Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will serve as the named ICT security officer for appointed entities. You will lead risk assessments, control testing, audit preparation, incident reporting, business continuity planning, regulatory engagement, and board reporting while aligning local controls with applicable frameworks and group standards.
Requirements
- 7+ years of experience in information security governance, ICT risk management, or regulatory compliance in regulated financial services, fintech, or virtual assets
- Experience as a named regulatory contact or with examinations, supervisory interactions, or licensing processes
- Familiarity with UAE regulatory frameworks
- Ability to build compliance or governance programs from the ground up
- Experience conducting risk assessments, business impact analyses, and resilience planning
- Familiarity with ICT outsourcing and third-party risk management
- Ability to translate technical risk into board-level and regulatory documentation
- Experience operating across multiple jurisdictions
- Project management skills
- Familiarity with EU frameworks such as DORA and MiCA
Responsibilities
- Prepare and report on regional risk governance and board committee meetings
- Execute risk assessments and control testing across UAE operations
- Maintain business impact assessments and integrate findings into resilience planning
- Contribute to business continuity documentation, testing, and updates
- Align UAE regulatory controls with global policies and control frameworks
- Validate security controls and document audit evidence
- Plan remediation for audit findings and track closure
- Prepare regulatory documentation and respond to examinations
- Present security and resilience reports to governance committees and entity management
- Interpret regulatory changes and adapt controls
- Participate in incident response and post-incident reviews
- Serve as the named ICT security officer for appointed entities
- Lead ICT and security risk assessments and maintain risk registers
- Manage ICT incident classification, escalation, and regulatory reporting
- Lead critical-function mapping and business continuity planning
- Oversee continuity testing and ICT third-party dependencies
- Represent local regulatory requirements in group-level decisions
Benefits
- Remote-first work arrangement
Hiring Process
May include a job-related skills or work-style assessment.