Search Jobs

Search by job, company or skills

Security Compliance Officer

Security Compliance Officer

DXC Technology
  • Posted 2 hours ago
  • Be among the first 10 applicants

Job Description

Security Compliance Officer

DXC Technology | United Arab Emirates | On-site – Senior Analyst I

Function: Cyber Security – Managed Detection & Response

DXC Technology is seeking an experienced Security Compliance Officer to support cybersecurity governance, compliance, control assurance, and audit readiness within a large-scale, complex technology environment in the UAE.

The role will be responsible for monitoring compliance with cybersecurity policies, standards, regulatory requirements, and security frameworks while working closely with cybersecurity, technology, operations, risk, audit, and service delivery teams.

The successful candidate will bring practical experience translating cybersecurity requirements into measurable controls, collecting and validating evidence, identifying compliance gaps, and driving remediation through to closure.

Key Responsibilities

Cybersecurity Compliance & Control Assurance

  • Monitor compliance with established cybersecurity policies, standards, procedures, and control requirements.
  • Perform periodic security control assessments and compliance reviews across technology and cybersecurity environments.
  • Assess the effectiveness of implemented controls and identify gaps, weaknesses, and areas requiring remediation.
  • Maintain security compliance registers, control matrices, assessment records, and supporting documentation.
  • Track identified compliance findings and remediation actions through to closure.
  • Support continuous improvement of cybersecurity governance and compliance processes.

Security Frameworks & Standards

  • Support implementation and assessment against relevant cybersecurity frameworks and standards such as ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, and applicable regulatory requirements.
  • Map internal security controls against relevant standards, contractual requirements, and security obligations.
  • Assist in maintaining policies, standards, procedures, and security control documentation.
  • Monitor changes to relevant cybersecurity requirements and support impact assessments where required.

Audit & Evidence Management

  • Coordinate cybersecurity evidence collection for internal audits, external audits, compliance assessments, and assurance reviews.
  • Validate evidence provided by technical and operational teams to ensure it adequately demonstrates control effectiveness.
  • Maintain organized and traceable compliance evidence repositories.
  • Support audit walkthroughs, control testing, interviews, and responses to auditor requests.
  • Track audit findings, observations, corrective actions, owners, and target closure dates.

Risk & Remediation Management

  • Identify and document cybersecurity compliance risks, control deficiencies, and exceptions.
  • Work with technical teams to define appropriate remediation and corrective action plans.
  • Monitor remediation progress and escalate overdue or high-risk findings.
  • Support security exception and risk acceptance processes where required.
  • Provide regular reporting on compliance status, findings, risks, and remediation progress.

Security Operations & Stakeholder Coordination

  • Work closely with SOC/MDR, SIEM, IAM/PAM, endpoint security, network security, OT/IoT security, vulnerability management, and other cybersecurity teams to validate operational security controls.
  • Coordinate with infrastructure, applications, cloud, service management, risk, and audit stakeholders.
  • Support security governance meetings and provide clear compliance status reporting.
  • Ensure security documentation and evidence remain accurate, current, and audit-ready.

Required Experience

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline.
  • 6+ years of cybersecurity governance, risk, compliance, information security, or security assurance experience.
  • Practical experience performing security compliance assessments, control testing, gap assessments, and audit support.
  • Strong understanding of cybersecurity frameworks and standards such as ISO/IEC 27001, NIST CSF, CIS Controls, or equivalent.
  • Experience managing audit evidence, compliance findings, remediation actions, and control documentation.
  • Good understanding of cybersecurity technologies and controls across areas such as SIEM/SOC, IAM/PAM, endpoint security, network security, vulnerability management, cloud security, and data protection.
  • Experience translating security requirements into practical and measurable controls.
  • Strong documentation, analytical, reporting, and stakeholder management capabilities.
  • Ability to work effectively with both technical cybersecurity teams and governance/audit stakeholders.

Preferred Experience

  • Experience supporting cybersecurity compliance within a large enterprise, SOC/MDR, managed security, or complex technology environment.
  • Knowledge of additional standards or frameworks such as ISO 27002, NIST 800-53, COBIT, PCI DSS, or relevant UAE cybersecurity requirements.
  • Experience supporting internal/external audits and formal security certification activities.
  • UAE/GCC cybersecurity or compliance experience is advantageous.
  • Certifications such as CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, CISSP, CISM, or equivalent are preferred.

What We Are Looking For

We are looking for a detail-oriented cybersecurity compliance professional who can work effectively between governance requirements and technical security operations.

The successful candidate should be comfortable reviewing security controls, challenging insufficient evidence, identifying compliance gaps, coordinating remediation, and maintaining strong audit readiness.

The ideal candidate will combine cybersecurity knowledge, control assurance, analytical thinking, strong documentation skills, and effective stakeholder management within a complex technology environment.

More Info

Key Skills

Risk remediation management

CIS Controls

Audit evidence management

Analytical reporting

Compliance control assurance

Cybersecurity governance

Gap assessments

Security compliance assessments

ISO IEC 27001

NIST Cybersecurity Framework

About Company