Roles and Responsibilities
Strategy
– Develop and implement information-security strategies and operating models aligned with laws, regulations, and Authority needs.
– Define the risk framework: maintain registers, scenarios, and response plans with accountable owners and escalation paths.
– Set Authority-wide security programs and technical standards across sectors to embed best practices consistently.
– Evaluate emerging technologies and threat trends and issue strategic recommendations to improve security systems and infrastructure.
– Coordinate with departments to align cybersecurity strategies and work plans with organizational objectives.
Operations
– Lead in-depth analysis of security incidents, direct incident-response activities, and strengthen digital forensics and investigation quality.
– Plan and coordinate Security Operations Centre (SOC) operations and response workflows with internal and external stakeholders.
– Support and advise team leads in the development and management of the organization’s Vulnerability Assessment and Penetration testing (VAPT) plan and building VAPT tools and frameworks
– Oversee the conduct of readiness evaluations and penetration tests; recommend preventive and corrective actions and track closure.
– Review architectures for new initiatives and system changes; prescribe security controls during design and implementation.
– Govern access and privileges: apply eligibility/approval procedures, review entitlements, monitor network/system activity, and report compliance.
– Execute risk-based audits of technical systems and projects; evaluate control effectiveness and drive corrective plans.
– Assess new technology projects for alignment with cybersecurity strategy and risk profile; provide improvement recommendations.
– Manage security assessments of external suppliers and partners and ensure compliance with required security standards.
– Execute additional Information Security duties assigned by leadership beyond the defined Section scope.
Product/Process Improvement
– Maintain risk registers and mitigation plans; analyse performance metrics and report system effectiveness and residual risks.
– Manage and update cybersecurity documentation, including policies, procedures, contingency plans, and ensure legal and regulatory compliance.
– Prepare and refine emergency/incident response and recovery plans via exercises and lessons learned.
Job Qualifications & Requirements
Education
– Bachelor’s degree/ master’s degree in computer science/ information technology
Experience
– 9+ Years in case of Master’s degree (11+ years in case of Bachelor’s degree)
Qualification
– Certifications such as Certified Information Systems Security Professional (CISSP) or, Certified Information Security Manager (CISM), ISO/IEC 27001 Lead Implementer/ Lead Auditor
Source: ae.linkedin.com

