Manager - Information Security Office
Community Development Authority · Dubai, United Arab Emirates
Apply & track with Apply EdgeJob PurposeManage the Authority’s information security framework by ensuring compliance with government requirements and approved standards, managing security risks, enhancing business readiness and continuity, and protecting digital and information assets in support of the Authority’s objectives and the sustainability of its services.Operational Duties and ResponsibilitiesLead the development of the strategic information security roadmap, define priorities and future initiatives, oversee their implementation, and measure their impact to enhance the level of security maturity and achieve the Authority’s strategic objectives.Manage the implementation of government information security requirements and the Information Security Regulations (ISR) by monitoring the implementation of approved security policies and controls, conducting periodic reviews, assessments, and oversight activities to identify violations, taking appropriate corrective actions, submitting recommendations to the Information Security Committee, ensuring compliance with government requirements, and enhancing the protection of the Authority’s information and digital assets.Oversee the compliance of organizational units with information security standards and requirements across both technical and non-technical projects by supervising reviews of initiatives, projects, and operational plans; assessing associated security risks; and approving the necessary security controls and requirements before and during implementation.Oversee business continuity planning, disaster recovery requirements, and related certifications and accreditations by developing and updating plans and procedures, monitoring periodic testing, and coordinating with relevant stakeholders to ensure the continuity of the Authority’s critical services and operations and enhance its readiness to respond to crises, emergencies, and operational risks.Oversee enterprise-level information security risk management by developing risk assessment methodologies, monitoring security risk registers, and submitting recommendations regarding risk treatment to the relevant committees to minimize the impact of cyber threats on the Authority’s operations and information assets.Measure and monitor information security and cybersecurity performance and compliance indicators by preparing dashboards and periodic reports for senior management and relevant committees, analyzing results, identifying improvement opportunities, supporting decision-making, and enhancing the Authority’s security maturity level.Develop and implement the annual information security and cybersecurity awareness and training plan by establishing frameworks to identify training needs, monitoring the implementation of training programs and awareness campaigns, conducting periodic tests and simulations, and measuring their impact on employees and relevant stakeholders to raise security awareness, reduce risks arising from human error, and strengthen the Authority’s information security culture.Collaborate with the Human Resources Department to plan for and provide specialized cybersecurity and information security competencies by identifying staffing and specialization requirements and participating in professional development planning, with the objective of building sustainable organizational capabilities and ensuring the availability of qualified human resources to support the Authority’s cybersecurity requirements.Oversee security incident management and response by approving the necessary procedures and methodologies for detecting and investigating incidents, coordinating with relevant stakeholders, and monitoring the implementation of corrective and preventive measures to minimize the impact of security incidents and enhance the Authority’s response and recovery capabilities.Oversee compliance reviews against security controls, closure of audit findings, and periodic information security assessments by conducting security assessment tests, monitoring their results, and following up on associated improvement plans to ensure their effectiveness and maintain continuous compliance with regulatory requirements.Oversee the Authority’s participation in international certifications and awards related to information security and cybersecurity by assessing the Authority’s readiness, documenting practices and achievements, preparing nomination and submission files, and coordinating with relevant organizational units to follow up on assessment and improvement requirements, thereby enhancing the Authority’s institutional standing, highlighting its achievements in information security, and adopting best practices.Build and manage strategic partnerships with government, regulatory, and cybersecurity-specialized entities through participation in committees and joint working groups and the exchange of relevant expertise, practices, and information to enhance institutional integration and benefit from national cybersecurity initiatives and expertise.Oversee relationships with regulatory authorities, service providers, and external partners concerning information security requirements by monitoring contractual obligations, security controls, assessments, and periodic audits to ensure that external parties comply with security requirements and protect the Authority’s data and information.Participate in national and sector-specific initiatives and programs related to information security and secure digital transformation through participation in conferences, forums, workshops, and joint programs to enhance the Authority’s standing and adopt best practices and the latest trends in cybersecurity.Prepare and submit specialized information security and cybersecurity reports and recommendations to senior management and relevant committees, covering performance indicator results, compliance levels, audit findings, risk management, and security incidents, and provide data-driven insights, recommendations, and development proposals based on leading practices to support strategic decision-making, enhance the effectiveness of the information security framework, and improve the Authority’s readiness to address cybersecurity risks and threats.Comply with the Authority’s approved information security policies and procedures and adhere to applicable controls to ensure the confidentiality of information.Perform any other duties and responsibilities within the scope of the position.Educational RequirementsBachelor’s degree in information security, Cybersecurity, Computer Science, Computer Engineering, Information Systems, or any related field.Preference will be given to candidates holding a master’s degree in Cybersecurity, Information Technology Management, Risk Management, Business Administration, or a related field.Proficiency in both Arabic and English, including speaking and writing.Experience RequirementsAt least 10 years of experience in information security or cybersecurity.8 years of experience may be accepted for candidates holding a Master’s or Doctoral degree, or relevant professional certifications in Information Security or Artificial Intelligence.