Senior Associate Information Security- Emirati

منذ 3 أيام

Sharjah city, Sharjah, الإمارات العربية المتحدة FISHER HUMAN RESOURCES CONSULTANCIES L.L.C دوام كامل
We are seeking Associate Information Security who manages and monitors the organization s information security framework ensuring compliance with internal policies regulatory standards and industry best practices The role supports enterprise security data governance risk management and business continuity initiatives conducts security assessments and risk reviews monitors cybersecurity controls and KPIs and identifies and mitigates security risks across systems vendorsContribute to the development implementation and continuous enhancement of the organization s information security governance framework standards and operating procedures Assess the effectiveness of security controls and recommend improvements to strengthen the overall cybersecurity posture across technology environments and third-party engagements Perform regular security reviews control assessments and compliance evaluations to identify risks vulnerabilities and opportunities for improvement Support the governance and oversight of information security initiatives ensuring alignment with organizational objectives and regulatory expectations Review security configurations user privileges network controls and infrastructure settings to verify compliance with security best practices and identify potential weaknesses Establish and monitor security performance indicators and risk metrics providing meaningful reporting to support informed decision-making Participate in technology initiatives and transformation programs by performing security reviews identifying potential risks and recommending practical mitigation strategies throughout the project lifecycle Develop maintain and periodically test cybersecurity incident response capabilities to ensure effective preparation response and recovery from security events Support compliance activities related to information security data protection and regulatory obligations including internal and external audit engagements Monitor the effectiveness of cybersecurity platforms and privileged access controls while supporting the implementation of new security technologies and continuous improvement initiatives Review business resilience disaster recovery and continuity arrangements to ensure appropriate planning testing and operational readiness Work closely with risk management and assurance functions to identify emerging cyber risks evaluate their impact and support the implementation of effective mitigation measures Evaluate security-related operational processes and internal controls recommending enhancements to reduce exposure to cyber threats data compromise and operational risk Maintain risk documentation and follow up on mitigation plans ensuring identified actions are tracked monitored and completed within agreed timelines Support enterprise risk data governance and fraud prevention initiatives by promoting consistent implementation of security and governance controls across the organization Deliver cybersecurity awareness sessions and promote a security-first culture through ongoing education and engagement initiatives Assist with maintaining compliance against recognized industry standards and regulatory frameworks coordinating assessments certifications and remediation activities where required Stay up to date with emerging cybersecurity threats new technologies and industry best practices and recommend improvements to strengthen the organization s overall security postureEducation & SkillsBachelor's degree in a related fieldMaster's or specialization in Computer Science, Engineering, or IT (Preferred)Professional cybersecurity certification (e.g., CISSP, CCSP, CISM)Proficient in EnglishExperience & Knowledge3-5 years of hands-on experience in Information Security GRC, including architecture, review, and deployment of next-generation firewalls, WAFs, DLP, PAM, IAM solutions3+ years implementing ISO standards, NIST frameworks, CIS benchmarking, and developing KPIs/KRIsExperience with enterprise-level integrations, DevSecOps lifecycle, and Cloud platforms (Azure, AWS, GCP), API management, and microservices architectureAbility to align information security strategies with technical projects and mitigate risks for digital transformation initiativesAbilities & Specific RequirementsMust be Emirati with Family BookAble to manage multiple priorities under pressure and meet deadlinesWorks effectively and responsibly without supervisionCan execute clear strategies and corporate requirementsAdaptable to start-up or fast-paced environments; flexible and agile thinker (Preferred)Applies a structured, analytical approach to challengesDemonstrates critical thinking and problem-solving capabilities