Virtual Chief Information Security Officer (vCISO)
ITSEC · Dubai, Dubai, United Arab Emirates
Apply & track with Apply Edge🚨 ITSEC is Hiring: Virtual Chief Information Security Officer (vCISO)📍 Dubai / UAE Preferred🌍 Exceptional international candidates may also be considered🤝 Full-time, fractional & specialist engagements may be availableAs ITSEC expands its work with regulated financial institutions, FinTechs, Virtual Asset businesses, and other high-compliance organizations, we are building our Virtual Executive Services practice.We are looking for an experienced Virtual Chief Information Security Officer (vCISO) to provide senior cybersecurity leadership to clients operating in highly regulated environments, including VARA, DFSA/DIFC, ADGM/FSRA, and CBUAE-related engagements.The RoleThe vCISO will take ownership of clients' cybersecurity governance, security strategy, risk management, and regulatory cybersecurity obligations.This is a senior, client-facing position requiring someone who can confidently work with CEOs, Boards, Compliance Officers, regulators, auditors, technology teams, and other senior stakeholders.Key Responsibilities
- Develop and oversee cybersecurity strategies and security roadmaps aligned with clients' business and regulatory requirements.
- Establish, implement, maintain, and continuously improve Information Security Management Systems (ISMS).
- Develop and oversee security governance frameworks, policies, standards, and procedures.
- Lead technology and cybersecurity risk assessments and support appropriate risk treatment and remediation.
- Support cybersecurity and technology readiness for regulatory requirements and licensing engagements.
- Provide oversight of incident response, crisis management, and cybersecurity resilience.
- Oversee vulnerability management and penetration-testing programs, including remediation activities.
- Provide governance and oversight for cloud, infrastructure, and information security.
- Assess and manage cybersecurity risks arising from third parties, vendors, and supply-chain relationships.
- Support regulatory inspections, cybersecurity audits, assessments, and remediation programs.
- Prepare and deliver cybersecurity reports and updates to Boards, executives, and senior management.
- Work closely with compliance, technology, risk, and senior management teams to ensure cybersecurity requirements are effectively implemented.Required Experience & Qualificationsâś… 10+ years of relevant cybersecurity / information security experienceâś… Previous experience as a CISO, Head of Security, Head of Information Security, or equivalent senior leadership roleâś… Strong knowledge of ISO 27001, NIST Cybersecurity Framework (NIST CSF), CIS Controls, and related cybersecurity requirementsâś… Experience working with regulated organizationsâś… Strong cybersecurity governance, risk management, policy, and documentation capabilitiesâś… Experience interacting with senior executives, Boards, Compliance Officers, auditors, and other senior stakeholdersâś… Ability to manage multiple client engagements and take ownership of cybersecurity programsâś… Strong executive communication and presentation skillsâś… Commercial awareness and a solution-oriented mindsetâś… UAE/GCC regulatory exposure is a major advantageAdvantageous CertificationsRelevant certifications may include:
- CISSP
- CISM
- CRISC
- CCISO
- ISO 27001 Lead Implementer
- ISO 27001 Lead Auditor
- Other relevant cybersecurity and risk certificationsEngagement Model📍 Dubai / UAE preferred🌍 Exceptional international candidates may also be considered🤝 Full-time, fractional, and specialist engagement models may be available depending on experience and client requirements.At ITSEC, this is not an internal-title-only position.The successful candidate will work directly with regulated businesses where cybersecurity leadership is a critical component of their licensing, operational readiness, governance, regulatory compliance, and long-term growth.📩 Apply to: talents@itsecnow.com