Assistant Manager, Security Governance & Compliance (UAE National)

🏢 Commercial Bank Of Dubai
📍 United Arab EmiratesFull-timeOn-site
📅 Posted: 1w ago🔄 Updated: 1w ago
CV%
✨ AI Summary
The Assistant Manager, Security Governance & Compliance will support the implementation and improvement of the bank's information security governance and compliance framework. This role involves maintaining security policies, standards, controls, risk registers, and ensuring regulatory compliance. Key responsibilities include developing and enhancing the security governance framework, managing security metrics and reporting, establishing and enforcing security policies, and leading security awareness programs. The position also involves ensuring compliance with international and UAE-specific regulatory frameworks, conducting risk assessments and vulnerability analyses, and overseeing third-party risk management. Collaboration with cross-functional teams and staying updated on emerging threats and trends are crucial.
Required Skills
Other
Lead AuditorNESA UAE IACisaSWIFT CSPSTRIDECisspCRISC
Information Technology
Threat ModelingPCI-DSSISO 27001NIST
Requirements
Requires a Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Risk Management, or a related discipline. Must have a minimum of 5-7 years of experience in information security, cybersecurity governance, IT risk, technology compliance, audit, or related functions, preferably in banking or financial services. A good understanding of information security governance frameworks, regulatory requirements, risk management practices, security controls, and internal policy management is essential. Experience in audit coordination, compliance monitoring, control testing, evidence management, policy review, risk registers, management reporting, and remediation tracking is required. Knowledge of cybersecurity standards and frameworks like ISO 27001, NIST, PCI-DSS, SWIFT CSP, UAE regulatory requirements, and data protection principles is preferred. Experience with Threat Modelling (MITRE ATT@CK, STRIDE, OWASP etc.) is also required.
Description
Job Purpose:To support the implementation, monitoring, and continuous improvement of the Bank's information security governance and compliance framework. The role assists in maintaining security policies, standards, controls, risk registers, regulatory compliance deliverables, audit coordination, third-party security governance, awareness activities, and management reporting to ensure that the Bank's information assets, systems, and processes remain protected and aligned with internal requirements, regulatory obligations, and industry best practices.Key Accountabilities:Security Governance & Compliance Strategic Framework Development: Design, implement, and continuously enhance a comprehensive information security governance framework that aligns with the bank's strategic goals, regulatory obligations, and risk appetite. Security Metrics & Reporting: Develop and maintain dashboards and reporting mechanisms that aggregate security control effectiveness, risk posture, and compliance status across the organization. Policy Management: Establish, review, and enforce enterprise-wide security policies, standards, and procedures to ensure consistent implementation and adherence. Awareness & Training: Lead the development and delivery of targeted security awareness programs, including phishing simulations, role-based training, and executive briefings to foster a culture of security. Regulatory Compliance: Ensure ongoing compliance with international and UAE-specific regulatory frameworks and standards such as ISO/IEC 27001, NIST, PCI-DSS, NESA, UAE IA, SWIFT CSP, and others.Security Assurance Risk & Vulnerability Management: Conduct comprehensive risk assessments and vulnerability analyses across various domains including ISMS, projects, change initiatives, thematic reviews, and third-party engagements. Threat Modelling & DevSecOps Integration: Implement threat modelling practices within the software development lifecycle and change management processes to proactively identify and mitigate risks. Third-Party Risk Management: Oversee a robust third-party security assessment program that spans the entire supplier lifecycle—from onboarding and due diligence to ongoing monitoring and offboarding.Collaboration & Strategic Engagement Cross-Functional Integration: Partner with business units, IT, legal, compliance, and risk teams to embed security into business processes, digital transformation initiatives, and strategic projects. Security Advocacy & Thought Leadership: Stay abreast of emerging threats, technologies, and industry trends. Share insights with internal stakeholders and contribute to the bank's strategic security roadmap.Requirements:Experience & Academic Qualifications: Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Risk Management, or a related discipline. Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer / Lead Auditor, or equivalent are preferred. Minimum 5–7 years of experience in information security, cybersecurity governance, IT risk, technology compliance, audit, or related functions, preferably within banking or financial services. Good understanding of information security governance frameworks, regulatory requirements, risk management practices, security controls, and internal policy management. Experience in audit coordination, compliance monitoring, control testing, evidence management, policy review, risk registers, management reporting, and remediation tracking. Knowledge of cybersecurity standards and frameworks such as ISO 27001, NIST, PCI-DSS, SWIFT CSP, UAE regulatory requirements, and data protection principles is preferred. Experience of Threat Modelling (MITRE ATT@CK, STRIDE, OWASP etc.)
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00