA, or equivalent.
  • Demonstrated ability to communicate security risk to executive and Board-level audiences.
  • Experience managing third-party security vendors and service providers.
  • Experience building and developing security teams.
  • Demonstrated ability to deliver security outcomes within constrained budgets, prioritising risk reduction per unit of spend.

Leadership & Soft Skills

  • Strong strategic thinking with ability to translate risk into business language.
  • Ability to influence without authority across engineering, product, and business teams.
  • Clear communicator who can brief executives and regulators under pressure.
  • Collaborative approach with Engineering, Operations, GRC, and business stakeholders.
  • Comfortable in fast-paced, scaling environments with evolving priorities.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
  • Industry certifications required (one or more): CISSP, CISM, CISA, or ISO 27001 Lead Auditor.
  • Additional certifications valued: PCIP, OSCP, CCSK, CRISC, AWS Security Specialty.

Technology Environment

AWS (Lambda, ECS, EKS, RDS, CloudFront, WAF), Kubernetes, Kafka, PostgreSQL, Java/Spring Boot, React, React Native, Datadog, Microsoft 365/Entra ID, Terraform.

Additional Conditions

  • Participation in an on-call escalation rota for security incidents.
  • Availability outside standard hours during live incidents and major change events.
  • Appointment subject to enhanced background screening appropriate to a regulated financial services control function.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search