Chief Information Security Officer (CISO)
Summary
Oversee cybersecurity strategy, risk, and compliance for a cloud-native payments and stored-value facility in Dubai, ensuring PCI DSS and UAE regulations are met while protecting AWS-based infrastructure.
Chief Information Security Officer
The Role
Security Strategy & Governance
- Define and maintain a multi-year cybersecurity strategy aligned with business growth, risk appetite, and regulatory
obligations.
- Establish and maintain the information security policy framework, reviewed at least annually.
- Maintain the cyber risk register and own the security maturity roadmap against a recognised control framework (NIST CSF, CIS Controls,
or ISO 27001).
- Own the security risk acceptance and exception register.
- Provide security leadership and advisory to executive management and regulatory stakeholders.
Threat & Vulnerability Management
- Direct the enterprise vulnerability management programme, including scanning, risk-based prioritisation, and remediation
SLA enforcement.
- Oversee the penetration testing programme and ensure findings are remediated and retested within defined timelines.
- Maintain threat intelligence capability relevant to financial services and payments, and translate it into detection and control
improvements.
Security Operations
- Oversee security monitoring, detection, and response capabilities including SIEM, EDR/XDR, and SOC operations
(internal or MSSP-managed).
- Own incident response end
to end: maintain and test playbooks, run tabletop exercises, lead containment and recovery, and coordinate regulatory notification within applicable deadlines.
- Manage identity and access governance including RBAC design, privileged access management, joiner/mover/leaver controls,
and periodic access recertification.
- Define and enforce data loss prevention and data classification standards across all platforms.
Regulatory & Compliance (First Line)
- Maintain operational compliance with PCI DSS, CBUAE technology and information security risk requirements, UAE Information Assurance standards, and applicable
payment scheme obligations.
- Serve as primary security liaison to external auditors, QSAs, and regulatory examiners.
- Ensure security controls are documented, evidenced, tested, and audit-ready at all times.
- Track and close security-related audit and examination findings within agreed timelines.
Data Protection & Privacy
- Implement and maintain security controls supporting UAE PDPL and applicable cross-border data transfer obligations, in coordination with Legal and the
Data Protection Officer.
- Support privacy impact assessments and data breach assessment and notification.
Security Architecture
- Provide security input to system design, change requests, and new initiatives, and approve security architecture standards and
baseline configurations.
- Embed security-by-design in the engineering lifecycle, including secure SDLC, code review, dependency scanning, secrets
management, and CI/CD pipeline controls.
- Maintain cloud security posture standards for the AWS estate.
Cyber Resilience
- Ensure cyber scenarios are represented in business continuity and disaster recovery planning and testing.
- Validate backup integrity, immutability, and recovery capability against destructive attack scenarios.
Third-Party Security
- Assess the security posture of prospective and existing third parties and outsourced providers, proportionate to criticality and data exposure.
- Define security requirements for vendor contracts in coordination with Legal and Procurement.
- Manage security service providers (MSSP, penetration testing firms, consultants) against defined SLAs.
People & Capability
- Lead and develop the security team.
- Drive security awareness through training programmes and phishing simulations.
- Foster a constructive security culture that enables safe escalation and reporting.
Reporting
- Monthly security reporting to the CTO.
- Standing quarterly security and cyber risk update to the Board Risk Committee.
- Immediate notification of material incidents to the CTO, CEO, and Chief Risk Officer.
Requirements
Experience
- 10+ years of progressive experience in information security, with at least 5 years in a leadership role.
- Demonstrated experience in a regulated financial services environment (banking, payments,
fintech, or SVF).
- Hands-on experience with the PCI DSS compliance lifecycle in a payment environment.
- Proven track record of leading incident response during live security events.
- Experience managing SOC operations (internal or MSSP) including SIEM, EDR/XDR, and threat intelligence.
- Strong understanding of cloud security (AWS preferred), container and Kubernetes security, and API security.
- Experience with regulatory frameworks: CBUAE technology and information security risk circulars, UAE IA, or equivalent.
- Demonstrated ability to communicate security risk to executive and Board-level audiences.
- Experience managing third-party security vendors and service providers.
- Experience building and developing security teams.
- Demonstrated ability to deliver security outcomes within constrained budgets, prioritising risk reduction per unit of spend.
Leadership & Soft Skills
- Strong strategic thinking with ability to translate risk into business language.
- Ability to influence without authority across engineering, product, and business teams.
- Clear communicator who can brief executives and regulators under pressure.
- Collaborative approach with Engineering, Operations, GRC, and business stakeholders.
- Comfortable in fast-paced, scaling environments with evolving priorities.
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent professional experience.
- Industry certifications required (one or more): CISSP, CISM, CISA, or ISO 27001 Lead Auditor.
- Additional certifications valued: PCIP, OSCP, CCSK, CRISC, AWS Security Specialty.
Technology Environment
Additional Conditions
- Participation in an on-call escalation rota for security incidents.
- Availability outside standard hours during live incidents and major change events.
- Appointment subject to enhanced background screening appropriate to a regulated financial services control function.