freehire launches on Product Hunt on 26 August.

Follow →

Chief Information Security Officer (CISO)

Summary

Oversee cybersecurity strategy, risk, and compliance for a cloud-native payments and stored-value facility in Dubai, ensuring PCI DSS and UAE regulations are met while protecting AWS-based infrastructure.

Chief Information Security Officer

The Role

Lead the organisation's cybersecurity and information security programme, ensuring the confidentiality, integrity, and availability of information assets across a regulated financial services environment. Define and execute security strategy, own and manage cyber risk within Board-approved appetite, and maintain regulatory compliance within a cloud-native payments and stored value facility (SVF) operation.
The role advises and recommends on security risk, with independent authority to escalate unresolved risk to the CTO, CEO, and Board Risk Committee. Operates within an approved annual security budget; spend proposals require cost-benefit justification and are prioritised within the allocated envelope.


Key Responsibilities

Security Strategy & Governance

  • Define and maintain a multi-year cybersecurity strategy aligned with business growth, risk appetite, and regulatory obligations.
  • Establish and maintain the information security policy framework, reviewed at least annually.
  • Maintain the cyber risk register and own the security maturity roadmap against a recognised control framework (NIST CSF, CIS Controls, or ISO 27001).
  • Own the security risk acceptance and exception register.
  • Provide security leadership and advisory to executive management and regulatory stakeholders.


Threat & Vulnerability Management

  • Direct the enterprise vulnerability management programme, including scanning, risk-based prioritisation, and remediation SLA enforcement.
  • Oversee the penetration testing programme and ensure findings are remediated and retested within defined timelines.
  • Maintain threat intelligence capability relevant to financial services and payments, and translate it into detection and control improvements.

Security Operations

  • Oversee security monitoring, detection, and response capabilities including SIEM, EDR/XDR, and SOC operations (internal or MSSP-managed).
  • Own incident response end to end: maintain and test playbooks, run tabletop exercises, lead containment and recovery, and coordinate regulatory notification within applicable deadlines.
  • Manage identity and access governance including RBAC design, privileged access management, joiner/mover/leaver controls, and periodic access recertification.
  • Define and enforce data loss prevention and data classification standards across all platforms.

Regulatory & Compliance (First Line)

  • Maintain operational compliance with PCI DSS, CBUAE technology and information security risk requirements, UAE Information Assurance standards, and applicable payment scheme obligations.
  • Serve as primary security liaison to external auditors, QSAs, and regulatory examiners.
  • Ensure security controls are documented, evidenced, tested, and audit-ready at all times.
  • Track and close security-related audit and examination findings within agreed timelines.

Data Protection & Privacy

  • Implement and maintain security controls supporting UAE PDPL and applicable cross-border data transfer obligations, in coordination with Legal and the Data Protection Officer.
  • Support privacy impact assessments and data breach assessment and notification.


Security Architecture

  • Provide security input to system design, change requests, and new initiatives, and approve security architecture standards and baseline configurations.
  • Embed security-by-design in the engineering lifecycle, including secure SDLC, code review, dependency scanning, secrets management, and CI/CD pipeline controls.
  • Maintain cloud security posture standards for the AWS estate.

Cyber Resilience

  • Ensure cyber scenarios are represented in business continuity and disaster recovery planning and testing.
  • Validate backup integrity, immutability, and recovery capability against destructive attack scenarios.

Third-Party Security

  • Assess the security posture of prospective and existing third parties and outsourced providers, proportionate to criticality and data exposure.
  • Define security requirements for vendor contracts in coordination with Legal and Procurement.
  • Manage security service providers (MSSP, penetration testing firms, consultants) against defined SLAs.

People & Capability

  • Lead and develop the security team.
  • Drive security awareness through training programmes and phishing simulations.
  • Foster a constructive security culture that enables safe escalation and reporting.

Reporting

  • Monthly security reporting to the CTO.
  • Standing quarterly security and cyber risk update to the Board Risk Committee.
  • Immediate notification of material incidents to the CTO, CEO, and Chief Risk Officer.

Requirements

Experience

  • 10+ years of progressive experience in information security, with at least 5 years in a leadership role.
  • Demonstrated experience in a regulated financial services environment (banking, payments, fintech, or SVF).
  • Hands-on experience with the PCI DSS compliance lifecycle in a payment environment.
  • Proven track record of leading incident response during live security events.
  • Experience managing SOC operations (internal or MSSP) including SIEM, EDR/XDR, and threat intelligence.
  • Strong understanding of cloud security (AWS preferred), container and Kubernetes security, and API security.
  • Experience with regulatory frameworks: CBUAE technology and information security risk circulars, UAE IA, or equivalent.
  • Demonstrated ability to communicate security risk to executive and Board-level audiences.
  • Experience managing third-party security vendors and service providers.
  • Experience building and developing security teams.
  • Demonstrated ability to deliver security outcomes within constrained budgets, prioritising risk reduction per unit of spend.

Leadership & Soft Skills

  • Strong strategic thinking with ability to translate risk into business language.
  • Ability to influence without authority across engineering, product, and business teams.
  • Clear communicator who can brief executives and regulators under pressure.
  • Collaborative approach with Engineering, Operations, GRC, and business stakeholders.
  • Comfortable in fast-paced, scaling environments with evolving priorities.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
  • Industry certifications required (one or more): CISSP, CISM, CISA, or ISO 27001 Lead Auditor.
  • Additional certifications valued: PCIP, OSCP, CCSK, CRISC, AWS Security Specialty.


Technology Environment

AWS (Lambda, ECS, EKS, RDS, CloudFront, WAF), Kubernetes, Kafka, PostgreSQL, Java/Spring Boot, React, React Native, Datadog, Microsoft 365/Entra ID, Terraform.


Additional Conditions

  • Participation in an on-call escalation rota for security incidents.
  • Availability outside standard hours during live incidents and major change events.
  • Appointment subject to enhanced background screening appropriate to a regulated financial services control function.


See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available