Information Security Risk Manager
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 hour ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Position Summary
We are seeking a seasoned Information and Cybersecurity Risk Manager based in Dubai to spearhead the design, governance, and continual enhancement of an organisation-wide cyber-risk management framework. This pivotal leadership role aims to advance the company's approach from traditional compliance-focused governance, risk, and compliance (GRC) towards a proactive, business-owned, and data-driven cyber risk strategy.
Key Duties
- Develop and continually refine the enterprise’s information and cybersecurity risk management framework.
- Implement standardized risk methodologies, governance structures, and reporting mechanisms across a complex international enterprise.
- Instill accountability for information risks within both business and technology divisions.
- Chair cyber-risk governance meetings and deliver clear, comprehensive reports to the board concerning major risks, mitigation strategies, and exposures.
- Ensure significant residual risks are escalated appropriately, formally acknowledged, and monitored regularly.
- Coordinate and prioritize risk assessments covering critical technology systems, business operations, large-scale projects, and third-party vendors.
- Introduce and advance quantitative risk management techniques, including probabilistic risk evaluation, simulations, and loss modelling.
- Collaborate closely with Enterprise Risk, Internal Audit, Privacy, Safety teams, and senior technology leaders.
- Support evaluation and management of new and emerging risks, such as those related to artificial intelligence and agentic AI.
- Lead initiatives aimed at improving cyber awareness and fostering behavioural change within the organisation.
- Build, lead, and enhance a highly capable cyber-risk team.
Candidate Profile
- At least 10 years of professional experience in cybersecurity, information security, technology risk, or GRC fields.
- Demonstrated leadership in managing enterprise-wide cyber or information risk programmes within large, complex organisations.
- Exceptional skills engaging with executives and board members, conveying cyber risks in terms of business and operational impact.
- Proven expertise in cyber risk quantification, data-driven risk analytics, or sophisticated risk modelling approaches.
- Comprehensive understanding of international cybersecurity, privacy, and data protection laws and regulations.
- Experience evaluating risks related to cloud environments, technological transformations, third party relationships, and enterprise processes.
- Mandatory CRISC certification.
- Highly desirable to hold CISM, CISA, or comparable certifications.
- Track record in leading teams and developing risk management functions.
- Preferably experienced in aviation, transport, financial services, government, consulting, or similarly regulated sectors.
Minimum education
Bachelor's Degree
Skills
How they work
Communication
Leadership
Strategic Thinking