Apply Edge Start your job search

Security Business Analyst

Dreamcast Interactive · Dubai, United Arab Emirates

Apply & track with Apply Edge

One Dubai-based contract seat with our external partner: a large retail group headquartered in Dubai with a workforce of more than 16,000 people. You will turn information security requirements into clear, documented, traceable delivery requirements inside its enterprise transformation programme, and keep the thread from every risk to its evidence unbroken.ABOUT THE CLIENTOur partner is one of the largest luxury and premium retail groups in the Middle East. Headquartered in Dubai, it employs more than 16,000 people across the region and runs several hundred stores, dozens of e-commerce sites and apps, and a portfolio of over 300 international brands. It is part-way through a multi-year technology transformation: a new SAP core across finance, people and logistics, and the omnichannel retail estate around it, delivered with a global system integrator. Group Information Security runs a dedicated security workstream inside that programme: remediation of agreed security priorities, hypercare on the releases already live, and security readiness for the next major release. This seat is the analyst at the centre of that workstream. We share the client's name with shortlisted candidates.ABOUT THE ROLEDreamcast Interactive is a Dubai-headquartered studio building AI systems, web and mobile products, immersive AR/VR and full-cycle games for clients across the US, UK and GCC. We are placing a Security Business Analyst with the client above on a [12-month] full-time contract, engaged through Dreamcast and based at the client's Dubai head office with hybrid flexibility. This is client work, not an internal role.You report to the Security Delivery Manager and work daily with Group Information Security subject-matter experts, the programme teams, business stakeholders and the delivery partners. The value you add is precision: requirements that specialists and delivery teams read the same way, acceptance criteria that can actually be evidenced, and a traceability record that survives an audit.WHAT YOU WILL OWN- Gathering, analysing and documenting security requirements across remediation, hypercare and the next release- Translating them, with the security specialists, into clear business, functional and technical requirements that delivery teams can build to- Requirements workshops with business, technology and partner stakeholders- Acceptance criteria and evidence requirements for each requirement and control- End-to-end traceability from risks to controls, requirements, remediation actions and evidence- Accurate records of action ownership, milestones, dependencies, decisions and supporting documentation- Support to the Security Delivery Manager in maintaining the integrated security remediation plan- Gaps, inconsistencies and dependencies across requirements and plans, identified and raised for resolution- Evidence submissions tracked and mapped to the right requirement or control before they reach assurance- Workstream reporting and governance materials- Security requirements identified early in the next release and traced through design, build, testing and implementation, with the specialists confirming that designs and delivered solutions meet themWHAT YOU BRING- Business analysis experience in a technology, information security, risk or large-scale transformation environment- You have gathered, analysed, documented and managed business, functional and technical requirements through a full delivery lifecycle- Requirements management and end-to-end traceability as a habit: you link requirements to risks, controls, remediation actions, acceptance criteria and evidence without being asked- Working knowledge of information security principles, technology risk and security controls, enough to translate a specialist's requirement into a delivery requirement- Experience on complex programmes with many business, technology and third-party stakeholders- Confident facilitation of requirements workshops with technical specialists, business stakeholders and delivery teams- Analytical and precise: you spot dependencies, inconsistencies and gaps, and you keep a high volume of requirements and actions accurate- Structured documentation: requirements, action registers, decision logs and evidence repositories- Clear written and spoken English with technical and non-technical audiencesNICE TO HAVE- Business analysis within SAP, ERP or other large enterprise transformation programmes- Familiarity with ISO/IEC 27001 and NIST CSF- CBAP, CCBA or a comparable analysis qualification- Previous work in the Middle EastCONTRACT- 12-month full-time contract through Dreamcast Interactive, starting as soon as possible, with extension based on performance- Based in Dubai at the client's head office, with hybrid flexibility- Competitive monthly rate, benchmarked to the profilePrefer email? hello@dreamcastinteractive.com with the subject "Security Business Analyst – Your Name".