Information Security Risk Manager
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Position Summary
We are seeking a seasoned Information and Cybersecurity Risk Manager based in Dubai to spearhead the design, governance, and continual enhancement of an organisation-wide cyber-risk management framework. This pivotal leadership role aims to advance the company's approach from traditional compliance-focused governance, risk, and compliance (GRC) towards a proactive, business-owned, and data-driven cyber risk strategy.
Key Duties
- Develop and continually refine the enterprise’s information and cybersecurity risk management framework.
- Implement standardized risk methodologies, governance structures, and reporting mechanisms across a complex international enterprise.
- Instill accountability for information risks within both business and technology divisions.
- Chair cyber-risk governance meetings and deliver clear, comprehensive reports to the board concerning major risks, mitigation strategies, and exposures.
- Ensure significant residual risks are escalated appropriately, formally acknowledged, and monitored regularly.
- Coordinate and prioritize risk assessments covering critical technology systems, business operations, large-scale projects, and third-party vendors.
- Introduce and advance quantitative risk management techniques, including probabilistic risk evaluation, simulations, and loss modelling.
- Collaborate closely with Enterprise Risk, Internal Audit, Privacy, Safety teams, and senior technology leaders.
- Support evaluation and management of new and emerging risks, such as those related to artificial intelligence and agentic AI.
- Lead initiatives aimed at improving cyber awareness and fostering behavioural change within the organisation.
- Build, lead, and enhance a highly capable cyber-risk team.
Candidate Profile
- At least 10 years of professional experience in cybersecurity, information security, technology risk, or GRC fields.
- Demonstrated leadership in managing enterprise-wide cyber or information risk programmes within large, complex organisations.
- Exceptional skills engaging with executives and board members, conveying cyber risks in terms of business and operational impact.
- Proven expertise in cyber risk quantification, data-driven risk analytics, or sophisticated risk modelling approaches.
- Comprehensive understanding of international cybersecurity, privacy, and data protection laws and regulations.
- Experience evaluating risks related to cloud environments, technological transformations, third party relationships, and enterprise processes.
- Mandatory CRISC certification.
- Highly desirable to hold CISM, CISA, or comparable certifications.
- Track record in leading teams and developing risk management functions.
- Preferably experienced in aviation, transport, financial services, government, consulting, or similarly regulated sectors.
Minimum education
Bachelor's Degree
Skills
Cybersecurity
Regulatory Affairs
Enterprise Risk Management
Quantitative risk analysis
risk simulation
Cloud Risk Assessment
How they work
Communication
Leadership
Strategic Thinking