Senior Information Security Manager

1 week ago


Dubai, Dubai, United Arab Emirates Chalhoub Group Full time

INSPIRE | EXHILARATE | DELIGHT

For over six decades, Chalhoub Group has been a partner and creator of luxury experiences in the Middle East. The Group, in its endeavour to excel as a hybrid retailer, has reinforced its distribution and marketing services with a portfolio of eight owned brands and over 300 international brands in the luxury, beauty, fashion, and art de vivre categories. More recently, the Group expanded its expertise into new categories of luxury watches, jewellery, and eyewear.

Every step at Chalhoub Group is taken with the customer at heart. Be it constantly reinventing itself or focusing on innovation to provide luxury experiences at over 750+ experiential retail stores, online and through mobile apps, each touch point leads to delighting the customer.

Today, Chalhoub Group stands for 14,000 skilled and talented professionals across seven countries, whose cohesive efforts have resulted in the Group being ranked third in the Middle East and first in Saudi Arabia as a Great Place to Work.

To keep the innovation journey going, the Group has set up "The Greenhouse", which is not just an innovation hub, but also an incubator space and accelerator for start-ups and small businesses in the region and internationally. This is just one of the several initiatives taken by the Group to reinvent itself, catalysed by forward thinking and future-proofing. The Group has also been embedding sustainability at the core of its business strategy with a clear commitment towards people, partners and the planet, and by being a member of the United Nations Global Compact Community and signatory of the Women's Empowerment Principles.

What You'll Be Doing

The Information Security Governance, Risk and Compliance (IS GRC) Senior Manager will be responsible for building and managing the Group Information Security GRC function. The function will deliver and manage ISO27001, Information Security Management System (ISMS), NIST CSF, PCI DSS, Supplier Assurance, Risk and Compliance activities. The ISMS caters for multiple complex IT environments and business processes.

Reporting to the Director of Information Security, the IS GRC Manager will develop and lead the IS GRC function and collaborate closely with key stakeholders across the business, suppliers, and Technology teams to implement best practice and assure controls to protect important information assets. The function will achieve and maintain certifications and compliance; and achieve alignment with industry standards and best practice.

  • Develop and lead an Information Security GRC team and capabilities.
  • Implement and manage all elements of the ISO2700:2022, ISMS documentation, including Policies, Standards, Controls, associated risk and exceptions registers, compliance testing.
  • Embedding and improving the ISMS controls across the 1st and 2nd line of defence operations and roadmap.
  • Assure compliance with NIST CSF and UCF across the technical ecosystem in partnership with Technology teams.
  • Lead internal and external assurance activities, certification and compliance audits, including controls gaps analysis and effectiveness assurance reviews across the Group and prioritising the output with business owners and the Information Security Board.
  • Provide advice, guidance and audit support to control owners.
  • Collaborate with both internal and external auditors and key stakeholders effectively to continually improve the posture of Information Security across the Group.
  • Day to day SME advice and guidance for change activity relating to implementation against Chalhoub Group policy, standards and controls.
  • Lead Information Security Risk Management, identify, assess and manage information security risks across Chalhoub Group.
    • Develop the Information Security Risk Management framework.
    • Ensure that it aligns and feeds into the organisation's broader corporate risk.
    • Performing risk analysis, manage risk lifecycle from various sources (e.g. Information Security Risk Assessment, Audit, Security Tests, etc).
    • Disseminating appropriate risk information to various levels within the organisation, as needed.
    • Ensuring that key 3rd party suppliers are measured against the ISO27001 control framework, and any identified risks managed within Chalhoub Group risk appetite.
  • Monitor evolving threat landscape and be intelligence led to factor in risk assessments.
  • Chair Information Security Risk Committee and Information Security Working Group.
  • Provide Information Security update as appropriate to the Risk and Crisis Committee.
  • Collaborate and work with stakeholders and interested parties to ensure Chalhoub Group is secure internally and externally.
  • Develop and manage a Group wide Information Security Education and Awareness program for employees and technical teams to embed and mature a culture of security awareness and compliance.

What You'll Need To Succeed

  • Proven experience in a multi-national retail organisation.
  • Proven track record of building and leading an Information Security GRC centre of excellence.
  • Significant knowledge and 5+ years' experience of ISO27001, NIST CSF, Data Privacy Law, PCI DSS and ITIL.
  • Awareness of regulatory requirements of the sector (e.g. UNC, GDPR; NIS Directive etc).
  • A solid understanding of Information Security Governance, Risk and Compliance policies, controls and best practice.
  • Previous experience developing, implementing and maintaining an Information Security Management System (ISMS), certification/re-certification to ISO27001.
  • Subject Matter Expert in enterprise Risk Management – Information Security
  • Experience in developing and embedding Risk Management Frameworks and associated processes and procedures.
  • Proven people management and leadership skills including performance management and improvement, measurement of KRIs, situational leadership, issue resolution, negotiation and motivating others.
  • Excellent senior leadership communication skills and demonstrable experience in a customer facing role.
  • Ability to lead, manage and prioritise across multiple work streams simultaneously.
  • Professional Certifications, including:
    • Certified Information Security Manager (CISM) or equivalent.
    • CISSP.
    • Certified ISO27001 implementer and or auditor.
    • Certified Information Security Auditor (CISA) is an advantage.

What We Can Offer You

With us,you will turn your aspirations into reality. We will help shape your journey through enriching experiences, learning and development opportunities and exposure to different assignments within your role or through internal mobility. Our Group offers diverse career paths for those who are extraordinary, every day.

We recognise the value that you bring, and we strive to provide a competitive benefits package which includes health care, child education contribution, remote and flexible working policies as well as exclusive employeediscounts.

We Invite All Applicants to Apply

It Takes Diversity Of Thought, Culture, Background, Differing Abilities and Perspectives to truly Inspire, Exhilarate and Delight our customers. At Chalhoub Group, we are committed to inclusion and diversity.

We welcome all applicants to apply and be part of our exciting future. We ensure equal opportunity for all our applicants without regard to gender, age, race, religion, national origin or disability status.


#J-18808-Ljbffr

  • Dubai, Dubai, United Arab Emirates CharterHouse Full time

    Job description:Charterhouse is working with a highly renowned flagship UAE organisation who is actively seeking an information Security Manager, to hire into their Dubai based office.About the roleThe information Security Manager will be expected to design & implement security processes that comply with Government policy & the appropriate regulatory...


  • Dubai, Dubai, United Arab Emirates Chalhoub Group Full time

    Manager – Information Security (Risk and Compliance) | Chalhoub Group DubaiFor over six decades, we have been a partner and creator of luxury experiences in the Middle East. The Group, in its endeavour to excel as a hybrid retailer, has reinforced its distribution and marketing services with a portfolio of eight owned brands and over 300 international...


  • Dubai, Dubai, United Arab Emirates Dautom Full time

    In this role you will have the opportunity to work closely with one of our esteemed clients known for its commitment to quality and innovation. They have chosen Dautom as their trusted partner for their upcoming projects.Job Title:Senior Information Security ConsultantMAIN DUTIES AND RESPONSIBILITIES:Monitoring various IT & Information security tools such as...


  • Dubai, Dubai, United Arab Emirates Majid Al Futtaim Full time

    Majid Al Futtaim invites you to join us in our quest to create great moments for everyone, everyday We are the leading shopping mall, residential communities, retail and leisure pioneer across the Middle East, Africa and Asia, serving over 560 million visitors a year. For the past two decades, we have shaped the consumer landscape across the region,...


  • Dubai, Dubai, United Arab Emirates Al Rostamani Group Full time

    Senior Engineer – Information Security Jobs in DubaiFor More Top Organization JobsClick HereDescription:This position will have primary responsibility for security platforms in the production environment, as well as development, quality-assurance and staging environmentsJob Responsibilities:Planning, implementing, managing, monitoring and upgrading...


  • Dubai, Dubai, United Arab Emirates Nair System Full time

    Nair Systems is currently looking for Information Security - Manager (Operations) for UAEProfessional / Technical Qualifications / Diplomas: Education Level Required: Bachelor's degree in computer science, Network/ Cyber Security or related information technology field. Professional / Technical Qualifications / Diplomas:Platform specific (e.g., SIEM/...


  • Dubai, Dubai, United Arab Emirates SEER SOLUTIONS DMCC Full time

    Job Type: Full-TimeWhat We're Looking For: Are you a highly skilled Information Security Manager looking for an exciting new challenge?_Our team is on the hunt for someone like you As our Information Security Manager, you'll be at the forefront of our organisation's security program. From developing and managing security policies to overseeing incident...


  • Dubai, Dubai, United Arab Emirates Aramex Full time

    Information Security Senior Leader Jobs In Dubai UAE | AramexFor More Top Organization Jobs Click HereSenior information security specialist is responsible for creating security measures to protect an organization's computer system and network. As a senior information security analyst, you should understand how the information security of your organization...


  • Dubai, Dubai, United Arab Emirates Gulf Career Hunt Full time

    Hiring Manager Information Security (Airline domain Must)Experience: 10+ YearsLocation: DubaiJob Type: 12 Months ContractNotice Period: 0 to 30 DaysSkillset Required: Proven experience in information security management, including policy development, risk assessment, incident response, and security awareness training. In-depth knowledge of security...


  • Dubai, Dubai, United Arab Emirates Gulf Career Hunt Full time

    Hiring Manager Information Security (Airline domain Must)Experience: 10+ YearsLocation: DubaiJob Type: 12 Months ContractNotice Period: 0 to 30 DaysSkillset Required: Proven experience in information security management, including policy development, risk assessment, incident response, and security awareness training. In-depth knowledge of security...


  • Dubai, Dubai, United Arab Emirates CHALHOUB Group Full time

    Implement risk management processes and capability to enable continuous monitoring of control effectiveness and key risk indicators.Identify, assess, and prioritize security risks associated with the group's Information assets, systems, and services.Develop and implement security risk mitigation strategies and control measures to protect critical assets and...


  • Dubai, Dubai, United Arab Emirates Intesa San Paolo Full time

    Intesa Sanpaolo is the banking group leader in Italy. Assisting more than 14,6 milion of retail customers through a network of 5360 branches, it significantly supports the development of Companies and gives an important sustain to the country's growth. The Group has a selected retail banking presence in Central and Eastern Europe, the Middle East and North...


  • Dubai, Dubai, United Arab Emirates CHALHOUB Group Full time

    Manager - Information Security Risk and Compliance Manager - Information Security Risk and ComplianceImplement risk management processes and capability to enable continuous monitoring of control effectiveness and key risk indicators.Identify, assess, and prioritize security risks associated with the group's Information assets, systems, and services.Develop...

  • Security Manager

    1 week ago


    Dubai, Dubai, United Arab Emirates Ratel Security Services Full time

    Ø MaleØ Driving License: Advantage (Not Mandatory)Ø Qualifications: Appropriate Qualification / certifications.Ø Work experience: UAE (Min - 5 yrs.) Bachelor's degree in Security Management, Criminal Justice, or a related field.Proven experience in security management or a similar role. Knowledge of security protocols, risk management, and emergency...


  • Dubai, Dubai, United Arab Emirates VAM Systems Full time

    We are currently looking for Information Security Manager for UAEProfessional / Technical Qualifications / Diplomas: Education Level Required: Bachelor's degree in computer science, Network/ Cyber Security or related information technology field. Professional / Technical Qualifications / Diplomas:Platform specific (e.g., SIEM/ Networking/ Operating System)...


  • Dubai, Dubai, United Arab Emirates VAM Systems Full time

    We are currently looking for Information Security - Manager for our UAE operations with the followingExperience:5- 10 years' experience in Information Security or related field.Skills Required for the Job: Indepth knowledge and understanding of information security and technology infrastructure. Indepth experiences in NESA requirements Implementation Indepth...

  • Security Manager

    1 week ago


    Dubai, Dubai, United Arab Emirates Al Safowan Security & Cleaning LLC Full time

    Key Responsibilities: Develop and implement security policies and procedures to ensure that all security operations are carried out effectively and efficiently Supervise and manage a team of security personnel, ensuring that they are trained to handle a range of situations and equipped with the latest technology Coordinate with clients to understand their...


  • Dubai, Dubai, United Arab Emirates MetLife Full time

    Metlife, Inc ("Metlife") has helped generations of people around the world protect their families and finances. We are one of the world's leading financial services companies, providing insurance, annuities, employee benefits, and asset management to our individual and institutional customers.Role Value Proposition:The Senior Consultant Information Security...

  • Security Manager

    1 week ago


    Dubai, Dubai, United Arab Emirates Skaka Security Full time

    Responsibilities Develop and implement security policies, protocols and procedures. Control budgets for security operations and monitor expenses. Hiring and onboarding new security guards Sets the Security Guards & staffing schedule Creating all security policies and procedures Conducts regular security inspection. Recruit, train and supervise security...


  • Dubai, Dubai, United Arab Emirates Dubai Careers – A Smart Dubai Initiative Full time

    1- Chief Information Security SpecialistAdvertiser: Department of FinanceJob: Full TimeLocation: Dubai, UAEJob Responsibilities:Planning, implementing and following up the requirements of the information security management program to ensure their compliance with the information security work policies and procedures approved at the government and department...