Job Description
Job Description: Cybersecurity Officer (GRC)
Position Overview
We are seeking an experienced Cybersecurity Officer with a primary focus on Governance, Risk, and Compliance (GRC).
This is a senior strategic role that requires a professional with the ability to drive governance, provide security advisory, support architecture reviews, and align cybersecurity with national and organizational objectives.
The ideal candidate will also be aware of emerging technology trends, including AI, and understand how to embed security and governance principles in their adoption.
Key Responsibilities
- Lead and manage GRC activities including policy development, risk management, compliance tracking, and audit preparation in line with Information Security Regulation v3 and UAE Cybersecurity Council frameworks.
- Establish and maintain a strong security governance structure, ensuring controls are embedded across all critical domains.
- Drive risk assessments and ensure clear reporting on exposure, mitigation plans, and accountability.
- Actively participate in architecture and solution design reviews, ensuring alignment with security standards and secure-by-design principles.
- Support the integration of security requirements into new projects and emerging technologies, including AI, Blockchain, and Cloud solutions.
- Provide regulatory and management reporting, including compliance dashboards and executive briefs.
- Work closely with IT, business teams, and vendors to ensure cybersecurity priorities are implemented effectively.
Profile Requirements
- Minimum 10+ years of progressive experience in cybersecurity, with a strong focus on GRC and security advisory.
- Solid understanding of enterprise security architecture concepts (Zero Trust, data protection, identity security, network segmentation, secure integration, etc.).
- Strong experience in reviewing and challenging project designs and solutions from a security perspective.
- Awareness of AI security considerations and the ability to factor them into governance and advisory discussions.
- Excellent communication and leadership skills, with the ability to work with both technical and executive stakeholders.
- Previous experience in government or critical sector environments is preferred.
- Hands-on technical knowledge is considered a plus, but the primary focus of this role is GRC and security oversight.
Preferred Certifications
- Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP)
- ISO/IEC 27001 Lead Implementer
- Certified Cloud Security Professional (CCSP) or equivalent
- Familiarity with UAE regulatory frameworks and international standards (ISO, NIST).
Important Note
- This is a cybersecurity role with a strong focus on GRC and security architecture advisory.
- The candidate must have solid technical knowledge and hands-on capabilities to support architecture reviews, solution assessments, and implementation discussions when required.
- Awareness of AI and other emerging technologies is expected to support decision-making and governance.
- Only senior profiles with 10+ years of relevant cybersecurity experience will be considered.
Position Details
- Position Title: Cyber Security
- Location: CA
- Experience Required: "10.0"