Head of Information Security

Legal and Compliance

United Arab Emirates
Posted on 3 weeks ago

Head of Information Security - RAK
Requirements:
12+ years in IT, including 8+ years in Information Security and 4+ years in a senior/managerial role leading security teams and cross-functional security initiatives.Mandatory certification: CISSP, OSCE3, or GSE (or equivalent proven hands-on expertise).Preferred certifications: OSCP (strongly preferred), GCIA, GCIH, GCFE, GCFA, CISM, ISO 27001/22301 Lead Implementer or Auditor.Security Architecture: Demonstrated ability to design and technically evaluate enterprise security architectures across hybrid and multi-cloud environments. Experience with zero-trust network design, SSE/SASE frameworks, API security, PKI, and encryption architectureThe ideal candidate should have strong expertise in Security Architecture, including designing and assessing enterprise security solutions across hybrid and multi-cloud environments, with hands-on experience in Zero Trust, SSE/SASE, API security, PKI, and encryption.Deep knowledge of Identity and Access Management, including Active Directory hardening, privileged access governance, PAM solutions, Entra ID, and cloud IAM, is essential. Proven experience leading SOC operations, managing SIEM platforms, EDR solutions, threat detection, and incident response programs is required.The candidate should be capable of handling the full incident response lifecycle, including forensic investigations, stakeholder communications, and regulatory reporting. Experience in Vulnerability Assessment, Penetration Testing (VAPT), threat hunting, DFIR, and compromise assessments is expected.Strong understanding of Information Security Governance, ISO 27001 and ISO 22301 frameworks, risk management, vendor security, and business continuity planning is required. Knowledge of OT/ICS security and operational infrastructure environments is advantageous. Hands-on experience with technologies such as Palo Alto, Zscaler, F5 WAF, Microsoft Defender, Sentinel, QRadar, Splunk, CyberArk, Entra ID, SAP security, and vulnerability management platforms is highly desirable.Knowledge or certification in IEC 62443 is an advantage for OT security.

Apply Now