Cybersecurity Advisory & Assurance Lead

Ghobash Group

Dubai, Dubai, United Arab Emirates Full-time 3 days ago
Workplace
On-site
Location
Dubai, Dubai, United Arab Emirates

Check your CV against this job

Free · No signup · A 0–100 ATS match score and the keywords you're missing.

Check my CV free

$14.99/month, cancel anytime. Already have an account? Log in

About the role

Job Description

The Cybersecurity Advisory & Assurance Lead is a senior, hands-on cybersecurity professional responsible for leading complex cybersecurity assessments, advisory engagements and transformation programmes for enterprise and government customers.The role independently leads comprehensive, framework-based assessments (NIST CSF, NIST SP 800-series, ISO/IEC 27001, CIS Controls and applicable UAE/GCC regulatory requirements), taking engagements from initial customer workshops and evidence collection through technical assessment, control testing, maturity evaluation, gap analysis, risk identification, target-state design, remediation planning and executive presentation.Drawing on broad expertise across defensive security, offensive security, governance, risk and compliance (GRC), security architecture and security operations, the jobholder acts as a technically credible adviser to CISOs, SOC, infrastructure, cloud and architecture teams, and senior management.

DUTIES & RESPONSIBILITIES:

* Lead enterprise-wide cybersecurity maturity and capability assessments, including NIST CSF-based current-state and target-state assessments covering governance and the Identify, Protect, Detect, Respond and Recover functions. * Conduct control design and operating-effectiveness assessments, evaluating whether technical controls are effectively implemented rather than relying solely on policy documentation. * Review cybersecurity policies, standards, procedures and operating models, and evaluate them against NIST CSF, NIST SP 800-series, ISO/IEC 27001/27002, CIS Critical Security Controls, UAE Information Assurance requirements, UAE/GCC cybersecurity regulations, PCI DSS, SWIFT CSP, cloud security frameworks and sector-specific requirements. * Assess and advise on defensive security and SOC capabilities, including SOC operating models, SIEM and security monitoring, EDR/XDR, detection engineering, threat intelligence, threat hunting, security logging, incident response, vulnerability management, IAM/PAM, network, endpoint, email and web security, ransomware resilience, cyber crisis management, and business continuity and cyber recovery. * Assess security architecture across enterprise infrastructure, cloud and hybrid environments, network, identity, endpoint, data, application security, security monitoring and, where applicable, OT/ICS environments. * Assess the effectiveness and maturity of cybersecurity processes, including asset, risk, vulnerability, patch and change management, identity lifecycle and privileged access management, security monitoring, incident response, third-party risk, secure development, threat management, security architecture governance, data protection, business continuity and cyber recovery. * Scope, challenge and interpret penetration-testing and red-team assessments; review vulnerability and penetration-testing results and assess vulnerability management and remediation processes. * Validate whether technical findings represent material business risks and work with offensive-security specialists to translate them into risk and remediation programmes, supporting purple-team and control-validation activities where required. * Conduct cybersecurity governance and cyber-risk assessments, assess governance structures and accountability, evaluate cyber-risk management methodologies, support regulatory and compliance readiness, and map controls across multiple regulatory frameworks. * Identify security gaps, risks, control weaknesses and capability deficiencies, and develop prioritised remediation roadmaps and cybersecurity improvement programmes. * Develop maturity models, heatmaps, risk registers and management dashboards, and produce executive, management and detailed technical assessment reports. * Present findings and recommendations to CISOs, CIOs, executives and governance committees, translating highly technical issues into business-risk language and practical remediation recommendations. * Lead customer workshops and stakeholder interviews; define assessment methodologies and evidence requirements, and maintain evidence traceability between findings and conclusions. * Manage assessment workstreams and guide junior consultants, challenging customer assumptions professionally and constructively. * Support proposals, RFP responses, statements of work and customer presentations, and assist Account Managers in identifying follow-on cybersecurity opportunities.

Qualifications

Education

Required:

* Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems or Engineering (Electronics, Computer or Telecom).

Desirable:

* Master's degree such as an MSc in Cybersecurity or Information Security, or an MBA with a technology focus. For a lead role this is a plus, not usually a must. * Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, CISA, CCSP, GIAC or NIST-related training/certification * Technical/offensive certifications such as OSCP, PNPT or CEH (or equivalent practical experience)

Experience

Required:

* 8 years of cybersecurity experience spanning multiple disciplines * Demonstrable experience leading enterprise cybersecurity assessments * Experience conducting stakeholder interviews and evidence-based assessments * Experience producing executive-level reports and presenting to senior customer stakeholders

Desirable:

* 12+ years of cybersecurity experience * Experience in government, critical infrastructure, financial services, aviation, energy or other highly regulated sectors

Additional Information

Skills & Abilities

Required:

* Strong practical knowledge of NIST CSF, ISO 27001 and cybersecurity control frameworks * Strong understanding of SOC/security operations, security architecture and enterprise controls * Working knowledge of offensive-security methodology * Understanding of major cybersecurity technology categories * Excellent report writing, workshop facilitation and executive communication * Ability to work independently and move between technical, operational and governance discussions

Desirable:

* Knowledge of UAE Information Assurance and GCC cybersecurity regulations * Experience with PCI DSS, SWIFT CSP and cloud security frameworks * Exposure to OT/ICS security assessments

Compliance with policies and procedures based on the ISO standards adopted by CNS.

Get matched & apply with FindAJobAI

Upload your resume once. We score every job against your profile, tailor your resume and cover letter, and autofill the application.