Executive - Information Security
Key Accountabilities:
Information Security Operations
- Support the day-to-day operation and monitoring of information security systems, controls, and processes in accordance with approved policies, standards, and procedures.
- Review security alerts and logs using available security tools, document observations, and promptly escalate suspected threats, vulnerabilities, or control failures.
- Assist in tracking vulnerabilities, security findings, and remediation actions with relevant internal teams and service providers.
- Maintain accurate security records, registers, evidence, and operational documentation.
Risk, Compliance and Audit Support
- Assist in information security risk assessments by gathering information, documenting risks and controls, and maintaining risk and remediation trackers.
- Support internal and external audits by coordinating evidence, arranging meetings, recording findings, and following up on agreed corrective actions.
- Assist in monitoring compliance with the ISMS, ISO/IEC 27001, applicable Dubai Electronic Security Center (DESC) requirements, and internal security policies.
- Identify potential gaps or non-compliance and escalate them to the Manager – Information Security with clear supporting information.
Cybersecurity Incident Support
- Support the logging, triage, investigation, containment, and documentation of cybersecurity incidents under the direction of the Manager – Information Security.
- Maintain incident records, timelines, evidence, and action logs, and support post-incident reviews and lessons-learned activities.
- Follow approved incident response and escalation procedures and maintain appropriate confidentiality.
Policies, Procedures and ISMS Documentation
- Support the development, review, communication, and maintenance of information security policies, procedures, standards, guidelines, and templates.
- Maintain controlled versions of information security documents and ensure records are complete, current, and accessible to authorized stakeholders.
- Support the collection and reporting of ISMS performance data, control implementation status, and supporting evidence.
Security Awareness and Stakeholder Coordination
- Support the delivery of information security awareness campaigns, training sessions, phishing simulations, and related communications.
- Respond to routine information security queries and coordinate with employees, IT teams, vendors, and other stakeholders as required.
- Promote responsible use of Dubai Chambers’ information and technology resources and reinforce a positive security culture.
Quality, Health, Security, Safety and Environment
- Ensure compliance with regulatory requirements and relevant quality, health, safety, security and environmental procedures and controls across the department to guarantee employee safety and delivery of high-quality services.
Reporting
- Prepare relative reports in a timely and accurate manner to meet the departmental requirements, policies, and standards.
Others
- Other relevant tasks of the job purpose when, and if required.
Qualifications & Experience:
Minimum Qualification
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Computer Engineering, Information Technology, or a related discipline.
Minimum Experience and Skills
- 0–2 years of relevant experience in information security, cybersecurity, IT security, risk, compliance, or audit.
- Relevant internships, cooperative training, graduate projects, or national service experience may be considered.