Senior IT GRC Officer
Hays · Dubai, United Arab Emirates
Apply & track with Apply EdgeYour New CompanyYou will be joining a premier cybersecurity and managed security services firm headquartered in Dubai, UAE. Driven by a core philosophy built on innovation, integrity, and strong industry partnerships, this organization operates at the forefront of digital resilience, threat detection, and IT governance. They partner with high-profile enterprise and financial institutions across the region to secure complex digital infrastructures and ensure total alignment with regional regulatory mandates.Your New RoleAs the Senior Officer – IT Risk, reporting directly to the Head of Compliance and Risk, you will be responsible for implementing and operating the organization’s technology control framework. In this key role, you will ensure that critical payment systems, digital wallets, and card processing environments remain secure, resilient, and fully compliant with Central Bank of the UAE (CBUAE) requirements for SVF and RPSCS license holders.Key responsibilities include:Implementing and maintaining IT governance frameworks aligned with CBUAE regulations, ISO/IEC 27001, and UAE IT standards.Managing the enterprise technology risk register, performing threat modeling, and assessing third-party vendor and cloud risks.Overseeing end-to-end security operations, including cyber incident response, threat containment, root-cause analysis, and SIEM/SOC governance.Managing data protection controls, including encryption, tokenization, key lifecycle management, IAM, DLP, and firewalls.Driving vulnerability assessments and penetration testing cycles while tracking remediation against defined SLAs.Supporting Business Continuity Planning (BCP), Disaster Recovery (DR) testing, and representing the technology risk function during internal/external audits and CBUAE regulatory inspections.What You'll Need to SucceedEducation: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.Certifications: Professional security certifications such as CISA, CISM, or CISSP are required.Experience: Minimum 5+ years of dedicated experience in information/cybersecurity, with strong exposure to the BFSI or Fintech sectors in the UAE.Regulatory Expertise: In-depth knowledge of CBUAE regulatory frameworks, UAE Information Assurance Regulations, and security standards (ISO 27001, NIST CSF, COBIT, ITIL).Technical & Governance Skills: Proven ability to manage enterprise risk registers, third-party risk, security architecture reviews, and regulatory audits.What You'll Get in ReturnThe opportunity to hold a high-visibility, impactful technology risk position within a fast-growing cybersecurity leader in Dubai.Direct exposure to high-level regulatory frameworks, including CBUAE inspections and large-scale digital payment infrastructures.A competitive Dubai-based compensation package combined with continuous professional development in a pioneering, security-first environment.A collaborative workplace culture that values technical excellence and career progression.What You Need to Do NowIf you are interested in this opportunity, click 'apply now' with an up-to-date copy of your CV, and if relevant a Hays consultant will contact you for a further discussion.