Chief Information Security Officer (CISO)
myZoi | Financial Inclusion Technologies
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- منذ 3 ساعات
- Work mode
- In office
- Education
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related discipline
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
As the Chief Information Security Officer, you will lead the cybersecurity and information security efforts of the organization, guaranteeing the confidentiality, integrity, and availability of data assets within a regulated financial services setting. You'll be responsible for crafting and executing the security strategy, managing cyber risks within board-approved limits, and ensuring compliance in a cloud-native payment and stored value facility environment.
You will provide independent advisory and escalation authority regarding security risks to senior leadership including the CTO, CEO, and Board Risk Committee. The role operates within a defined annual security budget, where expenditures require justifiable cost-benefit analysis and prioritization.
Primary Responsibilities
- Develop and maintain a long-term cybersecurity strategy that aligns with business goals, risk tolerance, and regulatory mandates.
- Set up and regularly update the information security policies, ensuring annual reviews.
- Oversee the cyber risk register and manage the security maturity roadmap using frameworks such as NIST CSF, CIS Controls, or ISO 27001.
- Administer the security risk acceptance and exception registers.
- Provide security leadership to executive management and external regulators.
- Lead the enterprise vulnerability management program including scanning, prioritizing risks, and enforcing remediation SLAs.
- Manage penetration testing initiatives ensuring timely remediation and retesting.
- Keep threat intelligence current and applicable to financial services and payments, translating insights into improved detection and controls.
- Supervise security monitoring, detection, and response functions including SIEM, EDR/XDR, and SOC (internal or MSSP).
- Handle end-to-end incident response: update and test procedures, lead containment and recovery actions, and coordinate regulatory notifications.
- Maintain identity and access management, including RBAC, privileged access, onboarding/offboarding controls, and access reviews.
- Implement data loss prevention and data classification policies across all systems.
- Ensure operational compliance with PCI DSS, CBUAE technology and information security requirements, UAE Information Assurance standards, and payment schemes.
- Act as the principal security contact for external auditors, QSAs, and regulators.
- Maintain audit-ready and tested security controls, and manage closure of audit findings on schedule.
- Implement security controls supporting UAE PDPL and cross-border data regulations in partnership with Legal and Data Protection teams.
- Support privacy impact assessments and data breach investigations and reporting.
- Provide security guidance for system designs, changes, new projects, and approve security architecture standards.
- Promote security-by-design practices within the engineering lifecycle including secure SDLC, code reviews, dependency scanning, secrets management, and CI/CD controls.
- Maintain cloud security best practices for AWS environments.
- Incorporate cyber threat scenarios into business continuity and disaster recovery plans and tests.
- Validate backup integrity, immutability, and recovery capabilities against destructive threats.
- Assess security posture of third-party vendors and outsourced providers based on risk level.
- Define security requirements in vendor contracts with Legal and Procurement teams.
- Manage security service providers per agreed service levels.
- Lead recruitment, development, and management of the security team.
- Drive security awareness through training and phishing simulation exercises.
- Promote a positive security culture encouraging safe risk reporting and escalation.
- Provide monthly security updates to the CTO and quarterly risk briefings to the Board Risk Committee.
- Immediately notify CTO, CEO, and Chief Risk Officer of significant security incidents.
Required Experience and Qualifications
- Over 10 years of growing experience in information security, including at least 5 years in leadership roles.
- Background in regulated financial services sectors such as banking, payments, fintech, or stored value facilities.
- Practical knowledge of the PCI DSS compliance process in payment environments.
- Proven leadership in managing incident response during active security events.
- Experience overseeing SOC operations, including SIEM, EDR/XDR, and threat intelligence.
- Strong expertise with cloud security, especially AWS, container/Kubernetes security, and API security.
- Familiarity with regulatory frameworks including CBUAE technology and information security circulars and UAE Information Assurance standards.
- Capability to effectively communicate security risks to executive and board audiences.
- Experience managing third-party security vendors and security service providers.
- Track record of building and mentoring security teams.
- Ability to deliver security risk reductions while optimizing constrained budgets.
Leadership and Interpersonal Skills
- Strong strategic mindset capable of translating risk concepts into business language.
- Influential without direct authority across engineering, product, and business teams.
- Clear and calm communication skills for briefing executives and regulators, even under pressure.
- Collaborative approach working across technical and governance functions.
- Comfortable working in fast-moving, scaling organizations with shifting priorities.
Educational Background and Certifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field, or equivalent professional experience.
- Essential certifications include CISSP, CISM, CISA, or ISO 27001 Lead Auditor.
- Additional advantageous certifications: PCIP, OSCP, CCSK, CRISC, AWS Security Specialty.
Technical Environment
The current technology stack includes AWS (Lambda, ECS, EKS, RDS, CloudFront, WAF), Kubernetes, Kafka, PostgreSQL, Java/Spring Boot, React, React Native, Datadog, Microsoft 365/Entra ID, and Terraform.
Additional Terms and Conditions
- Participation in an on-call rotation for security incident escalation.
- Must be available outside normal working hours during critical incidents or major changes.
- Appointment is contingent upon passing an enhanced background check appropriate for regulated financial services control roles.
Level
Head
Minimum education
Bachelor's Degree