On-site Full Time
--
Dubai Government Human Resource Department

Job Details

Job description

Job Purpose:


The responsibility of this role is to support the development and implementation of the Information Security Governance Framework at the Dubai Government Human Resources Department (DGHR), ensuring the confidentiality, integrity, and availability of information assets. This includes monitoring compliance with regulatory information security policies, standards, and requirements, conducting security assessments, managing cybersecurity risks, and supporting cybersecurity initiatives to protect the entity from internal and external threats.


Duties and Responsibilities:


·Support the implementation and monitoring of the Information Security Management System (ISMS) and Business Continuity Management System (BCMS).


·Ensure compliance with Dubai Information Security Regulation (ISR), ISO 27001, ISO 22301 standards, and the entity's security policies, standards, and procedures.


·Periodically review and update information security and business continuity policies, standards, guidelines, and procedures.


·Monitor compliance with information security requirements and controls across various departments, recommending necessary corrective and improvement actions to address non-compliance.


·Contribute to developing and applying information security governance frameworks and control measures to ensure enhanced information security and risk management.


·Contribute to planning, developing, and following up on the ISMS and BCMS risk assessment methodology entity-wide, ensuring alignment with corporate goals and senior management requirements.


·Ensure the selection and application of appropriate administrative, operational, and technical controls for ISMS and BCMS in line with risk assessment results and approved compliance requirements.


·Identify potential security risks and vulnerabilities, recommending appropriate measures and controls to mitigate risks and enhance the cybersecurity posture.


·Evaluate the effectiveness of applied security controls and measure their contribution to mitigating risks and enhancing the cybersecurity posture.


·Monitor and implement controls and requirements for ISO 27001 and ISO 22301 standards, NCEMA requirements, and others.


·Participate in or supervise internal audits for ISMS and BCMS, and follow up on the implementation of resulting corrective actions.


·Coordinate with certification bodies, internal, and external auditors, and represent the entity's management during audits related to ISR, ISMS, BCMS, and follow-up audits, ensuring adherence to approved requirements and standards.


·Track audit findings, observations, and corrective action plans until closure.


·Collect, review, and maintain audit evidence and compliance documentation.


·Coordinate with process owners to measure and monitor the performance of ISMS and BCMS.


·Present and discuss all non-conformities and audit reports with the Information Security Committee, following up on recommendations and corrective actions required to resolve observations.


·Coordinate with external entities to execute and follow up on technical security assessment requirements and controls, including Vulnerability Assessment and Penetration Testing (VAPT), business continuity tests, and other relevant security evaluations and tests.


·Review and verify the results and observations of the Dubai Cybersecurity Index, following up on necessary remediation and improvement actions to enhance security compliance levels within the entity.


·Develop and execute information security awareness programs and campaigns, contributing to fostering a security culture and increasing awareness and adherence to approved security practices and policies.


·Promote and disseminate cybersecurity best practices entity-wide, contributing to raising security awareness and compliance with approved policies and controls.


·Coordinate the execution of phishing simulation tests and security awareness initiatives.


·Provide security guidance and support to employees, contractors, and third parties.


·Measure the effectiveness of awareness programs and prepare reports on their results.


·Contribute to security incident investigations and root cause analysis.


·Ensure security incidents are documented, reported, and handled according to approved procedures.


·Prepare periodic security dashboards, Key Performance Indicators (KPIs), and management reports.


·Monitor and analyze information security performance indicators and compliance levels with approved policies and standards.


·Provide necessary recommendations to develop security controls and enhance the entity's overall security posture.


Educational Qualification:


Bachelor's or Master's degree in Computer Science or Information Technology (Cybersecurity / Information Security / Networks) from an internationally recognized university.


Certifications preferred such as:


·ISO 22301 Lead Implementer / Auditor


·ISO 27001 Lead Implementer / Auditor


·CISA / CISM / CISSP 


Years of Experience:


·Bachelor's degree: 4 – 6 years of experience in the field.


·Master's degree: 2 – 4 years of experience in the field.


Job Skills:


·Information Security and Business Continuity Management (ISMS / BCMS)


·Governance, Risk, and Compliance Management (GRC)


·Conducting and facilitating security audits and following up on results


·Assessing security risks and vulnerabilities and applying appropriate controls


·Preparing reports, dashboards, and communicating with internal and external entities


Behavioral Competencies:


·Effective Communication



·Excellence in Execution


·Community Service and Responsiveness to Stakeholder Needs


·Organizational Understanding


Similar Jobs