freehire launches on Product Hunt on 26 August.

Follow →

Assistant Manager Security Governance And Compliance

Open 32d

Operating in the UAE for over 50 years

CBD manages the financial requirements of some of the largest corporates and businesses operating in the country, driving the UAE economy. Over the years, CBD has transformed into a progressive and modern banking institution winning multiple awards for its digital initiatives, credit cards, bank accounts, mobile app features and services.

CBD has been recognized as the number one bank in the UAE on the Forbes list of The World’s Best Banks 2022.

As we continue to build upon our successes, we are looking for ambitious individuals who are passionate about the banking and finance industry and the markets in which CBD operates. Just as important to us is your ability to demonstrate a talent for dealing with people - your colleagues and our customers - and delivering service that really goes the extra mile.

Job Purpose:

Spearheading and managing security governance, risk assessment and security compliance programs.
Liaise with internal and external stakeholders and actively act as key influencer in security decisions.
Conduct independent security risk assessments, compliance reviews and train other staff members.
Support and work closely with business and information technology to review new initiatives, implement application security program, manage third party vendors, service contracts and interact with IT management on a regular basis.
Propose and plan information security strategy, yearly plans, inline to regulatory, compliance requirements and key risk areas for the bank.
Establish accountability to ensure controls are implemented to mitigate the risk and also mentor and guide internal teams, IT, IT security, IT development, business toward improving CBD security posture.
Developing and maintaining information security policies. Other activities include maintaining risk register, providing monthly management dashboard with KPI status.
Perform security review of new projects and project changes. Lead and manage application security assessment teams and reporting staff.
Act as key technical resource in a number of important CISO office activities, including application security risk assessments, security compliance reviews and independent security assessments.

Principal Accountabilities:

  • Establish an information security governance framework.
  • Document, review and update information security policies to protect the bank and its sensitive data while ensuring compliance with relevant regulations.
  • Break complex security requirements into easy-to-understand action plans for management.
  • Track and close security concerns with IT and business owners.
  • Provide management dashboards showing progress on compliance and security KPIs.
  • Support management in developing a security strategy.
  • Manage Swift and NESA/UAE IA compliance management programs.
  • Perform enterprise risk assessment and cloud risk assessment.
  • Perform vendor and third party risk assessment inline with information security risks.
  • Review information security risk acceptance requests.
  • Provide security awareness training for new joiners.
  • Conduct compliance review of regulatory requirements to identify gaps and action plans.
  • Review and approve changes on business applications security changes.
  • Represent information security in various meetings.
  • Develop business cases for special security engagements.
  • Manage penetration testing and vulnerability assessment activities.
  • Act as subject matter expert for security decisions, regularly reviewing security metrics, preparing reports and dashboards.
  • Present application security gaps and prepare reports on findings and recommendations.
  • Manage and evaluate application security testing activities for possible vulnerabilities.
  • Ensure that identified risk is managed in accordance with the IT risk management program by regular review and follow up.
  • Conduct application security risk assessments and independent assessments (penetration testing), including risk modelling, analysis and mitigation.
  • Manage and develop appropriate information security policies, standards, procedures, checklists and guidelines using generally recognized security concepts tailored to meet the requirements of the organization.
  • Create necessary documentation that codifies the application security program, including the development of secure coding policies, procedures and standards.
  • Lead active discussions around design and reviews of applications from a security standpoint to ensure SDLC process is being followed.
  • Work with third party vendors, managing the contract and projects.
  • Guide, influence and work with IT developers to adopt secure practices when developing applications.
  • Independently manage different technical assignments, involved in the evaluation and selection of third-party vendors and solutions.
  • Achieve and maintain compliance with applicable security regulations and internal policies.
  • Liaise among the IT, IT security team, compliance, internal audit, and HR management teams as required.
  • Mentor and train junior staff and other CBD staff as required.