dubai, dubai emirate, United Arab Emirates Unknown Posted 5 days ago
$250,000 – $450,000
Strategy
Define the enterprise security architecture and control baseline across the SDLC to reflect risk-management objectives, embedding security requirements in high-level designs and incorporating threat-modelling outcomes.
Establish and maintain corporate information-security policies, standards, guidelines, and ISMS design patterns aligned to regulations and best practices, ensuring designs meet cloud and on-premises security baselines.
Maintain risk-driven reference architectures and response scenarios; perform technology-riskassessments early in initiatives, highlight design-related risks/changes, and propose compensating controls.
Set Authority security programs and technical standards with Enterprise Architecture; ensure projects align to architectural requirements through early design signoffs with business/technology stakeholders.
Evaluate emerging security technologies and trends; research solutions for mandated requirements and recommend adoption paths aligned to RTA strategy and architecture.
Represent Information Security in enterprise architecture boards and technical steering committees to embed security perspectives in portfolio decisions.
Operations
Provide specialist security input to RFPs; define and review security requirements and compliance language.
Evaluate and approve changes per ITIL; improve change-management procedures and perform post-implementation audits.
Lead architectural reviews for all new digital initiatives and ensure security by design across solutions and platforms.
Define and govern secure integration patterns for third-party systems and APIs and ensure adherence during design and change.
Coordinate with the Security Operations Center on incident analysis and response, applying lessons to strengthen architectural controls.
Lead/advise on IAM, SSO, classification, DLP, SIEM and related platform architectures; verify configuration hardening.
Conduct and guide security assessments and vulnerability analysis; recommend and oversee mitigation actions.
Coordinate information-systems audits with stakeholders to assess control effectiveness and drive remediation.
Product/Process Improvement
Develop and update security-architecture practices and standards, document target states,gaps, and migration roadmaps.
Develop and maintain security policies, SOPs, and architecture documentation; report compliance metrics and audit artifacts; supervise and refine security training.
Job Qualifications & Requirements
Education
Bachelor's degree/ Master’s degree in Computer Science (CS)/ Information Technology (IT)/ Cybersecurity or related.
Experience
6+ Years in case of Master’s degree (8+ years in case of Bachelor’s degree)
Qualification
Certifications such as Certified Information Systems Security Professional (CISSP), SABSA