Talentmate
United Arab Emirates
29th January 2026
2601-23442-1
Role Overview
The Senior Security and Compliance Officer will lead the end-to-end implementation and oversight of the organizations information security governance, risk management, and compliance (GRC) initiatives.
The role is dedicated to ensuring alignment with global standards and regional regulatory frameworks within a highly regulated environment.
Key Responsibilities
Governance & Compliance
• Manage full lifecycle compliance with ISO/IEC 27001, PCI DSS v4.0.1, NIST, UAE PDPL, UAE Central
Bank regulations, and other applicable laws.
• Develop, review, and maintain information security policies, procedures, and governance documents.
• Serve as the single point of contact for InfoSec compliance.
Risk Management
• Lead technology and information security risk assessments across all domains.
• Maintain centralized risk registers with clear ownership, treatment plans, and traceability.
• Provide regular risk posture reports and validate remediation effectiveness.
Audit & Regulatory Oversight
• Plan and manage audits, inspections, regulatory assessments, and certifications.
• Coordinate internal and external stakeholder responses and ensure closure of findings.
PCI DSS v4.0.1 Compliance
• Own PCI DSS compliance program, including scoping, assessment coordination, remediation, and
documentation management.
• Track scope-impacting changes in systems or vendors.
Awareness & Training
• Design and manage induction and awareness programs via LMS platforms.
• Automate training lifecycle and track compliance for audit readiness.
Vendor & Third-Party Risk
• Perform third-party risk assessments and ensure contractual compliance with InfoSec, PCI DSS, and CPR requirements.
Continuous Improvement
• Monitor regulatory changes and drive maturity improvements across GRC processes and tooling.
Qualifications & Experience
• Education: Bachelor’s in InfoSec, Computer Science, Risk Management, or related fields.
• Experience: 8+ years in Information Security GRC roles, preferably in banking, fintech, or regulated sectors.
• Certifications (Preferred): CISSP, CISM, CRISC, ISO 27001 LA/LI, PCI DSS.
Core Skills
• Deep understanding of information security frameworks and risk governance.
• Strong documentation, analytical, and stakeholder engagement capabilities.
• Ability to operate independently with strategic thinking and execution.
Success Metrics
• Sustained PCI DSS and regulatory compliance.
• Timely risk remediation and validated risk closures.
• Strong audit performance and visibility of risk posture improvements.
| Role Level: | Mid-Level | Work Type: | Full-Time |
|---|---|---|---|
| Country: | United Arab Emirates | City: | Dubai |
| Company Website: | https://cybranytech.com/ | Job Function: | Information Technology (IT) |
| Company Industry/ Sector: |
IT Services and IT Consulting | ||
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.