Infosec Management Officer (GRC)
CPX · Abu Dhabi Emirate, United Arab Emirates
قدّم وتابع مع أبلاي إيدجPrimary ResponsibilitiesMaintain the Information Security Management System and supporting policies, standards, procedures, guidelines and templates.Perform and document information security risk assessments for technologies, applications, vendors, cloud/SaaS services, AI tools and business initiatives.Maintain the risk register, treatment plans, risk owners, due dates, residual risk and acceptance evidence.Map controls to applicable requirements including UAE IA, ADHICS, ISO/IEC 27001, ISO/IEC 27701, ISO 22301 and contractual obligations.Coordinate control self-assessments, evidence collection, gap assessments and remediation tracking.Support internal and external audits, auditor queries, evidence packs, corrective actions and closure validation.Support certification readiness and maintenance activities, including management review inputs and improvement actions.Conduct vendor and third-party security due diligence; track high-risk findings and remediation commitments.Prepare governance dashboards, compliance status, risk summaries, heatmaps, ageing reports and executive updates.Maintain consolidated action, issue, dependency and decision registers for governance forums.Coordinate policy exceptions and risk acceptances through defined approval, compensating control and expiry processes.Support business continuity and resilience activities including BIA, plans, exercises and corrective action tracking.Assist with security awareness, policy communication and role-based guidance.Ensure records are complete, version-controlled, confidential and audit-ready.Secondary ResponsibilitiesSupport privacy, AI governance and customer assurance activities in coordination with specialist teams.Track incident lessons learned and ensure governance actions are incorporated into policies and risk treatment.Facilitate workshops, interviews, governance meetings and management reviews.Contribute to continuous improvement and maturity roadmaps.Skills / CertificationsISO/IEC 27001 Lead Implementer or Lead AuditorCISA, CRISC, CISM or CISSP (preferred)ISO 22301/BCM training (advantage)Privacy or third-party risk certification (advantage)ITIL Foundation (advantage)Soft skills: Excellent written and verbal communication, Analytical thinking and problem solving, Attention to detail and quality, Accountability and ownership, Teamwork and stakeholder collaboration, Ability to prioritize and meet deadlines, Ability to work at client sites and provide after-hours support when requiredMinimum Work Experience5+ years of GRC, information security assurance, risk, compliance or audit experience, preferably in government, healthcare or another regulated environmentEducationBachelor’s degree in Computer Science, Cybersecurity, Information Technology, Information Systems, Engineering or equivalent.Postgraduate qualification in information/cyber security is an advantage.Preferred Skill SetRisk assessment, control testing and risk register managementPolicy and standards developmentAudit and certification supportThird-party risk and compliance reportingStrong writing, coordination, evidence management and stakeholder communication