Salt

Information Security Risk Manager

Salt

Dubai, United Arab Emirates · Full Time

Be the first to apply

Experience
10+ yrs
Salary
Openings
1
Posted
1 hour ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Position Summary

We are seeking a seasoned Information and Cybersecurity Risk Manager based in Dubai to spearhead the design, governance, and continual enhancement of an organisation-wide cyber-risk management framework. This pivotal leadership role aims to advance the company's approach from traditional compliance-focused governance, risk, and compliance (GRC) towards a proactive, business-owned, and data-driven cyber risk strategy.

Key Duties

  • Develop and continually refine the enterprise’s information and cybersecurity risk management framework.
  • Implement standardized risk methodologies, governance structures, and reporting mechanisms across a complex international enterprise.
  • Instill accountability for information risks within both business and technology divisions.
  • Chair cyber-risk governance meetings and deliver clear, comprehensive reports to the board concerning major risks, mitigation strategies, and exposures.
  • Ensure significant residual risks are escalated appropriately, formally acknowledged, and monitored regularly.
  • Coordinate and prioritize risk assessments covering critical technology systems, business operations, large-scale projects, and third-party vendors.
  • Introduce and advance quantitative risk management techniques, including probabilistic risk evaluation, simulations, and loss modelling.
  • Collaborate closely with Enterprise Risk, Internal Audit, Privacy, Safety teams, and senior technology leaders.
  • Support evaluation and management of new and emerging risks, such as those related to artificial intelligence and agentic AI.
  • Lead initiatives aimed at improving cyber awareness and fostering behavioural change within the organisation.
  • Build, lead, and enhance a highly capable cyber-risk team.

Candidate Profile

  • At least 10 years of professional experience in cybersecurity, information security, technology risk, or GRC fields.
  • Demonstrated leadership in managing enterprise-wide cyber or information risk programmes within large, complex organisations.
  • Exceptional skills engaging with executives and board members, conveying cyber risks in terms of business and operational impact.
  • Proven expertise in cyber risk quantification, data-driven risk analytics, or sophisticated risk modelling approaches.
  • Comprehensive understanding of international cybersecurity, privacy, and data protection laws and regulations.
  • Experience evaluating risks related to cloud environments, technological transformations, third party relationships, and enterprise processes.
  • Mandatory CRISC certification.
  • Highly desirable to hold CISM, CISA, or comparable certifications.
  • Track record in leading teams and developing risk management functions.
  • Preferably experienced in aviation, transport, financial services, government, consulting, or similarly regulated sectors.

Minimum education

Bachelor's Degree

How they work

Communication Leadership Strategic Thinking

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer