Specialist- Information Security GRC at Flydubai
Dubai, , United Arab Emirates -
Full Time


Start Date

Immediate

Expiry Date

22 Oct, 25

Salary

0.0

Posted On

23 Jul, 25

Experience

3 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Risk, Information Technology, Mitigation, Aviation, Iso, Business Units, Regulatory Requirements, English, Security Metrics, Information Security Governance, Grc, Isr, Information Security, Nist

Industry

Financial Services

Description

MAIN OBJECTIVE OF ROLE: To support the organization’s cybersecurity governance, risk management, and compliance activities by coordinating and executing Governance, Risk, and Compliance (GRC) processes to ensure alignment with regulatory requirements, industry standards, and internal policies, ultimately strengthening the organization’s security posture. KEY RESPONSIBILITIES:

  • Develops, implements, and maintains information security governance frameworks, policies, and procedures.
  • Conducts risk assessments and facilitate risk management activities, including identification, evaluation, and mitigation of security risks.
  • Supports compliance efforts with relevant regulations and standards such as DESC ISR, ISO 27001, NIST, GDPR, PCI-DSS, and others.
  • Manages and coordinates internal and external audits related to information security and compliance.
  • Maintains the organization’s risk register and track remediation plans to closure.
  • Collaborates with IT, legal, and business units to embed GRC best practices across the organization.
  • Prepares and presents risk and compliance reports for senior management and key stakeholders.
  • Facilitates training and awareness programs to promote understanding of information security policies and compliance requirements.
  • Supports the assessment, monitoring, and mitigation of vendor and third-party risks to ensure compliance with organizational policies and regulatory requirements.
  • Monitors emerging regulations, standards, and industry trends related to cybersecurity governance and compliance.
  • Coordinates and documents business impact assessments (BIAs) and support the development of security risk treatment plans.
  • Participates in the design and implementation of security metrics and KPIs to measure compliance and control effectiveness.
  • Assists in the evaluation and implementation of GRC tools and automation solutions.

QUALIFICATIONS:

  • Bachelor’s Degree (3+ years)
  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, or a related field
  • Fluent in English
  • Minimum of 7 years experience in information security governance, risk management, and compliance, preferably in regulated industries such as aviation or banking. Proven skills in risk assessments, audit support, policy implementation, and hands-on third-party risk management. Familiarity with standards such as DESC ISR, ISO 27001, NIST, and GDPR is essential.
  • Years with qualifications: 7 - 9 years
  • Relevant certifications preferred (e.g., CISM, CRISC, CISA, CISSP)
Responsibilities
  • Develops, implements, and maintains information security governance frameworks, policies, and procedures.
  • Conducts risk assessments and facilitate risk management activities, including identification, evaluation, and mitigation of security risks.
  • Supports compliance efforts with relevant regulations and standards such as DESC ISR, ISO 27001, NIST, GDPR, PCI-DSS, and others.
  • Manages and coordinates internal and external audits related to information security and compliance.
  • Maintains the organization’s risk register and track remediation plans to closure.
  • Collaborates with IT, legal, and business units to embed GRC best practices across the organization.
  • Prepares and presents risk and compliance reports for senior management and key stakeholders.
  • Facilitates training and awareness programs to promote understanding of information security policies and compliance requirements.
  • Supports the assessment, monitoring, and mitigation of vendor and third-party risks to ensure compliance with organizational policies and regulatory requirements.
  • Monitors emerging regulations, standards, and industry trends related to cybersecurity governance and compliance.
  • Coordinates and documents business impact assessments (BIAs) and support the development of security risk treatment plans.
  • Participates in the design and implementation of security metrics and KPIs to measure compliance and control effectiveness.
  • Assists in the evaluation and implementation of GRC tools and automation solutions
Loading...