251 Technology Risk jobs in the United Arab Emirates
Identity & Technology Risk Lead
Posted today
Job Viewed
Job Description
Abu Dhabi, United Arab Emirates | Posted on 05/28/2025
Consultz is supporting our client, a well-renowned SWF in the region, in their search for an Identity & Technology Risk Lead.
Role Overview:
We are seeking a strategic and technically proficient Identity & Technology Risk Architect to lead identity governance and technology risk management initiatives. This individual will architect and operationalize the Identity & Access Governance (IAG) program, design scalable controls for access lifecycle and policy enforcement, and enhance how Digital & AI, along with the broader organization, manage technology risk.
This role operates at the intersection of security architecture, enterprise systems, DevOps, and governance, collaborating closely with auditors, technology leaders, and risk stakeholders.
Key Responsibilities:
Identity & Access Governance (IAG)- Develop and execute the organization’s IAG strategy and program.
- Design, implement, and manage IGA tools such as SailPoint IdentityIQ to automate and enforce policies like birthright access control, segregation of duties (SoD), toxic combination detection, access reviews, and recertification.
- Establish policies and guardrails across critical applications, platforms, and infrastructure to ensure secure, compliant access provisioning.
- Identify, register, and manage technology risks within Digital & AI divisions and the broader enterprise.
- Lead initiatives to embed risk assessments and controls into solution development, cloud engineering, and platform architecture.
- Collaborate with GRC, legal, and risk teams to align with enterprise-wide risk frameworks and standards.
- Assist Enterprise Architecture and DevOps teams in integrating identity and risk considerations into technical architectures and CI/CD pipelines.
- Participate in secure design reviews, risk assessments, and threat modeling.
- Serve as a subject matter expert on identity and access architecture.
- Act as the primary contact for internal and external audits related to IT, access controls, identity governance, and technology risk.
- Manage evidence collection, documentation, control testing, and remediation tracking.
- No direct management responsibilities but requires excellent stakeholder management skills across departments.
- 10+ years in identity management and technology risk.
- Expertise in Identity Governance & Administration (IGA), especially SailPoint IdentityIQ, including implementation and operation.
- Deep knowledge of access control principles, SoD models, toxic combinations, and compliance standards.
- Experience with technology risk frameworks like NIST CSF, ISO 27005, COBIT.
- Hands-on experience with DevOps and enterprise IT teams in secure solution design.
- Certifications such as CISSP, CISA, CRISC, or relevant identity certifications.
- Experience integrating identity solutions with HR systems, ITSM, cloud platforms, and application catalogs.
- Strong communication and stakeholder engagement skills, including interactions with auditors and regulators.
Identity & Technology Risk Lead
Posted today
Job Viewed
Job Description
Abu Dhabi, United Arab Emirates | Posted on 05/28/2025
Consultz is supporting our client, a well-renowned SWF in the region, in their search for an Identity & Technology Risk Lead.
Role Overview:
We are seeking a strategic and technically proficient Identity & Technology Risk Architect to lead identity governance and technology risk management initiatives. This individual will architect and operationalize the Identity & Access Governance (IAG) program, design scalable controls for access lifecycle and policy enforcement, and enhance how Digital & AI, along with the broader organization, manage technology risk.
This role operates at the intersection of security architecture, enterprise systems, DevOps, and governance, collaborating closely with auditors, technology leaders, and risk stakeholders.
Key Responsibilities:
Identity & Access Governance (IAG)- Develop and execute the organization's IAG strategy and program.
- Design, implement, and manage IGA tools such as SailPoint IdentityIQ to automate and enforce policies like birthright access control, segregation of duties (SoD), toxic combination detection, access reviews, and recertification.
- Establish policies and guardrails across critical applications, platforms, and infrastructure to ensure secure, compliant access provisioning.
- Identify, register, and manage technology risks within Digital & AI divisions and the broader enterprise.
- Lead initiatives to embed risk assessments and controls into solution development, cloud engineering, and platform architecture.
- Collaborate with GRC, legal, and risk teams to align with enterprise-wide risk frameworks and standards.
- Assist Enterprise Architecture and DevOps teams in integrating identity and risk considerations into technical architectures and CI/CD pipelines.
- Participate in secure design reviews, risk assessments, and threat modeling.
- Serve as a subject matter expert on identity and access architecture.
- Act as the primary contact for internal and external audits related to IT, access controls, identity governance, and technology risk.
- Manage evidence collection, documentation, control testing, and remediation tracking.
- No direct management responsibilities but requires excellent stakeholder management skills across departments.
- 10+ years in identity management and technology risk.
- Expertise in Identity Governance & Administration (IGA), especially SailPoint IdentityIQ, including implementation and operation.
- Deep knowledge of access control principles, SoD models, toxic combinations, and compliance standards.
- Experience with technology risk frameworks like NIST CSF, ISO 27005, COBIT.
- Hands-on experience with DevOps and enterprise IT teams in secure solution design.
- Certifications such as CISSP, CISA, CRISC, or relevant identity certifications.
- Experience integrating identity solutions with HR systems, ITSM, cloud platforms, and application catalogs.
- Strong communication and stakeholder engagement skills, including interactions with auditors and regulators.
Chief Technology Risk Management Officer
Posted today
Job Viewed
Job Description
IT Governance Officer
">">Job Description: ">
The IT Governance Officer will be responsible for managing technology risks and ensuring that IT investments align with the company's mission, vision, values, and objectives. This includes identifying and managing risk, improving control, and increasing the value of IT investments.
">- Develop and implement a robust IT governance framework that aligns with industry standards and regulatory requirements. ">
- Assess the existing IT governance framework/policies and identify areas for enhancement and optimization. ">
- Ensure the organization's adherence to governance framework, industry-specific compliance standards and regulations. ">
- Provide regular reports and updates on compliance performance and improvement initiatives. ">
- Support in identifying, assessing, and mitigating IT risks through the establishment of common IT risk analysis methodologies and management strategies. ">
- Support continuous monitoring of compliance with governance policies and reporting on risk management activities. ">
- Support the execution of approved IT governance strategies and initiatives, providing expert guidance and oversight. ">
- Collaborate with other departments to ensure that IT governance practices are integrated into all relevant processes. ">
- Establish and maintain Service Level Agreements (SLAs) with internal and external service providers, while aligning with IT Operations and corporate approved SLAs. ">
- Prepare necessary pre-requisites/checklists across infrastructure, applications and security domains, and collaborate with IT Operations to ensure adherence to these requirements. ">
- Facilitate communication and collaboration between International Offices and central D&TS functions to address technological needs and challenges. ">
- Coordinate IT operations and support services for Masdar's International Offices, ensuring alignment with corporate standards and policies. ">
- Develop and deliver training programs to educate employees on IT governance policies and procedures. ">
- Foster a culture of governance and compliance within the organization. ">
- Ensure compliance with relevant laws, regulations, standards, and corporate policies. ">
- Coordinate internal and external audits related to IT governance and compliance. ">
- Perform gap analysis to identify areas of non-compliance and improvement. ">
- Gather evidence to support compliance and audit requirements. ">
- Submit evidence on time to ensure audit timelines are met. ">
- Generate detailed reports summarizing audit findings and compliance status. ">
- Monitor industry trends and best practices to make recommendations to improve the IT governance framework. ">
- Engage with and monitor relationships with internal and external stakeholders in order to ensure adequate knowledge transfer and completion of services as per agreed parameters. ">
- Apply consistent approaches/discipline and standardized forms in line with relevant policies, processes and procedures. ">
- Remain abreast of current and emerging technology trends and ensure that the organization is properly and timely informed. ">
- Arrange for technology demonstrations, PoCs to ensure the organization has all the knowledge needed to make informed technology decisions. ">
- Manage document change requests and obtain approvals in line with relevant policies and procedures. ">
- Develop and maintain documentation related to KPI tracking and reporting policies and procedures. ">
Preferred Qualifications:
">- Bachelor's degree in information management, computer science, business administration, or related field. A master's degree is a plus. ">
- Relevant certifications (e.g., CISM, CRISC, COBIT, ITIL, PMO) are preferred. ">
Required skills and qualifications include excellent analytical, problem-solving, and decision-making skills, strong communication and interpersonal skills with the ability to influence at all levels of the organization, familiarity with IT governance frameworks such as COBIT, ITIL, ISO, & CGEIT, ISO, and a strong understanding of IT governance principles, regulatory requirements, and best practices.
">Benefits: ">Working at this organization offers various benefits including fostering a culture of governance and compliance within the organization, promoting innovation in solar, wind, energy storage, waste-to-energy, and geothermal energy, and being part of a global clean energy pioneer across renewables and green hydrogen.
">Additional Information: ">This organization is one of the world's fastest growing renewable energy companies and a green hydrogen leader, placing the UAE at the forefront of the energy transition.
">As a pioneer in advancing the clean energy sector and a key enabler of the UAE's vision as a global leader in sustainability and climate action, this organization has developed projects in more than 40 countries across six continents and has invested, or committed to invest, in worldwide projects with a combined value of more than US$30 billion.
">Promoting innovation in solar, wind, energy storage, waste-to-energy, and geothermal energy, this organization has a proven record of delivering pioneering projects using cutting-edge clean energy technologies, that are commercially viable and bankable.
")},Strategic Identity & Technology Risk Architect
Posted today
Job Viewed
Job Description
Key Role Summary:
We are looking for a seasoned Identity & Technology Risk professional to lead the development and implementation of our Identity Governance and Technology Risk Management strategies.
This individual will be responsible for architecting and operationalizing the Identity & Access Governance (IAG) program, designing scalable controls for access lifecycle and policy enforcement, and enhancing how we manage technology risk.
Our ideal candidate will have strong technical expertise in identity management and technology risk, with a proven track record of successfully implementing IGA solutions and managing complex security projects.
- Identity Governance
- Develop and execute the organization's IAG strategy and program.
- Design, implement, and manage IGA tools such as SailPoint IdentityIQ to automate and enforce policies like birthright access control, segregation of duties (SoD), toxic combination detection, access reviews, and recertification.
- Establish policies and guardrails across critical applications, platforms, and infrastructure to ensure secure, compliant access provisioning.
- Technology Risk Management
- Identify, register, and manage technology risks within Digital & AI divisions and the broader enterprise.
- Lead initiatives to embed risk assessments and controls into solution development, cloud engineering, and platform architecture.
- Collaborate with GRC, legal, and risk teams to align with enterprise-wide risk frameworks and standards.
- Stakeholder Engagement and Communication
- Assist Enterprise Architecture and DevOps teams in integrating identity and risk considerations into technical architectures and CI/CD pipelines.
- Participate in secure design reviews, risk assessments, and threat modeling.
- Serve as a subject matter expert on identity and access architecture.
- Audit and Assurance
- Act as the primary contact for internal and external audits related to IT, access controls, identity governance, and technology risk.
- Manage evidence collection, documentation, control testing, and remediation tracking.
- Requirements:
- 10+ years of experience in identity management and technology risk.
- Expertise in Identity Governance & Administration (IGA), especially SailPoint IdentityIQ, including implementation and operation.
- Deep knowledge of access control principles, SoD models, toxic combinations, and compliance standards.
- Experience with technology risk frameworks like NIST CSF, ISO 27005, COBIT.
- Hands-on experience with DevOps and enterprise IT teams in secure solution design.
- Certifications such as CISSP, CISA, CRISC, or relevant identity certifications.
- Experience integrating identity solutions with HR systems, ITSM, cloud platforms, and application catalogs.
- Strong communication and stakeholder engagement skills, including interactions with auditors and regulators.
Information Technology Compliance Specialist
Posted today
Job Viewed
Job Description
IT Audit Role Overview
We are seeking a skilled IT Auditor with fluency in Arabic to join our team. The IT Auditor will assess and ensure the effectiveness, reliability, and security of IT systems, processes, and controls.
Key Responsibilities- Audit Planning and Execution: Develop and execute IT audit plans and programs.
- Perform risk assessments of IT systems, networks, and processes to identify vulnerabilities.
- Conduct audits to ensure compliance with internal policies, industry standards, and regulatory requirements.
- Control Evaluation: Assess the effectiveness of IT controls, including application controls, access controls, and change management processes.
- Identify weaknesses or inefficiencies in IT systems and recommend improvements.
- Documentation and Reporting: Prepare detailed audit reports outlining findings, risks, and recommendations.
- Presentation: Present audit results to stakeholders and provide actionable insights to address identified issues.
- Collaboration: Work closely with IT, compliance, and business teams to ensure proper implementation of audit recommendations.
- Bachelor's degree in Information Technology, Computer Science, Accounting, or a related field.
- Proven experience as an IT Auditor or in a similar role.
- Strong knowledge of IT systems, processes, and controls.
- Fluency in Arabic (written and spoken) is mandatory.
- Familiarity with audit tools and frameworks such as COBIT, ISO, or NIST.
- Proficiency in risk assessment, data analysis, and problem-solving.
- Excellent written and verbal communication skills in both Arabic and English.
- Professional certifications such as CISA, CRISC, CISSP, or equivalent are highly preferred.
- Experience in auditing ERP systems, databases, and cloud environments.
- Knowledge of cybersecurity frameworks and best practices.
- Ability to manage multiple audits and prioritize tasks effectively.
- Not Applicable
- Contract
Language Proficiency: Fluency in Arabic is essential for effective communication with stakeholders and understanding local regulations.
Industry Expertise: Knowledge of IT systems, processes, and controls, as well as audit tools and frameworks, is required.
Communication Skills: Excellent written and verbal communication skills in both Arabic and English are necessary.
Chief Security Risk Officer
Posted today
Job Viewed
Job Description
This senior-level Information Security Risk Manager role is responsible for leading the development and implementation of enterprise-wide security risk management frameworks, policies, and procedures. The successful candidate will possess a deep understanding of information security principles, risk management methodologies, and governance frameworks.
The ideal candidate will have:
- At least 7 years of experience in information security or technology risk roles, with at least 5 years in a leadership capacity;
- Proven expertise in building or maturing a Group-level security risk and assurance function in a complex, regulated environment;
- Experience in designing and implementing scalable, metrics-driven security risk management frameworks covering risk identification, assessment, treatment, monitoring, and reporting;
- Strong knowledge of ISO 27001/27005, NIST CSF/RMF, COBIT, FAIR, and the Three Lines of Defence model;
- Ability to translate complex technical risks into clear, actionable business insights and recommendations aligned to Group objectives and risk appetite.
The Information Security Risk Manager will be responsible for:
- Defining and establishing the Information Security Risk capabilities, including governance frameworks, policies, reporting lines, and operating models;
- Partnering with Enterprise Risk and Internal Audit to embed security risk into the Group's Three Lines of Defence and Enterprise Risk Management (ERM) framework;
- Acting as the principal information security risk advisor to senior executives, business leaders, and functional heads;
- Designing and delivering enterprise training or awareness programs on risk and compliance topics;
- Leading annual PCI DSS assurance and compliance programs across retail, payments, and commerce channels;
- Providing assurance and second-line oversight over security incident management, including root cause analysis, response effectiveness, and post-mortem controls evaluation.
We offer a competitive benefits package which includes health care, child education contribution, remote and flexible working policies, as well as exclusive employee discounts.
Join our team of talented professionals who are shaping the future of luxury retail. We strive to create a diverse and inclusive work environment that fosters growth, innovation, and success.
Lead – Information Security Risk
Posted today
Job Viewed
Job Description
INSPIRE | EXHILARATE | DELIGHT
For over seven decades, Chalhoub Group has been a partner and creator of luxury experiences in the Middle East. In its pursuit to excel as a hybrid luxury retailer, the Group has curated a portfolio of over 10 owned brands and strengthened its distribution and marketing expertise for over 400 international names across luxury fashion, beauty, jewellery, watches, eyewear, and art de vivre categories.
Every step at Chalhoub Group is taken to build a future where luxury dreams become reality — bridging cultures and crafting memorable experiences for our consumers. Be it by constantly reinventing itself, committing to innovation, or embracing new technologies, the Group is shaping the future of luxury retail. It delivers seamless omnichannel experiences across more than 950 stores, online platforms, and mobile apps. Driving this innovation journey is The Greenhouse — the Group's innovation hub, incubator, and accelerator for startups and emerging businesses, regionally and globally.
Chalhoub Group fosters a people-at-heart culture rooted in diversity, equity, and inclusion, and a workplace catalysed by forward thinking and future-proofing. Today, it brings together over 16,000 talented professionals across eight countries in the Middle East, with a presence in LATAM. Their collective efforts have earned the Group the Great Place to Work certification in several markets.
Sustainability is at the core of the Group's strategy, guided by a clear commitment to people, partners, and the planet. Chalhoub Group is proud to be a member of the United Nations Global Compact, a signatory of the Women's Empowerment Principles, and to have pledged to reach Net Zero by 2040.
What You'll Be Doing
The Information Security Risk & Assurance Lead is responsible for establishing and leading Chalhoub Group's enterprise-wide security risk and assurance capabilities. This role drives the development of risk frameworks, control assurance, ISO 27001 and PCI DSS compliance, and IAM governance, while serving as a strategic advisor to executive leadership. It plays a critical role in embedding a culture of security risk ownership and awareness through robust processes, education, and engagement.
- Define and establish the Information Security Risk capabilities, including governance frameworks, policies, reporting lines, and operating model.
- Partner with Enterprise Risk and Internal Audit to embed security risk into the Group's Three Lines of Defence and Enterprise Risk Management (ERM) framework.
Chair or co-chair relevant InfoSec risk committees or forums, providing credible challenge and escalation for emerging cyber risks across the business and technology estate. - Act as the principal information security risk advisor to senior executives, business leaders, and functional heads.
- Translate complex technical risks into clear, actionable business insights and recommendations, aligned to Group objectives and risk appetite.
- Deliver quarterly security risk briefings, dashboards, and thematic risk deep dives for Executive Leadership and Board-level committees as required.
- Design and implement a scalable, metrics-driven security risk management framework covering risk identification, assessment, treatment, monitoring, and reporting.
- Establish and maintain a centralised Information Security Risk Register, ensuring ownership, tracking, and oversight of key risks and mitigation plans.
Align Group risk methodologies to leading practices such as ISO 27005, FAIR, or NIST RMF where appropriate. - Build and lead a risk-based security assurance programme in partnership with Internal Audit, covering internal audits, control testing, supplier reviews, and compliance assessments.
- Ensure continual improvement, compliance and ISO/IEC 27001 certification, driving maturity across the ISMS and control environment.
- Lead annual PCI DSS assurance and compliance programmes across retail, payments, and commerce channels.
- Provide assurance and second-line oversight over security incident management, including root cause analysis, response effectiveness, and post-mortem controls evaluation.
- Champion a culture of risk ownership, continuous learning, and control improvement following security events.
- Lead the development and delivery of a Group-wide information security risk education and training programme, tailored by audience and risk level.
- Equip business and technology stakeholders with practical knowledge to identify, assess, and own security risks as part of day-to-day operations.
- Collaborate with Group Risk, Internal Audit, and People & Culture to embed risk responsibilities into role-based learning paths, onboarding, and manager training.
- Track effectiveness of training initiatives through KPIs and maturity assessments, continuously evolving content and engagement strategies.
- Actively support a culture of proactive risk awareness, clear accountability, and continuous improvement across the organisation.
What You'll Need to Succeed
- The ideal candidate will bring deep expertise in information security and enterprise risk management, with relevant qualifications such as CISA, CRISC, or ISO 27005, and proven experience embedding risk frameworks aligned to ISO 27001, NIST RMF, or FAIR in complex, multinational environments.
- Minimum 7 years of experience in Information Security or Technology Risk roles, with at least 5 years in a leadership capacity.
- Demonstrated experience building or maturing a Group-level security risk and assurance function in a complex, regulated or multinational environment.
- Proven leadership in achieving and maintaining ISO 27001 certification, PCI DSS compliance.
- Solid understanding of frameworks and standards such as ISO 27001/27005, NIST CSF/RMF, COBIT, FAIR, and the Three Lines of Defence model.
- Experience designing and delivering enterprise training or awareness programmes on risk and compliance topics is a distinct advantage.
What We Can Offer You
With us,you will turn your aspirations into reality. We will help shape your journey through enriching experiences, learning and development opportunities and exposure to different assignments within your role or through internal mobility. Our Group offers diverse career paths for those who are extraordinary, every day.
We recognise the value that you bring, and we strive to provide a competitive benefits package which includes health care, child education contribution, remote and flexible working policies as well as exclusive employeediscounts.
We Invite All Applicants to Apply
It Takes Diversity Of Thought, Culture, Background, Differing Abilities and Perspectives to truly Inspire, Exhilarate and Delight our customers. At Chalhoub Group, we are committed to inclusion and diversity.
We welcome all applicants to apply and be part of our exciting future. We ensure equal opportunity for all our applicants without regard to gender, age, race, religion, national origin or disability status.
#J-18808-LjbffrBe The First To Know
About the latest Technology risk Jobs in United Arab Emirates !
Chief Security Risk Officer
Posted today
Job Viewed
Job Description
The Information Security Risk & Assurance Lead plays a vital role in safeguarding our enterprise. This dynamic leader will establish and lead our security risk and assurance capabilities, driving the development of risk frameworks, control assurance, ISO 27001 and PCI DSS compliance, and IAM governance.
Responsibilities- Define and establish information security risk capabilities, including governance frameworks, policies, reporting lines, and operating models.
- Partner with Enterprise Risk and Internal Audit to embed security risk into our Three Lines of Defence and Enterprise Risk Management framework.
- Provide strategic advice to executive leadership on information security risk management.
- Translate complex technical risks into actionable business insights and recommendations.
- Deliver quarterly security risk briefings, dashboards, and thematic risk deep dives for Executive Leadership and Board-level committees.
- Design and implement a scalable, metrics-driven security risk management framework.
- Establish and maintain a centralized Information Security Risk Register.
- Build and lead a risk-based security assurance program.
- Ensure continual improvement, compliance, and ISO/IEC 27001 certification.
- Deep expertise in information security and enterprise risk management.
- Relevant qualifications such as CISA, CRISC, or ISO 27005.
- Proven experience embedding risk frameworks aligned to ISO 27001, NIST RMF, or FAIR in complex environments.
- Minimum 7 years of experience in Information Security or Technology Risk roles.
- Demonstrated leadership in achieving and maintaining ISO 27001 certification, PCI DSS compliance.
- Solid understanding of frameworks and standards such as ISO 27001/27005, NIST CSF/RMF, COBIT, FAIR, and the Three Lines of Defence model.
We provide a competitive benefits package including health care, child education contribution, remote and flexible working policies, and employee discounts. We welcome diverse applicants and ensure equal opportunity for all without regard to gender, age, race, religion, national origin, or disability status.
Lead – Information Security Risk
Posted today
Job Viewed
Job Description
Join to apply for the Lead – Information Security Risk & Assurance role at Chalhoub Group
Lead – Information Security Risk & AssuranceJoin to apply for the Lead – Information Security Risk & Assurance role at Chalhoub Group
Get AI-powered advice on this job and more exclusive features.
INSPIRE | EXHILARATE | DELIGHT
For over seven decades, Chalhoub Group has been a partner and creator of luxury experiences in the Middle East. In its pursuit to excel as a hybrid luxury retailer, the Group has curated a portfolio of over 10 owned brands and strengthened its distribution and marketing expertise for over 400 international names across luxury fashion, beauty, jewellery, watches, eyewear, and art de vivre categories.
INSPIRE | EXHILARATE | DELIGHT
For over seven decades, Chalhoub Group has been a partner and creator of luxury experiences in the Middle East. In its pursuit to excel as a hybrid luxury retailer, the Group has curated a portfolio of over 10 owned brands and strengthened its distribution and marketing expertise for over 400 international names across luxury fashion, beauty, jewellery, watches, eyewear, and art de vivre categories.
Every step at Chalhoub Group is taken to build a future where luxury dreams become reality — bridging cultures and crafting memorable experiences for our consumers. Be it by constantly reinventing itself, committing to innovation, or embracing new technologies, the Group is shaping the future of luxury retail. It delivers seamless omnichannel experiences across more than 950 stores, online platforms, and mobile apps. Driving this innovation journey is The Greenhouse — the Group's innovation hub, incubator, and accelerator for startups and emerging businesses, regionally and globally.
Chalhoub Group fosters a people-at-heart culture rooted in diversity, equity, and inclusion, and a workplace catalysed by forward thinking and future-proofing. Today, it brings together over 16,000 talented professionals across eight countries in the Middle East, with a presence in LATAM. Their collective efforts have earned the Group the Great Place to Work certification in several markets.
Sustainability is at the core of the Group's strategy, guided by a clear commitment to people, partners, and the planet. Chalhoub Group is proud to be a member of the United Nations Global Compact, a signatory of the Women's Empowerment Principles, and to have pledged to reach Net Zero by 2040.
What You'll Be Doing
The Information Security Risk & Assurance Lead is responsible for establishing and leading Chalhoub Group's enterprise-wide security risk and assurance capabilities. This role drives the development of risk frameworks, control assurance, ISO 27001 and PCI DSS compliance, and IAM governance, while serving as a strategic advisor to executive leadership. It plays a critical role in embedding a culture of security risk ownership and awareness through robust processes, education, and engagement.
- Define and establish the Information Security Risk capabilities, including governance frameworks, policies, reporting lines, and operating model.
- Partner with Enterprise Risk and Internal Audit to embed security risk into the Group's Three Lines of Defence and Enterprise Risk Management (ERM) framework. Chair or co-chair relevant InfoSec risk committees or forums, providing credible challenge and escalation for emerging cyber risks across the business and technology estate.
- Act as the principal information security risk advisor to senior executives, business leaders, and functional heads.
- Translate complex technical risks into clear, actionable business insights and recommendations, aligned to Group objectives and risk appetite.
- Deliver quarterly security risk briefings, dashboards, and thematic risk deep dives for Executive Leadership and Board-level committees as required.
- Design and implement a scalable, metrics-driven security risk management framework covering risk identification, assessment, treatment, monitoring, and reporting.
- Establish and maintain a centralised Information Security Risk Register, ensuring ownership, tracking, and oversight of key risks and mitigation plans. Align Group risk methodologies to leading practices such as ISO 27005, FAIR, or NIST RMF where appropriate.
- Build and lead a risk-based security assurance programme in partnership with Internal Audit, covering internal audits, control testing, supplier reviews, and compliance assessments.
- Ensure continual improvement, compliance and ISO/IEC 27001 certification, driving maturity across the ISMS and control environment.
- Lead annual PCI DSS assurance and compliance programmes across retail, payments, and commerce channels.
- Provide assurance and second-line oversight over security incident management, including root cause analysis, response effectiveness, and post-mortem controls evaluation.
- Champion a culture of risk ownership, continuous learning, and control improvement following security events.
- Lead the development and delivery of a Group-wide information security risk education and training programme, tailored by audience and risk level.
- Equip business and technology stakeholders with practical knowledge to identify, assess, and own security risks as part of day-to-day operations.
- Collaborate with Group Risk, Internal Audit, and People & Culture to embed risk responsibilities into role-based learning paths, onboarding, and manager training.
- Track effectiveness of training initiatives through KPIs and maturity assessments, continuously evolving content and engagement strategies.
- Actively support a culture of proactive risk awareness, clear accountability, and continuous improvement across the organisation.
- The ideal candidate will bring deep expertise in information security and enterprise risk management, with relevant qualifications such as CISA, CRISC, or ISO 27005, and proven experience embedding risk frameworks aligned to ISO 27001, NIST RMF, or FAIR in complex, multinational environments.
- Minimum 7 years of experience in Information Security or Technology Risk roles, with at least 5 years in a leadership capacity.
- Demonstrated experience building or maturing a Group-level security risk and assurance function in a complex, regulated or multinational environment.
- Proven leadership in achieving and maintaining ISO 27001 certification, PCI DSS compliance.
- Solid understanding of frameworks and standards such as ISO 27001/27005, NIST CSF/RMF, COBIT, FAIR, and the Three Lines of Defence model.
- Experience designing and delivering enterprise training or awareness programmes on risk and compliance topics is a distinct advantage.
With us, you will turn your aspirations into reality. We will help shape your journey through enriching experiences, learning and development opportunities and exposure to different assignments within your role or through internal mobility. Our Group offers diverse career paths for those who are extraordinary, every day.
We recognise the value that you bring, and we strive to provide a competitive benefits package which includes health care, child education contribution, remote and flexible working policies as well as exclusive employee discounts.
We Invite All Applicants to Apply
It Takes Diversity Of Thought, Culture, Background, Differing Abilities and Perspectives to truly Inspire, Exhilarate and Delight our customers. At Chalhoub Group, we are committed to inclusion and diversity.
We welcome all applicants to apply and be part of our exciting future. We ensure equal opportunity for all our applicants without regard to gender, age, race, religion, national origin or disability status.Seniority level
- Seniority level Director
- Employment type Full-time
- Job function Information Technology
- Industries Retail Luxury Goods and Jewelry
Referrals increase your chances of interviewing at Chalhoub Group by 2x
Get notified about new Information Security Specialist jobs in Dubai, Dubai, United Arab Emirates.
Information Security Manager – Banking - Dubai Manager - Information Security & Data Privacy Senior Manager, Security Governance & Compliance Business Development Manager – MSSP, Cloud & Cybersecurity Integration Cybersecurity Governance, Risk and Compliance (GRC) Officer P-3 - Rome, Italy Manager | Security & Infrastructure | UAE National Manager-Data Privacy- Cyber Security (Arabic Speaker Preferred) Information Security Officer (UAE National) Digital Forensics and Incident Response Consultant Consultant-Identity Access Management (Cybersecurity)Dubai, Dubai, United Arab Emirates 1 year ago
Information Security - Data Protection Consultant Assistant Manager-Cyber (Identity and Access Management) Security Consultant – WAF, Proxy, DLP, VAPT, and Digital Security Assessment Consultant/Senior Consultant - Data Security - Cybersecurity(Arabic Speaking Preferred) Consultant-Cyber (Identity and Access Management) Manager– Network Security (UAE National)Dubai, Dubai, United Arab Emirates 1 year ago
Senior Security Lead - F5 WAF and Firewall Technical Consultant & Project Coordinator - CybersecurityAjman, Ajman Emirate, United Arab Emirates 6 months ago
We're unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSecurity and Risk Management Professional
Posted today
Job Viewed
Job Description
We are seeking a highly skilled Security Manager to oversee the security of our premises, staff, and assets. Key responsibilities include developing, implementing, and monitoring security policies and procedures; ensuring personnel and visitor safety; responding to security incidents; and managing security staff.
Essential Qualifications:- Bachelor's Degree in a relevant field such as security management, business administration, or law enforcement
- Minimum 3 years experience in a similar role with responsibility for security policy development and implementation
- Familiarity with various security systems including surveillance cameras, access control, fire alarms, and other safety measures
- Strong problem-solving and communication skills with ability to work effectively under pressure
- Confidentiality and discretion when handling sensitive information
- Knowledge of relevant laws and regulations related to security and risk management
- A competitive salary package with opportunities for career progression
- The chance to work in an international environment with experienced professionals
- Ongoing training and development to enhance your skillset
- Opportunities for advancement within the organization
This job posting is currently active and accepting applications.