VP - Cybersecurity & Cyber Defense Center

7 days ago


Dubai, Dubai, United Arab Emirates Mashreq Full time
VP - Cybersecurity & Cyber Defense Center
  • This role will provide strategic thinking for CDC, with a deep understanding of cybersecurity risks, incident monitoring, detection, and response methodologies.
  • This role defines Mashreq's CERT strategy to manage a state-of-the-art CERT capability covering all global locations including UAE, Egypt, NY, UK, Qatar, India, Pakistan, etc.
  • This role provides leadership and oversight of a 24 X 7 X 365 security operations team responsible for monitoring, detection, and incident management of security incidents.
  • This role will lead a team of cybersecurity professionals who perform intrusion monitoring, detection, triage, investigation, containment, and notification as part of blue team activities.
  • This role will work with business and security leadership to build an operational threat model, services, and response capabilities globally to enhance business ability to serve and protect our customer interests.

Key Result Areas:

Strategic Leadership and Oversight:

  • Create strategic roadmap for Cyber Defense Center based on threats arising from emerging technologies.
  • Provide management and leadership for the team focused on monitoring and responding to security incidents.
  • Oversee the execution of security strategies, policies, and procedures to address complex cybersecurity challenges, ease frictions, and enhance overall collaboration with LOD-1, LOD-3, and other key stakeholders.

Operational Excellence:

  • Budgeting, demand management, and capacity planning of cyber defense operations.
  • Enhance capability uplift and maturity of SOC operations through automation and process improvement.
  • Ensure efficient and effective monitoring and response to security events received on SIEM platforms (Azure Sentinel & ArcSight preferred) from diverse sources such as FWs, IDS, IPS, AV, DAM, DLP, EDR, etc.
  • Drive improvements through threat detection, incident response, and threat hunting in overall CDC operations.
  • Enhance threat detection capabilities by leveraging Microsoft's native KQL, automation, and queries and reduce false positives.
  • Lead and drive cyber simulation and cyber drills to enhance detection and response capability of the organization.
  • Use case life cycle management including continuously enhancing/enriching the SIEM rules based on change in business requirements and threat landscape.
  • Liaise with GRC to comply with central bank submission requirements/timelines including that of regional regulatory authorities.
  • Represent and lead CDC organization while preparing and participating in internal and external audits.
  • Effectively manage security incidents, involving relevant stakeholders during crisis management situations.

Team Management and Development:

  • Mentor and develop the CDC team, fostering a culture of continuous improvement and high performance.
  • Manage the recruitment, training, and performance evaluation of team members, including direct and indirect reports.
  • Governance and oversight of vendor performance including tracking of SLA metrics and operational metrics.

Strategic Collaboration & Communication:

  • Collaborate with senior leadership across business groups including technology compliance, audit, and regulatory teams to ensure alignment with security requirements.
  • Actively participate and contribute to business engagement meetings including that of relevant business-specific updates from CDC's standpoint.
  • Effectively communicate security posture and CDC metrics.
  • Represent the CDC in strategic discussions and coordinate with external stakeholders as necessary.

Process and Policy Enhancement:

  • Oversee the design, implementation, and updating of security processes, policies, and procedures (SOPs, playbooks, runbooks) with a focus on best practices and regulatory compliance.
  • Ensure the integration of new security technologies and the effective onboarding of new log sources.
  • Preparedness in anticipation of any adverse situations, by means of relevant playbooks and procedures for various emerging threat scenarios.
  • Able to drive tabletop exercises, conduct cyber drills, and prepare for simulations and wargaming scenarios.

Risk Management, Fraud Prevention, and Brand Reputation:

  • Manage reputation of Mashreq brand in social media against any infringement activities in collaboration with Marketing communication group and other stakeholders.
  • Develop and implement comprehensive Cyber Defense & risk management strategies to protect organizational assets and brand reputation.
  • Integrate with Offensive Security team to assess vulnerabilities, threats, and risks continuously, ensuring improvements and adaptation to emerging challenges.
  • Proactively manage and mitigate risks to maintain customer trust and uphold the institution's reputation.

Regulatory Compliance and Client Protection:

  • Ensure all cybersecurity measures comply with financial regulations such as PCI-DSS, GDPR, NESA, and local banking regulations.
  • Regularly review and update policies to remain aligned with evolving legal requirements on monitoring/sanctions, ensuring robust client protection and compliance.
  • Liaise with Data Privacy & Protection team to ensure protection of sensitive customer data through rigorous encryption, strong authentication, access control measures, and having them continuously monitored for deviation.

Incident Response, Financial Stability, and Client Confidence:

  • Establish and maintain robust incident response and disaster recovery plans tailored to financial systems.
  • Ensure swift detection, response, and mitigation of security breaches while minimizing financial loss, operational disruption, and maintaining client confidence.
  • Develop a communication strategy to transparently handle incidents, reassuring clients and preserving trust.

Customer Data Protection and Enhanced User Security:

  • Prioritize the security of customer data and financial information by implementing advanced security measures, integration, and orchestration.
  • Focus on end-to-end encryption, secure transactions, and continuous monitoring to safeguard against breaches.
  • Foster a culture of security awareness among employees to prevent social engineering and other security threats.

Stakeholder Communication, Collaboration, and Regulatory Assurance:

  • Assist cross-functional teams to integrate cybersecurity into all business processes, ensuring cohesive and comprehensive security.
  • Foster collaboration with IT, legal, HR, compliance, and customer service teams to create a unified security culture.
  • Communicate effectively about cybersecurity risks, policies, and incidents to maintain transparency, regulatory assurance, and stakeholder trust.

Knowledge, Skills, & Experience:

  • Graduate/Postgraduate degree in Science, Engineering, or IT.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent.
  • Extensive experience in managing Cyber Defense Center or Security Operations Center operations, with a strong background in overseeing large teams.
  • 10+ years of experience in incident monitoring and response (CERT & SOC), with proven leadership skills and expertise in managing complex security operations.
  • Proficiency in managing SIEM platforms, security technologies, and operational processes.
  • Strong analytical skills for evaluating security requirements and implementing appropriate controls.
  • Excellent leadership, communication, and collaboration skills.
  • Knowledge of the banking environment is advantageous.
Seniority Level

Mid-Senior level

Employment Type

Full-time

Job Function

Other

Industries

Banking and Financial Services

#J-18808-Ljbffr

  • Dubai, Dubai, United Arab Emirates Dicetek LLC Full time

    Cybersecurity Architecture& Design: Leadthe design and implementation of comprehensive securityarchitectures for both on-premises and cloudenvironments.Ensure that security solutionsalign with business objectives and comply with industrystandards. Cyber Defenseand Operations: Overseeday-to-day cybersecurity operations, including monitoring,detection, and...


  • Dubai, Dubai, United Arab Emirates Dicetek LLC Full time

    10+ years of experience as atrainer.The candidate has worked in industrynot just the academic field.HasOffensive-Defensive Cyber Security Skills.QualificationsEducation:Bachelor'sdegree in Computer Science, Information Technology, Cybersecurity,or a related field. Relevant certifications (e.g., CISSP, CISM,CEH) are aplus.Experience:Provenexperience in...


  • Dubai, Dubai, United Arab Emirates Dicetek LLC Full time

    Job Requirements10+ years of experience as a trainer.The candidate has worked in industry not just the academic field.Has Offensive-Defensive Cyber Security Skills.QualificationsEducation:Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. Relevant certifications (e.g., CISSP, CISM, CEH) are a...


  • Dubai, Dubai, United Arab Emirates Avrioc Technologies Full time

    Cyber Threat Defense Engineer is responsible for reviewing, designing, implementing, and maintaining security measures to protect cloud infrastructure from evolving threats.This role involves overseeing Network Detection and Response (NDR) to identify and mitigate threats in real-time.**Responsibilities Include:**Administer Privileged Access Management (PAM)...


  • Dubai, Dubai, United Arab Emirates Ateca Consulting Full time

    We are seeking a highly skilled professional to safeguard the integrity, confidentiality, and availability of our telecommunications networks and systems against cyber threats. As a Cybersecurity Professional at Ateca Consulting, you will be responsible for providing 24/7 customer support via our Cyber Security Operations Center.Key...

  • Cyber Trust Advisory

    4 weeks ago


    Dubai, Dubai, United Arab Emirates Help AG Full time

    Cyber Trust Advisory - Consultant - OT/IoTHelp AG Protect your business with Help AG's unmatched cybersecurity expertise and industry-leading solutions in the Middle East and Africa.Help AG is looking for a talented and experienced Cyber Trust Advisory - Consultant - OT/IoT who will be responsible for the successful delivery of consultancy tasks for projects...


  • Dubai, Dubai, United Arab Emirates Menlo Ventures Full time

    Regional Sales Director CybersecurityWe're seeking a Regional Sales Director Cybersecurity to join our team at Menlo Ventures.About the Role:This is an exciting opportunity to lead our sales efforts in the METNA region.You'll be responsible for creating and executing a sales strategy for your territory, working closely with our VP of Sales.As one of the...


  • Dubai, Dubai, United Arab Emirates Cyber Crime Full time

    Cyber CrimeWe are seeking an experienced Regional Account Manager to join our team in the UAE/Dubai. The ideal candidate will have a proven track record of success in sales and account management, with a strong understanding of cybersecurity solutions.The Regional Account Manager will be responsible for proactively building new clients and growing assigned...


  • Dubai, Dubai, United Arab Emirates Immersive Dynamics Inc. Full time

    Cyber Security Sales ProfessionalImmersive Dynamics Inc. is a leading provider of people-centric cyber resilience solutions.We are seeking an experienced Cyber Security Sales Professional to join our team in Dubai.The successful candidate will have a proven track record of selling complex software products to enterprise organizations.You will be responsible...


  • Dubai, Dubai, United Arab Emirates Parsons Oman Full time

    Key Responsibilities:Design and implement comprehensive cybersecurity strategies and frameworks tailored to the specific needs of the railway/metro project, ensuring the protection of critical infrastructure, operations, and data.Identify, assess, and mitigate potential cyber threats and vulnerabilities within the project's systems and networks. Lead cyber...


  • Dubai, Dubai, United Arab Emirates Help AG, an e& enterprise company Full time

    About Help AG: As the cybersecurity arm of e& enterprise, we provide strategic consultancy, tailored information security services, and solutions to leading enterprise businesses and governments across the Middle East. Our experts remain vendor-agnostic, trustworthy, independent, and cybersecurity focused, delivering unmatched value by strengthening our...


  • Dubai, Dubai, United Arab Emirates Immersive Dynamics Inc. Full time

    Senior Cyber Sales Specialist Middle EastImmersive Dynamics Inc. is seeking a highly experienced Senior Cyber Sales Specialist to join our team in the Middle East.As a Senior Cyber Sales Specialist, you will be responsible for developing and executing the sales strategy for the region, managing a portfolio of enterprise accounts, and driving revenue...


  • Dubai, Dubai, United Arab Emirates VAM Systems Full time

    About VAM SystemsVAM Systems is a leading provider of innovative technology solutions. We are committed to delivering exceptional results and building long-lasting relationships with our clients.We are seeking a cybersecurity expert to join our team in the UAE. The successful candidate will be responsible for protecting our computer systems and networks from...


  • Dubai, Dubai, United Arab Emirates Dicetek LLC Full time

    Job DescriptionDicetek LLC is seeking an Information Technology Security Consultant to provide expert guidance on cybersecurity matters. The ideal candidate will have extensive experience in cybersecurity and possess excellent communication and interpersonal skills.Key ResponsibilitiesAssess and mitigate cybersecurity risks across the organization.Develop...

  • Account Manager

    6 days ago


    Dubai, Dubai, United Arab Emirates Immersive Dynamics Inc. Full time

    Account Manager - Cyber Resilience SolutionsImmersive Dynamics Inc. is seeking an experienced Account Manager to join our team in the Middle East.As an Account Manager, you will be responsible for managing a portfolio of enterprise accounts, developing and executing the sales strategy for the region, and driving revenue growth.You will also build...


  • Dubai, Dubai, United Arab Emirates Parsons Oman Full time

    Job Description:Parsons Oman is seeking a highly skilled Senior Cybersecurity Engineer to join our team and play a critical role in the successful delivery of a high-profile railway/metro project in the UAE. This transformative infrastructure project will enhance urban connectivity and improve public transportation efficiency across the region.As part of...


  • Dubai, Dubai, United Arab Emirates Avrioc Technologies Full time

    Job Title: Cyber Security EngineerDepartment/ Function: Cyber Security & ResiliencyLocation: Abu Dhabi, UAEAn Overview about us:Avrioc Technologies is headquartered in Abu Dhabi, UAE, specializes in developing applications, software, games, and AI models that enhance daily experiences. Its offerings include CBUAE Licensed Fintech solution, AI-driven...


  • Dubai, Dubai, United Arab Emirates Arios21 Full time

    Technology & Cyber Security Audit ManagerJob Title: Technology & Cyber Security Audit ManagerDepartment: Internal Audit – Technology & Cybersecurity AuditReporting To: Head of Technology and Cybersecurity AuditGrade: N/ANumber of Reportees: NoneSalary range: 25000 - 33000 AED per monthJob Purpose:The Technology & Cyber Security Audit Manager leads and...


  • Dubai, Dubai, United Arab Emirates Parfums de Marly Full time

    We are seeking a highly skilled Cybersecurity Professional to lead and support the implementation of a robust cybersecurity strategy for our group of companies. This role will work collaboratively with cross-functional teams to ensure the security, availability, and integrity of systems and data, while delivering on the IT roadmap to achieve a strong cyber...


  • Dubai, Dubai, United Arab Emirates ENOC Full time

    **Principal Accountabilities**Manage communication of policies & guidelines and monitor compliance of CIC operations to cybersecurity policies & guidelines.Identify cyber threats, trends, and new developments by analyzing raw intelligence and data.Track technology field and cyber threat environment changes to address them in cybersecurity strategy plans and...