Information Security Risk Manager
Dubai
We are looking for an experienced Information & Cybersecurity Risk Manager to lead the design, governance and ongoing development of an enterprise-wide cyber-risk management framework.
This is a senior leadership position for someone who can move an organisation beyond traditional compliance-led GRC towards proactive, business-owned and data-driven cyber-risk management.
What you'll do
- Lead and evolve the organisation's information and cybersecurity risk-management framework.
- Establish consistent risk methodologies, governance and reporting across a complex global business.
- Drive accountability for information risk within business and technology teams.
- Lead cyber-risk governance forums and provide clear, board-ready reporting on key risks, treatment plans and exposure.
- Ensure material residual risks are appropriately escalated, formally accepted and tracked.
- Prioritise and coordinate risk assessments across critical technology environments, business processes, major programmes and third parties.
- Introduce and mature quantitative risk practices, including probabilistic assessment, risk simulation and loss modelling.
- Partner with Enterprise Risk, Internal Audit, Privacy, Safety and senior technology stakeholders.
- Support the assessment and management of emerging risks, including AI and agentic AI.
- Lead targeted cyber-awareness and behavioural-change initiatives.
- Develop and upskill a high-performing cyber-risk function.
What we're looking for
- 10+ years experience across cybersecurity, information security, technology risk or GRC.
- Proven experience leading enterprise-wide cyber or information-risk programmes within a large, complex organisation.
- Strong executive and board-level stakeholder management, with the ability to translate cyber risk into commercial and operational impact.
- Genuine experience with cyber-risk quantification, data-led risk analysis or advanced risk modelling.
- Strong knowledge of global cybersecurity, privacy and data-protection regulations.
- Experience assessing risks across cloud, technology transformation, third parties and enterprise business processes.
- CRISC certification is essential.
- CISM, CISA or equivalent certifications are highly desirable.
- Previous people-leadership and risk-function development experience.
- Background in aviation, transport, financial services, government, consulting or another highly regulated environment would be advantageous.