Information Security Manager - 1 Year Contract
Hays- Posted 3 hours ago
- Be among the first 10 applicants
Job Description
Our client, a leading organization within the Banking sector, is seeking an experienced Information Security Manager – Governance to support and lead Information Security Governance, Risk, Compliance, and Regulatory Security initiatives.
Reporting to the Head of Information Security, the successful candidate will be responsible for establishing and maintaining information security governance frameworks, managing security and compliance projects, ensuring alignment with regulatory requirements, and supporting key banking and technology initiatives.
Key Responsibilities
- Manage end-to-end Information Security and Compliance projects, including:
- UAE IA (NESA) Assessments
- PCI DSS Compliance
- SWIFT Customer Security Programme (CSP)
- Vulnerability Assessment & Penetration Testing (VAPT)
- Regulatory and Security Assessments
- Develop, maintain, and improve Information Security:
- Policies
- Standards
- Procedures
- Guidelines
- Governance Frameworks
- Conduct and oversee security risk assessments, risk registers, risk treatment plans, risk acceptance processes, and exception management activities.
- Act as the Information Security Lead for:
- Cloud Transformation Projects
- Infrastructure Initiatives
- Application Implementations
- Digital Transformation Programmes
- Enterprise Technology Projects
- Review project proposals and business requirements from an Information Security and Risk Management perspective.
- Ensure Information Security requirements are integrated throughout the project lifecycle, including planning, design, implementation, testing, and go-live phases.
- Validate and manage remediation activities arising from:
- Internal Audits
- External Audits
- Regulatory Assessments
- Security Reviews
- Track security and compliance findings through to validated closure.
- Ensure security controls are aligned with regulatory and compliance requirements.
- Monitor compliance with applicable information security regulations, standards, and contractual obligations.
- Develop and manage third-party security assessment and due diligence processes.
- Coordinate with IT, Business, Compliance, Audit, Risk Management, PMO teams, and external stakeholders on security-related initiatives.
- Support security awareness programs and promote a strong security culture across the organization.
Mandatory Requirements
Experience
- 10-12 years of Information Security / Cyber Security experience.
- Strong Information Security experience within the Banking or Financial Services sector.
- Experience operating at Manager level with ownership of security governance and compliance initiatives.
Technical & Functional Expertise
- Strong Information Security Governance (GRC) experience covering:
- Policies and Standards
- Compliance Management
- Risk Assessments
- Risk Registers
- Risk Acceptance & Exception Management
- Security Governance Frameworks
- Hands-on experience with UAE IA (NESA) including:
- Implementation
- Assessments
- Gap Analysis
- Policy and Control Alignment
- Demonstrated experience managing:
- PCI DSS
- SWIFT CSP
- VAPT Programmes
- Regulatory Assessments
- Security Compliance Initiatives
- Proven track record managing audit and regulatory findings through remediation and validated closure.
- Experience serving as the Information Security lead for major:
- Technology Projects
- Digital Transformation Initiatives
- Cloud Projects
- Infrastructure Deployments
- Application Delivery Programmes
- Ability to manage multiple security and regulatory projects simultaneously while engaging with cross-functional stakeholders.
Education
- Bachelor's Degree in Information Security, Cyber Security, Computer Science, Information Technology, or a related discipline.
Preferred Certifications
One or more of the following certifications are highly preferred:
- CISSP
- CISM
- CRISC
- CISA
Key Skills
- Information Security Governance
- Cyber Security Risk Management
- UAE IA (NESA)
- PCI DSS
- SWIFT CSP
- Vulnerability Management
- Regulatory Compliance
- Information Security Policies & Standards
- Audit & Assessment Management
- Third-Party Risk Management
- Security Framework Implementation
- Project & Stakeholder Management
- Banking Security Controls
More Info
Key Skills
UAE IA NESA
Security Framework Implementation
Third-Party Risk Management
SWIFT CSP
Banking Security Controls
Information Security Policies
Audit Assessment Management
Project Stakeholder Management
Cyber Security Risk Management
