Security Assurance Specialist
Dreamcast Interactive · Dubai, United Arab Emirates
Apply & track with Apply EdgeOne Dubai-based contract seat with our external partner: a large retail group headquartered in Dubai with a workforce of more than 16,000 people. You will provide independent assurance over the security controls and remediation work inside its enterprise transformation programme: is each control designed, implemented and evidenced the way the Group requires, and can that conclusion be defended.ABOUT THE CLIENTOur partner is one of the largest luxury and premium retail groups in the Middle East. Headquartered in Dubai, it employs more than 16,000 people across the region and runs several hundred stores, dozens of e-commerce sites and apps, and a portfolio of over 300 international brands. It is part-way through a multi-year technology transformation: a new SAP core across finance, people and logistics, and the omnichannel retail estate around it, delivered with a global system integrator. Group Information Security runs a dedicated security workstream inside that programme: remediation of agreed security priorities, hypercare on the releases already live, and security readiness for the next major release. This seat is the independent assurance voice in that workstream. We share the client's name with shortlisted candidates.ABOUT THE ROLEDreamcast Interactive is a Dubai-headquartered studio building AI systems, web and mobile products, immersive AR/VR and full-cycle games for clients across the US, UK and GCC. We are placing a Security Assurance Specialist with the client above on a [12-month] full-time contract, engaged through Dreamcast and based at the client's Dubai head office with hybrid flexibility. This is client work, not an internal role.You report to the Director of Information Security and you are independent of remediation delivery: control and remediation owners implement and provide evidence, you assess it. You work alongside the Security Delivery Manager and the Security Business Analyst and with the Group's wider GRC and security teams, so that the workstream's assurance position and the Group's methodology stay one and the same.WHAT YOU WILL OWN- Independent assessment of security controls and remediation evidence against the Group's defined requirements- Control design, implementation and, where it applies, operating effectiveness- The call on whether submitted evidence actually demonstrates that a remediation requirement is complete, and a clear, defensible written conclusion each time- Assurance activity prioritised by security risk and agreed remediation milestones- Evidence gaps identified and the required remediation or additional evidence communicated to the right action owner- An auditable assurance record across every control assessed- Traceability, with the Business Analyst, between risks, controls, actions and evidence- Reassessment of residual security risk as controls land, and independent assurance input into consolidated security risk reporting- Systemic or recurring control weaknesses identified and material findings escalated- Security readiness assessments through hypercare and into the next major release- Assessment against the Group's information security policies and standards and against ISO/IEC 27001:2022 and NIST CSF- Consistency with the Group's assurance methodology, and the transition of controls into its business-as-usual assurance modelWHAT YOU BRING- Strong experience in information security assurance, technology risk, IT audit or GRC- You have assessed security control design and effectiveness and can show it- A firm grasp of ISO 27001, NIST CSF and risk-based security assurance- Practical knowledge across identity and access management, access governance and segregation of duties, vulnerability management, network security, resilience, supplier security, data protection and security operations- Experience weighing technical and governance evidence and writing conclusions that stand up to challenge- Analytical rigour and clear written EnglishNICE TO HAVE- Security assurance within an SAP or ERP transformation programme (a strong advantage for this seat)- CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, or equivalent- Previous work in the Middle EastCONTRACT- 12-month full-time contract through Dreamcast Interactive, starting as soon as possible, with extension based on performance- Based in Dubai at the client's head office, with hybrid flexibility- Open only to candidates already based in the UAE- Competitive monthly rate, benchmarked to the profilePrefer email? hello@dreamcastinteractive.com with the subject "Security Assurance Specialist – Your Name".