Security Guard Jobs in UAE
1020 Jobs Found
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><strong>Job Description:</strong></p><br><p>The Information Security Specialist supports the Information Security Manager in strengthening UAEU’s overall cybersecurity posture. This role ensures effective implementation and continuous improvement of the ISMS aligned with ISO/IEC 27001:2022, UAE IA Standards, and government regulations. It oversees information security governance, risk management, and compliance activities. The specialist conducts security assessments and supports internal and external audits. The role monitors risk posture and maintains the information security risk register. It coordinates investigation of significant security incidents and recommends corrective actions. The position ensures security controls are properly designed, implemented, and monitored. It supports third-party and vendor security risk assessments. The specialist contributes to policy development, awareness initiatives, and regulatory reporting. The role collaborates with IT, SOC, and business units to protect institutional data and research assets. • Support the Information Security Manager in implementing, maintaining, and continuously improving UAEU’s Information Security Management System (ISMS) in alignment with ISO/IEC 27001:2022, UAE IA Standards, and applicable regulations. • Develop, review, and maintain information security policies, standards, procedures, and technical security baselines. • Conduct information security risk assessments for systems, projects, and cloud initiatives, and maintain the Information Security Risk Register. • Monitor the University’s cybersecurity risk posture and provide risk analysis and recommendations to the Information Security Manager and senior management. • Perform security control assessments, compliance reviews, and gap analyses to ensure effective implementation of security measures. • Support internal and external audits by preparing documentation, evidence, and remediation plans. • Oversee vulnerability management activities, validate remediation efforts, and report on risk exposure trends. • Coordinate and support investigation of significant cybersecurity incidents, ensuring proper documentation, root cause analysis, and corrective actions. • Review system architectures, infrastructure changes, and new technology deployments to ensure security-by-design principles are applied. • Conduct third-party and vendor security assessments, review security requirements in contracts, and monitor ongoing compliance. • Ensure effective implementation of technical and administrative controls including access management, encryption, logging, and monitoring. • Support security awareness, education, and phishing simulation programs across the University. • Prepare periodic security dashboards, compliance reports, and risk summaries for management and regulatory authorities. • Collaborate with IT, SOC, data owners, and business units to strengthen control effectiveness and operational resilience. • Promote continuous improvement of UAEU’s cybersecurity capabilities, governance practices, and regulatory compliance. • Perform any additional information security duties as assigned by the Information Security Manager or management. </p><br><p><strong>Minimum Qualifications:</strong></p><br><p>Bachelor’s degree in computer science, Information Technology, Cybersecurity </p><br><p><strong>Experience/Skills:</strong></p><br><p>3+ years in a similar role. </p><br><p><strong>Preferred Qualifications:</strong></p><br><p>Bachelor’s degree in computer science, Information Technology, Cybersecurity </p><br> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
Job Description<br><p>We are currently looking for Information Security Architect for our UAE operations with the following terms & conditions.</p><br><p>Required Skills & Experience</p><br><p>• 10+ years of Information Security experience.</p><br><p>• 5+ years as an Information Security Architect or Enterprise Security Architect.</p><br><p>• Mandatory banking or financial services experience.</p><br><p>Strong knowledge of:</p><br><p>• Enterprise Security Architecture</p><br><p>• Zero Trust Architecture</p><br><p>• Cloud Security (Azure/AWS)</p><br><p>• Identity & Access Management (IAM)</p><br><p>• Network Security</p><br><p>• Application Security</p><br><p>• Data Security</p><br><p>• SIEM, SOC, DLP, EDR/XDR</p><br><p>Experience with security frameworks:</p><br><p>• ISO 27001</p><br><p>• NIST Cybersecurity Framework</p><br><p>• PCI DSS</p><br><p>• CIS Controls</p><br><p>• TOGAF (preferred)</p><br><p>• Mandatory Certification</p><br><p>• CISSP (Certified Information Systems Security Professional)</p><br><p>Preferred Certifications</p><br><p>• CCSP</p><br><p>• CISM</p><br><p>• CEH</p><br><p>• SABSA</p><br><p>• TOGAF</p><br><p>• Azure Security Engineer / AWS Security Specialty</p><br><p>Preferred Candidate Profile</p><br><p>• Excellent stakeholder management and communication skills.</p><br><p>• Experience working in large enterprise banking environments.</p><br><p>• Strong documentation and presentation skills.</p><br><p>• Ability to work with cross-functional technology teams.</p><br><p>Terms and conditions</p><br><p>Joining time frame: Immediate</p><br><br><br> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><span><span>·</span></span><span>Develop and enhance the corporate Cybersecurity Strategy and Key Performance Indicators (KPIs) in alignment with the applicable legislation and regulations of the Government of Dubai and the UAE.</span></p><br><p><span><span>·</span></span><span>Develop and update corporate cybersecurity policies, methodologies, and programs in accordance with the approved cybersecurity frameworks and standards of the Government of Dubai and the UAE.</span></p><br><p><span><span>·</span></span><span>Define and periodically review the roles and responsibilities of all stakeholders involved in implementing cybersecurity controls across the corporate environment.</span></p><br><p><span><span>·</span></span><span>Manage cybersecurity risks through a systematic approach to protect the corporate information and technology assets, in compliance with approved policies, procedures, and applicable legislative and regulatory requirements.</span></p><br><p><span><span>·</span></span><span>Conduct cybersecurity risk assessments for technology projects and prior to implementing any major changes to the technology infrastructure.</span></p><br><p><span><span>·</span></span><span>Develop, maintain, and document cybersecurity requirements to protect corporate external smart applications against cyber threats.</span></p><br><p><span><span>·</span></span><span>Develop, maintain, and document cybersecurity requirements for identity and access management (IAM), including user identities, system access, and access privileges across the corporate environment.</span></p><br><p><span><span>·</span></span><span>Develop, maintain, and document cybersecurity requirements for backup management and information encryption within the corporate environment.</span></p><br><p><span><span>·</span></span><span>Develop, maintain, and document cybersecurity requirements to be incorporated into contracts and agreements with external entities and service providers engaged by the department.</span></p><br> <p><span><span>·</span></span><span>Master's Degree: Minimum 6 years of experience in Information Security, Cybersecurity, or a related field.</span></p><br><p><span><span>·</span></span><span>Bachelor's Degree: Minimum 8 years of experience in Information Security, Cybersecurity, or a related field.</span></p><br> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><strong>Join the team at Yas Water World Abu Dhabi!</strong></p><br><p>At Miral Experiences, we don’t just create jobs — we create extraordinary moments. As part of the visionary Miral Group, we bring to life some of the world’s most iconic attractions, including Ferrari World Abu Dhabi, Warner Bros. World Abu Dhabi, Yas Waterworld, and SeaWorld Yas Island.</p><br><p><strong>Lifeguard Job Overview:</strong></p><br><p>This is a guest facing role which ensures smooth and efficient delivery of the experience for all guests who visit Yas Waterworld. This position ensures guest safety by watching water, responding to emergencies, operating rides and attractions, giving clear directions and instructions, attending on-going training and maintaining essential swimming, lifeguarding, and basic life support skills.</p><br><p><strong>Job Scope:</strong></p><br><ul><li>Ride all rides, slides and attractions as required for operational purposes.</li><li>Ensure guest, colleague and contractor safety at all times.</li><li>Work at heights, in water, and in extreme temperatures, outside, year-round.</li><li>Follow all manufacturer and department guidelines and standard operating procedures regarding ride dispatch and guest safety.</li><li>Maintain rescue skill competency and basic life support skill competency at “test ready” levels at all times.</li><li>Adhere to training standards set by the department.</li><li>Move furniture, ride vehicles and equipment in and out of the park.</li><li>Have basic spoken English proficiency.</li><li>Work nights, evenings, and/or holidays.</li><li>Smile and be friendly.</li><li>Ability to work in a diverse team and be culturally aware.</li><li>Perform all other duties as directed by management.</li></ul><p><strong>Job Essentials:</strong></p><br><ul><li>20/25 vision, corrected or uncorrected</li><li>Swim a minimum of 50 meters, non-stop, using front crawl or breaststroke</li><li>Swim underwater at a depth 1.4 meters for 3 meters and retrieve a 10-pound brick.</li><li>Maintain test-ready lifeguard skills in accordance with International Lifeguard Training Program.</li><li>Basic spoken English proficiency</li></ul><p><strong>Job Desirables:</strong></p><br><ul><li>International Lifeguard Training Program or similar program experience</li><li>Swimming experience</li><li>UAE Driver’s License/Buggy License</li><li>SCUBA certification</li><li>Previous lifeguard experience</li><li>Previous Guest service experience</li><li>Swim 200 meters, non-stop, using front crawl or breaststroke</li><li>Retrieve a 10-pound brick from the deepest water in Yas Waterworld (5 meters)</li><li>Tread water for 2 minutes without using arms</li><li>Intermediate or better English proficiency (read, write, speak)</li><li>Basic spoken Arabic proficiency</li></ul><p>Don't hesitate to apply!</p><br><br>Miral Experiences </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Job Title <br></span><p><span><span>Cyber Security Governance Manager</span></span></p><br>
<br><br>Business <br><br>Job Purpose <br><p>Manage and co-coordinate cyber security activities regarding governance of ENOC information and cyber security efforts towards protecting the organization information assets and critical infrastructure. Manage and maintain the development of cyber security policies, monitor compliance directly or in coordination with the cyber security assurance team. Manage cyber risk management activities and compliance and assist in cyber security planning requirements as directed by Cyber Governance Senior Manager.</p><br>
<br><br>Principal Accountabilities <br><p>Strategy/Governance <br>
coordinate with ENOC technology functions and other departments in order to ensure that cyber-security elements are embedded and taken into account in their strategic and operational plans.<br>
Operational <br>
Develop and enforce cyber-policies, procedures and standards that are in line with best practices and industry trends.<br>
Manage the communication of cyber security policies and guidelines and ensure compliance.<br>
Manage and implement cyber security metrics and reporting framework that measures the efficiency and effectiveness of the cyber security program.<br>
Develop and facilitate a metrics and reporting framework to measure the efficiency and effectiveness of cyber security program<br>
Develop and maintain cyber security architecture.<br>
Act as the cyber security risk management liaison with IT/OT and other departments.<br>
Report to ENOC's management with regard to risks, vulnerabilities and other security exposures, including misuse of information assets and noncompliance.<br>
Work directly with business units and other internal departments and organizations to facilitate cybersecurity risk analysis and management processes, identify acceptable levels of residual risk.<br>
Benchmark cyber security risk management practices of other organizations — particularly those in related industries or with similar business models <br>
Monitor risk mitigation and coordination of policy and controls to ensure that risk owners are taking effective remediation steps.<br>
Contribute and assist in the cyber security risk treatment plan.<br>
Review external cyber security risk assessments, analyse the accuracy of the findings and report on them with actionable recommendations to Line manager and other relevant stakeholders.<br>
Provide support and guidance for cyber security legal and regulatory compliance efforts, including audit support<br>
Participate in the investigation of any potential unlawful or fraudulent action related to cyber security compliance, such as the intentional release of sensitive information or a related security breach<br>
</p><br>
<br><br>Additional Principal Accountabilities <br><p>Manages relationship with the audit group. Receives audit findings, and manages the collection of responses and remediation plans with owners.<br>
manage cyber security compliance control monitoring to ensure cyber compliance risks are managed to the appropriate level of acceptable residual risk.<br>
Maintain an up-to-date understanding of industry best practices, and monitor the regulatory environment for developments that could require changes to ENOC established cyber security policies and practices<br>
Manage the establishment and maintenance of a robust security awareness program<br>
Act as cyber security awareness consultants for ENOC business units<br>
Stakeholder Management <br>
Build strong relationships and working collaboratively with internal/external stakeholders and customers to achieve objectives.<br>
</p><br>
<br><br>Experience <br><p>Education<br>
Degree: Bachelor’s degree in Computer Science, Engineering or Business field or equivalent, Diploma with additional relevant experience.<br>
MBA or Master’s degree in computer science, engineering, information security is preferable.<br>
Required professional certifications: Professional certificate such as CISSP, CISM, C-CISO, GSEC.<br>
Experience <br>
8+ years of Information Technology experience.<br>
4+ years of relevant working experience. <br>
Working experience in multiple industries (e.g. Oil & Gas, Energy, Utilities, Retail, Government…) is preferable.<br>
Working experience in managing cyber risk programs and assessments.<br>
Working experience in managing information and cyber security awareness programs.<br>
Working experience in working with cyber security policies, standards and guidelines.</p><br>
<br><br><br>
</div>
Join the Cybersecurity Marketplace Redefining How Startups Access Security Leadership<br>Fractional CISO - Independent Consultant Remote · Flexible Engagement · Multiple Positions Available<br>The opportunity<br>We're building the first dedicated marketplace connecting startups with world-class fractional CISOs and we're looking for experienced security leaders to be part of it from day one. Startups are scaling fast and facing real security challenges. They need senior guidance, but not a full-time hire. That's where you come in.<br>As a fractional CISO on our platform, you set your terms, choose your clients, and deliver the strategic security leadership that early-stage companies desperately need on a schedule that works for you.<br>What you'll do<br>Depending on client engagements, your work will typically include developing security strategies and roadmaps aligned to startup growth stages, advising on compliance frameworks (SOC 2, ISO 27001, GDPR), leading risk assessments and security architecture decisions, preparing startups for investor due diligence and enterprise sales security reviews, and building security culture from the ground up in fast-moving teams.<br>Who you are<br>You have 10+ years in cybersecurity with at least 3 years in a CISO or senior security leadership role. You've worked with or inside startups and understand their speed, constraints, and priorities. You can translate complex security risk into plain business language and you're comfortable owning the security conversation at board and executive level. You're looking for variety, autonomy, and the ability to make real impact across multiple companies simultaneously.<br>What we offer Early access to a curated pipeline of vetted startup clients, a platform built specifically for security professionals (not a generic freelance marketplace), full control over your rate, availability, and engagement terms, a community of peers at the same level, and visibility to hundreds of businesses actively looking for fractional security leadership.<br>This is not a job. It's a practice. We're not hiring employees, we're partnering with independent security leaders who want to build something on their own terms. If you've been thinking about going fractional, or you're already doing it and want better client access, this is your platform.<br>Apply to join the marketplace We're onboarding our founding cohort of fractional CISOs now. Spots are limited to maintain quality on both sides of the marketplace.<br>Apply today and shape the future of startup security.
Join the Cybersecurity Marketplace Redefining How Startups Access Security Leadership<br>Fractional CISO - Independent Consultant Remote · Flexible Engagement · Multiple Positions Available<br>The opportunity<br>We're building the first dedicated marketplace connecting startups with world-class fractional CISOs and we're looking for experienced security leaders to be part of it from day one. Startups are scaling fast and facing real security challenges. They need senior guidance, but not a full-time hire. That's where you come in.<br>As a fractional CISO on our platform, you set your terms, choose your clients, and deliver the strategic security leadership that early-stage companies desperately need on a schedule that works for you.<br>What you'll do<br>Depending on client engagements, your work will typically include developing security strategies and roadmaps aligned to startup growth stages, advising on compliance frameworks (SOC 2, ISO 27001, GDPR), leading risk assessments and security architecture decisions, preparing startups for investor due diligence and enterprise sales security reviews, and building security culture from the ground up in fast-moving teams.<br>Who you are<br>You have 10+ years in cybersecurity with at least 3 years in a CISO or senior security leadership role. You've worked with or inside startups and understand their speed, constraints, and priorities. You can translate complex security risk into plain business language and you're comfortable owning the security conversation at board and executive level. You're looking for variety, autonomy, and the ability to make real impact across multiple companies simultaneously.<br>What we offer Early access to a curated pipeline of vetted startup clients, a platform built specifically for security professionals (not a generic freelance marketplace), full control over your rate, availability, and engagement terms, a community of peers at the same level, and visibility to hundreds of businesses actively looking for fractional security leadership.<br>This is not a job. It's a practice. We're not hiring employees, we're partnering with independent security leaders who want to build something on their own terms. If you've been thinking about going fractional, or you're already doing it and want better client access, this is your platform.<br>Apply to join the marketplace We're onboarding our founding cohort of fractional CISOs now. Spots are limited to maintain quality on both sides of the marketplace.<br>Apply today and shape the future of startup security.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p>The Information Security Cyber Organization Alignment and Compliance position focuses on aligning our information security practices with the bank’s overall risk management strategy, compliance requirements, and governance frameworks.</p><br><p>The role focuses on driving Information Security Governance, Risk, and Compliance (GRC) initiatives to strengthen the bank’s security posture while ensuring alignment with regulatory and business objectives. through effective processes i.e., risk tracking, compliance monitoring, RCSA, evaluating exceptions, and ensuring accurate reporting. The role ensures the right level of governance and compliance are in place and drives continuous improvement in risk management processes.<br> </p><br><ul><li>Ensure compliance with policies, regulatory requirements, and industry standards.</li><li>Identify, assess, and manage information security risks with business.</li><li>Ensure adherence to internal and external compliance requirements.</li><li>Perform risk trend analysis and reporting</li><li>Develop and maintain a comprehensive process for managing policy exceptions, including documentation, expiration date and approval workflows.</li><li>Ensure all policy exceptions are properly documented, reviewed, and approved in accordance with organizational standards.</li><li>Drive risk assessments for proposed policy exceptions to evaluate their potential impact on compliance and security.</li><li>Work with stakeholders to communicate policy exception process, develop compensating controls for policy exceptions, and ensure timely closure.</li><li>Regularly review and monitor granted exceptions to ensure compliance with the terms and conditions.</li><li>Conduct periodic review of approved exceptions and identify gaps for improvements. </li><li>Develop and maintain a comprehensive service catalog that accurately reflects the services offered by ISG. Regularly review and update the service catalog to ensure it aligns with business needs and technological advancements</li><li>Monitor the performance of ISG services to ensure they meet established service level agreements (SLAs) and key performance indicators (KPIs).</li></ul><ul><li>Minimum 6–8 years of total professional experience, including 4–6 years of dedicated Information Security GRC experience.</li><li>Familiarity with information security technologies, risk, threat and vulnerability assessments, and security measures.</li><li>Experience with governance, risk management, and compliance frameworks (e.g., ISO 27001, NIST, GDPR, PDPL).</li><li>Hold professional certifications such as CISA, CISM, CISSP, CRISC</li><li>Skills and Application</li><li>Strong communication and interpersonal skills.</li><li>Ability to manage multiple projects and priorities.</li><li>Proficiency in security tools and technologies.</li><li>Strategic Insight</li><li>Foster a culture of security awareness and compliance within the organization.</li><li>Continuously improve the information security posture of the organization.</li><li>Ensure that information security risks are effectively managed and mitigated.</li></ul><br> </div><h2 data-automation-id="subHeaderPreferredCandidate" class="h5">
Preferred candidate </h2>
<div class="row is-m v-align-top t-small bg-mute">
<div class="col is-3 p5" data-automation-id="label_Nationality">
<b>Nationality</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Nationality">
United Arab Emirates </div>
</div>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><ul><li>Monitor security alerts and investigate potential incidents, distinguishing between false positives and genuine threats to safeguard organizational assets.</li><li>Conduct vulnerability assessments and penetration testing to identify weaknesses in systems and applications before malicious actors can exploit them.</li><li>Develop and implement security policies and procedures, ensuring alignment with industry best practices and regulatory compliance.</li><li>Respond to security incidents by containing, eradicating, and recovering compromised systems, minimizing impact and restoring normal operations.</li></ul></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li><p>Possess a Bachelor's degree in Computer Science, Information Security, or a related field, providing a strong theoretical foundation.</p></li><li><p>Hold relevant certifications such as CompTIA Security+, CISSP, or CEH, demonstrating validated expertise in information security principles.</p></li><li><p>Have 2-5 years of progressive experience in cybersecurity roles, with a proven track record of protecting digital assets.</p></li><li><p>Demonstrate proficiency in network security concepts, including TCP/IP, firewalls, VPNs, and routing protocols.</p></li></ul><p></p></section>
<p>The Information Security Specialist is responsible for safeguarding the organization’s systems, data, and technology infrastructure by implementing and maintaining effective security controls and monitoring activities.
This role supports the organization’s security and compliance objectives by identifying risks, responding to security incidents, and ensuring alignment with regulatory and industry standards.</p><p>• Monitor and respond to security incidents and alerts, supporting investigation, escalation, and resolution.
• Maintain and implement security controls to protect systems, applications, and data against internal and external threats.
• Perform security monitoring using SIEM and other security tools, analysing logs and events to identify potential threats and recommend remediation.
• Support vulnerability management activities, including identifying, prioritising, and tracking remediation of security weaknesses.
• Conduct security risk assessments and support internal and external security audits.
• Ensure compliance with security standards and regulatory requirements, including PCI-DSS.
• Implement and maintain Web Application Firewalls (WAF), DDoS protection, firewall technologies, and cloud-native security controls (e.g. Cloudflare, Akamai, Azure/AWS security services where applicable).
• Support application security throughout the software development lifecycle, including static application security testing (SAST) using tools such as Veracode, Checkmarx, Trivy or similar.
• Assist with container and cloud workload security, including Docker, Kubernetes and container image scanning.
• Perform or support penetration testing, vulnerability assessments and security validation activities using industry-standard tools (e.g. Kali Linux, Burp Suite, OWASP methodologies).
• Develop and maintain automation scripts using Python, PowerShell or Bash to improve security operations and monitoring.
• Collaborate closely with Engineering, Infrastructure, DevOps and Compliance teams to embed security into development and operational processes.
• Maintain security documentation, operational procedures and technical standards to support audit readiness and operational consistency.</p>
Job Purpose<br><br>Supervise security functions for all Employees, its contractors, on-site security with military and / or government entities. Ensures compliance of applicable gate pass & security policies and procedures while implementing security measures.<br><br>Job Responsibilities<br><br>Supervising security personnel and ensuring that they are securing the premises and personnel, inspecting areas and access points. Daily security Patrolling. Rotation on Night duty shift Permitting entry based on the gate pass approval and documents Coordinates with the Security Document Controller regarding the approvals and documents required Prevent losses and damages by reporting irregularities, informing violators of policies and procedures Makes and completes incident reports by recording observations, information, occurrences and surveillance activities; interviewing witnesses; obtaining signatures Writing clear reports and logs. Completing reports of alarms, incidents, and complaints. Ensure the security, safety and well-being of all personnel and the premises Adhere to all company service and operating standards Remain in compliance with local regulations / authorities Respond to incidents related to security to provide necessary assistance to official authorities Follow procedures for various initiatives including property patrol and incident investigations Ensuring the safety, security, protection of property and assets. Evaluate, assess and analyze performance of security personnel. Keep the premises free from all kinds of dangers. Assist in developing and implementing preventative measures against incidents and other risks. Provide excellent customer service Maintain organization's stability and reputation by complying with legal requirements Perform other duties as assigned by the Direct Manager.<br><br>Job Requirements<br><br>High school/ Secondary or a combination of appropriate Education and Experience Military background is a plus SIRA certified (Security Industry Regulatory Authority) and DPS certified (Department of Protective System) is a must. Minimum 2-3 years at the same position within similar structure or in 5-6 stars hotels. Safety & Security Awareness1st aider certified Fire training certified Bomb threat certified Good communication in Arabic and English (writing , reading and speaking) Computer Literate (MS Office)
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><span>0</span></p><br> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p>The Information Security Cyber Organization Alignment and Compliance position focuses on aligning our information security practices with the bank’s overall risk management strategy, compliance requirements, and governance frameworks.</p><br><p>The role focuses on driving Information Security Governance, Risk, and Compliance (GRC) initiatives to strengthen the bank’s security posture while ensuring alignment with regulatory and business objectives. through effective processes i.e., risk tracking, compliance monitoring, RCSA, evaluating exceptions, and ensuring accurate reporting. The role ensures the right level of governance and compliance are in place and drives continuous improvement in risk management processes.<br> </p><br><ul><li>Ensure compliance with policies, regulatory requirements, and industry standards.</li><li>Identify, assess, and manage information security risks with business.</li><li>Ensure adherence to internal and external compliance requirements.</li><li>Perform risk trend analysis and reporting</li><li>Develop and maintain a comprehensive process for managing policy exceptions, including documentation, expiration date and approval workflows.</li><li>Ensure all policy exceptions are properly documented, reviewed, and approved in accordance with organizational standards.</li><li>Drive risk assessments for proposed policy exceptions to evaluate their potential impact on compliance and security.</li><li>Work with stakeholders to communicate policy exception process, develop compensating controls for policy exceptions, and ensure timely closure.</li><li>Regularly review and monitor granted exceptions to ensure compliance with the terms and conditions.</li><li>Conduct periodic review of approved exceptions and identify gaps for improvements. </li><li>Develop and maintain a comprehensive service catalog that accurately reflects the services offered by ISG. Regularly review and update the service catalog to ensure it aligns with business needs and technological advancements</li><li>Monitor the performance of ISG services to ensure they meet established service level agreements (SLAs) and key performance indicators (KPIs).</li></ul><ul><li>Minimum 6–8 years of total professional experience, including 4–6 years of dedicated Information Security GRC experience.</li><li>Familiarity with information security technologies, risk, threat and vulnerability assessments, and security measures.</li><li>Experience with governance, risk management, and compliance frameworks (e.g., ISO 27001, NIST, GDPR, PDPL).</li><li>Hold professional certifications such as CISA, CISM, CISSP, CRISC</li><li>Skills and Application</li><li>Strong communication and interpersonal skills.</li><li>Ability to manage multiple projects and priorities.</li><li>Proficiency in security tools and technologies.</li><li>Strategic Insight</li><li>Foster a culture of security awareness and compliance within the organization.</li><li>Continuously improve the information security posture of the organization.</li><li>Ensure that information security risks are effectively managed and mitigated.</li></ul><br> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><span>To be filled by the Recruiter</span></p><br> </div>
<p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Bachelor's degree in Information Security, Information Management Systems, Information Technology, Cybersecurity, or any related discipline.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Master's degree in Information Management Systems, Information Technology, Cybersecurity (preferred).</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Professional certifications such as Project Management Professional (PMP), CISSP, CISM, CCSP/CCSK; are advantageous</span></span><span >.</span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Certified ISO 27001 lead implementer or lead auditor.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Training or certification in security monitoring tools such as SIEM.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >A minimum of 11 years of experience in information security, with 5 years leading operations/support or SOC/IAM/vulnerability functions.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Extensive experience in conducting risk assessments, developing risk mitigation strategies, and managing incident response for security breaches and attacks.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Extensive experience in leading the implementation and management of access controls and authorizations for various systems and databases to ensure compliance with organizational security policies.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Experience ensuring compliance with these standards and regulations in all operations and third-party engagements.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Robust experience in managing all aspects of information security incidents, including identification, analysis, containment, eradication, and recovery.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Proven competence in overseeing testing and compliance checks on applications and systems developed by third-party vendors.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Strong background in developing and implementing disaster recovery plans that address potential risks and ensure continuity of operations in the event of security breaches or disasters.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Proven track record of effectively managing an information security operations center (SOC), cyber threat intelligence or similar environments that monitor and protect organizational IT infrastructure.</span></span></p><table class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0" width="616"><tbody><tr ><td valign="top" width="616"><p class="MsoNormal" ><span ><b ><span ><strong>Key Skills & Capabilities:</strong></span></b></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Capable of advanced implementation of information security policies and procedures to monitor operations and ensure compliance with standards and regulations.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Advanced in classifying information into various asset groups, maintaining systems, and sharing information with stakeholders.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Advanced in understanding and applying risk management methodologies, including assessing risks, evaluating vulnerabilities and threats, and following up on risk treatments.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Advanced in responding to security incidents by following established protocols and effectively managing stakeholder interactions.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Advanced in developing access control matrices and conducting thorough access reviews of information systems, identifying and addressing deviations.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Proficient in developing secure operational policies and ensuring effective implementation of change controls, backups, and patch management.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Proficient in applying secure software development Life Cycle (S-SDLC) practices, advising on application security, and conducting architecture reviews.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Proficient in conducting vulnerability and penetration tests, monitoring threats, and addressing continuity issues with relevant business departments.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Advanced in auditing information security standards and processes, capable of conducting compliance checks and developing continual improvement plans.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Advanced in understanding the requirements for information security assurance and performance assessments for standards like ISO 27001 and ISR.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Advanced in developing and delivering information security training and awareness programs, researching new topics, and evaluating training outcomes.</span></span></p><p class="TableParagraph" ><span ><span >●</span><span > </span></span><span ><span >Proficient in understanding cloud security regulations, ensuring compliance, and conducting governance and risk assessments.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Ability to develop and execute long-term security strategies that align with organizational goals.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Capability to manage a diverse team to achieve excellent results in information security.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Strong analytical capabilities for troubleshooting, problem-solving, and decision-making within operational settings.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Skill in using analytics to monitor system performance and to derive actionable insights from data.</span></span></p><p class="MsoNormal" ><span ><span >●</span><span > </span></span><span ><span >Profound knowledge of cybersecurity principles, practices, and technologies including firewall management, intrusion detection systems, anti-virus software, data encryption, and other industry-standard techniques and practices.</span></span></p></td></tr></tbody></table>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Job Title <br></span><p>OT/ICS Cybersecurity & Automation Specialist</p><br>
<br><br>Business <br><p>CIS</p><br>
<br><br>Job Purpose <br><p>Execute the Cybersecurity and Automation technical day-to-day management and coordination of related projects and operations within the business segments to ensure alignment of all process and operational aspects with ENOC’s Automation and cyber security policies and work requirements.</p><br>
<p>This includes implementation of OT Automation and Cybersecurity needs of the organization and translating them into secure systems designs and principles, also adopt the recommended technologies and best practices within ICS/OT domain.</p><br>
<p>Support technical evaluation and site related cybersecurity and automation work in coordination with business team.</p><br>
<br><br>Principal Accountabilities <br><p>Enforce site installation compliance and adherence to ENOC’s cybersecurity controls, policies, and procedures.<br>
Develop, implement, operate, and maintain security solutions with ICS infrastructure such as firewalls, IPS, patching solution, secure remote access and endpoint security.<br>
Conduct asset inventory for the industrial automation control systems and the cybersecurity solutions and then delegate control, ownership, and authentication of OT/ICS assets to the associated asset owner.<br>
Liaise with the cyber security & Automation team to facilitate cyber security assessments, performance reporting and projects planning and implementation.<br>
Review and improve IT/OT network design and architecture with reference to PERA, ISA Reference Model across business units.<br>
Design and implement security measures in line with ENOC cyber security and industrial best practices and requirements.<br>
Review Engineering submittals (HLD, LLD, FDS, SDS, FAT, SAT, Operation manuals, etc.) from the Vendors for IACS and security systems integration.<br>
Review risk assessments and audit observations to implement mitigation actions to address identified gaps and coordinate the identified mitigation actions with all relevant stakeholders.</p><br>
<br><br>Additional Principal Accountabilities <br><p>Coordinate & support site works with vendors (OEM, system integrators, Service providers) and Company’s concerned departments for the RFI, RFQ, POC, SOW, SOS, Purchase requisite, etc.<br>
Participate in ICS projects and changes within the business unit to ensure proper implementation of cyber security requirements.<br>
Support implementation and testing of the industrial automation control systems along with the related security technologies and controls.<br>
Support to generate site specific Cybersecurity & Automation policies and procedures.<br>
Partner with the department team member (Network, System, Automation) to populate the HLD, LLD, and identify improvement opportunities and the current challenges in addition to raised alerts and incidents with the OT/ICS environment.<br>
Work with OT/ICS Automation & Cybersecurity Manager and CIC & SOC teams and department team member for the new CVE and Zero-Day vulnerability identified within the OT/ICS environment. <br>
Participate in ICS security incident response through all phases and act as a member of Security Incident Response Team (SIRT).<br>
Raise and highlight pain points in aligning Automation and Cybersecurity controls within the business.</p><br>
<br><br>Experience <br><p>Bachelor’s degree in a technical field, e.g., (Engineering degree, Computer Science or Information Systems, Industrial Cybersecurity, or another related technical field with appropriate experience).<br>
Demonstrated years of experience working with Automation and Security Programs phases from Assessment, design, implementation to maintain and daily operation with multinational organization or with OEM and Vendors for OT/IACS digital industries and automation systems (SCADA, DCS, SIS, PLC, PAC).<br>
Preferred professional certifications: ISA/IEC 62442, CISSP, SANS ICS certifications<br>
Minimum 7+ years of experience in industrial control systems and cybersecurity preferably in the Oil & Gas, Energy, Lubricant, Aviation and Critical Infrastructure<br>
Demonstrated years of experience working with Automation and Security solutions.<br>
Advanced Knowledge of Automation process and safety instrumented system industries standards such as IEC61131, SIL and FS standards IEC61508/IEC61511, ATEX Directive and ISA standards.<br>
Extensive knowledge of industrial communication protocols and ports used such as: (Serial Protocols, HART, TCP/IP, UDP, DNP3, Modbus, IEC 61850, S7, OPC, OPC UA, EtherNet/IP, BACnet, Profibus and PROFINET)<br>
Experience with security engineering principles, various cybersecurity assessment methodologies, security control implementation, and validation, and system life-cycle practices.<br>
Experience with any OT security tools such as Darktrace, Dragos, Nozomi Networks, Claroty etc. is a must, and having training certificate is preferable.<br>
Strong analytical and critical thinking skills, along with strong written and oral communication skillsersecurity controls within the business.</p><br>
<br><br><br>
</div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
Job description
<p>This is a great opportunity to join a well-established, rapidly growing office in the region and drive the cybersecurity strategy for the entire group of companies globally. <br><b>Discover the Company</b></p><br><p>A Globally recognized French Luxury house that seamlessly blends cultural heritage, artistry, and modern sophistication.</p><br><p><br><b>Discover the role:</b></p><br><p>We are seeking a Cyber Security Manager to own and drive the end-to-end cybersecurity function across a multi-entity group spanning the UAE, France, and beyond. This is a unique greenfield opportunity giving you the autonomy to build, formalize, and scale a global security framework from scratch.<br></p><br><p>Reporting directly to the IT Director, you will combine high-level strategy and stakeholder management with hands-on transformation delivery.</p><br><p></p><br><p><b>Discover the Requirements</b></p><br><ul><li><p>Minimum 5+ years of dedicated cybersecurity experience in a management or lead role within the UAE region.</p><br></li><li><p>Proven track record delivering cybersecurity programs in complex, multi-entity international environments. Experience or background working with European markets is highly advantageous.</p><br></li><li><p>Deep, hands-on experience within Azure-heavy cloud environments, enterprise identity management (IAM), network security, and SIEM/XDR platforms.</p><br></li><li><p>A forward-thinking approach to security, with the capability to map out defenses against next-generation, AI-driven threats.</p><br></li><li><p>A background in fast-scaling digital platforms, retail, or manufacturing ecosystems is a strong plus.</p><br></li><li><p>CISSP, CISM, or equivalent professional certifications are required.<br></p><br></li></ul><p><b>We are only considering candidates who are already based in the UAE and have regional experience.</b></p><br><br>
</div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span></span><p><span>The Project Manager Cybersecurity controls the day-to-day delivery interface between RTA, the contractor, and internal KM stakeholders, ensuring governance, milestones, deliverables, and acceptance evidence meet the contractual requirements and the RFP. The role is accountable for planning and coordinating all operational gating required for implementation within a live rail environment, including KM change control. Delivery is typically executed within restricted engineering access windows, and requires disciplined readiness checks, testing, communications, contingency planning, and rollback capability.</span></p><br>
<p><span><strong>KEY RESPONSIBILITIES </strong></span></p><br> <p><span><strong> Strategic</strong></span></p><br> <ul>
<li><span>Lead end-to-end delivery of RTA-sponsored cybersecurity initiatives, ensuring project governance, milestones, and deliverables align with the RFP, contract, and agreed acceptance criteria. </span></li>
<li><span>Maintain a secure-by-design approach across project life cycle stages, ensuring cybersecurity requirements are built in early and evidenced through testing and documentation. </span></li>
<li><span>Ensure solutions align with applicable local and international cybersecurity standards, and rail industry expectations for safety-critical environments, including DESC ISR v3.1, DESC ICS v1.0, ISO/IEC 27001:2022, IEC 62443, and CLC/TS 50701:2023.</span></li>
<li><span>Work in partnership with RTA RMD (Rail Maintenance Department) governance</span></li>
<li><span>Operate within governance chaired by RTA (typically RTA RMD), ensuring key milestones and acceptance decisions are jointly signed off by RTA and Keolis-MHI in line with the contract and RFP</span></li>
</ul> <p><span><strong>Financial </strong></span></p><br>
<ul>
<li><span>Manage delivery to agreed budget and schedule baselines for large programmes, including forecasting, variance analysis, and change control.</span></li>
<li><span>Control scope and cost impacts through disciplined management of variations, claims, and dependencies, working with the Project and Innovation Department on KPIs, commercial controls, and penalty exposure.</span></li>
<li><span>Monitor contractor performance against delivery KPIs and milestone evidence, escalating deviations through the Project and Innovation Department governance.</span></li>
</ul> <p><span><strong>Stakeholder / Customer </strong></span></p><br> <ul>
<li><span>Act as KM’s primary day-to-day project manager interface for RTA and the contractor, ensuring transparent communication, clear action tracking, and timely escalation. </span></li>
<li><span>Coordinate strongly with the Head of Cybersecurity and the cybersecurity team to align delivery with security governance and operational needs</span></li>
<li><span>Align internal stakeholders across IT, OT, Operations, Maintenance, Safety, and QHSE to ensure delivery is practical for a live metro environment.</span></li>
</ul> <p><span><strong>Operational </strong></span></p><br>
<ul>
<li><span>Establish and maintain the full project controls pack, including integrated schedule, RAID log (risks, assumptions, issues, dependencies), decision log, change register, and acceptance tracker. </span></li>
<li><span>Lead delivery planning and execution for work performed in constrained access windows, typically engineering hours, ensuring correct sequencing, readiness, and rollback planning. </span></li>
<li><span>Own and manage all approvals required for implementation in critical infrastructure environments, including: </span>
<ol>
<li><span><strong>RTA CIMP (Change Impact Management Process)</strong> coordination to secure RTA approvals for impacted services and interfaces.</span></li>
<li><span><strong>ACCA (Asset Configuration Change Application)</strong> initiation, coordination, tracking, and closure within KM change control.</span></li>
<li><span><strong>PTW (Permit to Work)</strong> management to ensure site works only proceed when formally authorised, safe, and controlled.</span></li>
</ol>
</li>
<li><span>Ensure the contractor provides compliant and complete work packs, such as method statements, risk assessments, test procedures, and site readiness evidence. </span></li>
<li><span>Enforce separation between Business ICT and Rail OT networks and ensure Rail OT systems remain isolated and air-gapped unless explicitly approved through change control and security governance. </span></li>
<li><span>Manage quality assurance across delivery stages including but not limited to:</span>
<ol>
<li><span>design reviews</span></li>
<li><span>FAT (Factory Acceptance Test)</span></li>
<li><span>PICO (Post-installation Check-Out</span></li>
<li><span>SAT (Site Acceptance Test)</span></li>
<li><span>SIT (System Integration Testing)</span></li>
<li><span>UAT (User Acceptance Test)</span></li>
<li><span>Security testing, cutover planning, and handover.</span></li>
</ol>
</li>
<li><span>Ensure delivery outputs support operational sustainment, including RTA SOC integration (log sources, alerts, use cases), runbooks, and support models.</span></li>
</ul> <p><span><strong>Capability / People</strong></span></p><br>
<ul>
<li><span>Lead matrix teams across KM and direct the contractor delivery team through structured governance and delivery management. </span></li>
<li><span>Drive delivery discipline, documentation quality, and evidence-based acceptance across all workstreams. </span></li>
<li><span>Promote a safety and security culture, including the right and obligation to stop work if safety or security conditions are not met.</span></li>
</ul> <p><span><strong>DIMENSIONS </strong></span></p><br>
<ul>
<li><span>Multi-stakeholder delivery model: RTA sponsor and chair, KM project manager, contractor as delivery party under the 3-partite agreement. </span></li>
<li><span>Delivery context: operational metro and tram environment, critical infrastructure constraints, restricted access windows, and strict change and work authorisation controls.</span></li>
<li><span>Working at night or during weekends as required for timely project completion in line with HR Policy and UAE Law.</span></li>
<li><span>Office environment. Occasional travel may be required.</span></li>
</ul> <p><span><strong>MINIMUM QUALIFICATIONS</strong></span></p><br>
<p><span><strong>Min.</strong></span></p><br>
<p><span><strong>Required</strong></span></p><br>
<p><span><strong>Desirable</strong></span></p><br>
<br>
<p><span><strong>Education</strong></span></p><br>
<ul>
<li><span>Bachelor’s degree in engineering, Information Systems, Computer Science, Cybersecurity, or related discipline.</span></li>
</ul>
<ul>
<li><span>Postgraduate qualification in project management, cybersecurity, or systems engineering.</span></li>
</ul>
<br>
<p><span><strong>Experience</strong></span></p><br>
<ul>
<li></li></ul> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>We are looking for a Senior Network Security Engineer with a strong specialization in Secure Web Gateway (SWG) and proxy technologies, particularly Blue Coat ProxySG (now part of Broadcom/Symantec).<br> This role sits within our broader network security function and is responsible for administering, securing, and optimizing web/internet access infrastructure across the organization.<br> Candidates should bring at least 2–3 years of hands-on Blue Coat ProxySG / SGOS administration experience as part of a broader network security career (typically 5+ years overall).<br> Experience in banking and financial services is a strong plus, but not mandatory.<br> Key Responsibilities Proxy & Secure Web Gateway Administration Administer, configure, and support Blue Coat ProxySG (SGOS) and related secure web gateway/web security solutions.<br> Design, implement, and maintain web filtering categories, acceptable use policies, and secure internet access controls.<br> Configure and manage SSL/TLS interception (SSL Visibility), authentication integration (AD/LDAP, Kerberos, SAML), and ICAP integration with DLP, antivirus, and sandboxing solutions.<br> Monitor proxy performance, availability, and capacity; conduct tuning and optimization to ensure minimal latency and maximum uptime.<br> Troubleshooting & Incident Response Troubleshoot proxy-related incidents, connectivity issues, and policy conflicts, working across network layers (TCP/IP, DNS, HTTP/HTTPS, routing).<br> Participate in security incident response related to web-based threats, malicious traffic, and policy violations.<br> Collaborate with SOC, network, and broader cybersecurity teams to correlate proxy logs with SIEM and threat intelligence platforms.<br> Project, Migration & Lifecycle Support Support upgrades, patching, and lifecycle management of Blue Coat ProxySG appliances and related SWG components.<br> Assist with migration or integration projects between on-premise proxy solutions and cloud-delivered SWG/SASE platforms.<br> Contribute to automation and scripting initiatives to streamline policy deployment, reporting, and routine administration tasks.<br> Governance, Documentation & Compliance Prepare and maintain technical documentation, configuration standards, and operational runbooks.<br> Support internal and external audits by providing evidence of secure configuration, change control, and policy enforcement.<br> Ensure alignment with information security policies and relevant regulatory frameworks (e.<br>g., SAMA, NCA ECC, ISO/IEC 27001, PCI DSS) where applicable.<br> Bachelor's degree in Computer Science, Information Technology, Network Engineering, or a related field (or equivalent practical experience).<br> 5+ years of overall network/cybersecurity engineering experience, including a minimum of 2–3 years of hands-on Blue Coat ProxySG / SGOS administration.<br> Alternatively, 5+ years of overall network/cybersecurity experience with strong hands-on exposure to other leading secure web gateway or proxy platforms (e.<br>g., Symantec Web Security Service, Forcepoint, McAfee/Skyhigh Web Gateway, Cisco WSA/Umbrella, Zscaler, Fortinet FortiProxy), with demonstrated ability and willingness to specialize in Blue Coat ProxySG.<br> Strong understanding of core networking concepts: TCP/IP, DNS, HTTP/HTTPS, routing, and network segmentation.<br> Hands-on experience with web filtering, URL categorization, SSL/TLS interception, and content inspection policies.<br> Experience integrating proxy/SWG platforms with DLP, sandboxing, threat intelligence, or SIEM solutions is highly valued.<br> Excellent troubleshooting, analytical, and communication skills, with the ability to work cross-functionally with network, security, and infrastructure teams.<br> Experience in banking, financial services, or other regulated sectors is preferred but not required.<br></span> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<b>Overview:</b> <br><p><strong>About Analog</strong></p><br><br><br><p>Analog is pioneering the era of physical intelligence. Where digital intelligence transformed our online lives, Analog is transforming the lived world, making cities more adaptive, industries more resilient, services more human centered, and experiences more extraordinary.</p><br><br><br><p>At the heart of our approach are living world models, continuously updated, enriched by every capture point, every device, every interaction. Within them resides Ana, the Analog Neural Agent. Ana perceives, adapts, and guides, transforming raw data into foresight and orchestration that improves outcomes across sectors, from safeguarding high-value assets to enhancing human performance.</p><br><br><br><p><strong>Job Description</strong></p><br><br><p>We are seeking a highly skilled <strong>Senior Security Engineer</strong> to be the first hire in our Infosec team. This is a hands-on technical leadership role with high growth potential in a cutting-edge AI driven organization. The ideal candidate will have deep expertise in designing, implementing, and maintaining end-to-end security solutions across infrastructure, applications, and data. As the first dedicated security hire, you will play a pivotal role in building and shaping our cybersecurity strategy and practices from the ground up.</p><br><br><br><p>In this role, you will be responsible for planning, designing, and implementing security solutions, identifying risks, and ensuring compliance with industry standards. You will work closely with cross-functional teams to embed security at every level of our technology and business processes. You will also play a lead role in developing a longer term security improvements roadmap, setting the foundation for future team expansion and required security tooling investments. If you are an experienced, hands-on security professional eager to make a significant impact in a high-growth organization, we encourage you to apply.</p><br><br><b>Responsibilities:</b> <br><ul><li><strong>Security Strategy & Roadmap</strong>: Develop a comprehensive security roadmap that aligns with business strategy, supporting product launches and future business growth.</li><li><strong>Security Architecture</strong>: Design, implement, and manage security architectures for cloud, on-premises, and hybrid environments.</li><li><strong>Policies & Standards</strong>: Develop, enforce, and continuously improve security policies, frameworks, and best practices across the organization.</li><li><strong>Risk & Compliance</strong>: Conduct risk assessments, threat modeling, and vulnerability management to proactively mitigate security threats, while ensuring compliance with relevant security standards e.g. ISO 27001, NIST, GDPR, SOC 2, and CIS benchmarks</li><li><strong>Incident Management:</strong> Lead incident response efforts, including investigation, containment, remediation, and post-mortem analysis.</li><li><strong>Security Testing</strong>: Perform penetration testing, security audits, and compliance assessments to validate security posture.</li><li><strong>Security Tooling</strong>: Deploy and manage security solutions such as SIEM, IDS/IPS, endpoint protection, IAM, firewalls, and encryption technologies.</li><li><strong>Collaboration & Communication</strong>: Works closely with Engineering, DevOps, and IT teams to integrate security into system architectures and software development processes (DevSecOps). Communicates security risks and recommendations effectively to technical and non-technical stakeholders.</li><li><strong>AI & Data Security</strong>: Develop & implement security measures to protect AI models, data pipelines and APIs from adversarial attacks and data leakage.</li><li><strong>Emerging Trends</strong>: Stays current with evolving cyber threats, attack techniques, and security trends, applying knowledge to strengthen defenses.</li><li><strong>Training & Awareness:</strong> Develop and conduct security awareness training programs to foster a strong security culture within the organization.</li><li><strong>External Partnerships:</strong> Establish relationships with external security vendors, partners, and regulatory bodies to leverage expertise and support.</li></ul><br><b>Qualifications:</b> <br><ul><li>Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.</li><li>Minimum of 5 years of hands-on experience in cybersecurity, information security, or a related field.</li><li>Proven experience in security architecture, engineering, and operations in cloud (AWS, Azure, GCP) and on-prem environments.</li><li>Strong knowledge of security frameworks such as NIST, ISO 27001, CIS Controls, and Zero Trust architecture.</li><li>Hands-on experience with security tools, including firewalls, SIEM, EDR, IDS/IPS, vulnerability scanners, DLP, and encryption.</li><li>Expertise in security incident response, threat intelligence, and forensic investigations.</li><li>Experience with identity and access management (IAM), multi-factor authentication (MFA), and privilege access management (PAM).</li><li>Proficiency in programming and scripting languages such as Python, PowerShell, or Bash</li><li>Industry certifications such as CISSP, CISM, CEH, OSCP, or equivalent are highly preferred.</li><li>Strong knowledge of DevSecOps principles and secure software development practices.</li><li>Demonstrated ability to communicate effectively with both technical and non technical audiences.</li><li>Experience working with security governance, risk management, and compliance (GRC) programs.</li><li>Excellent problem-solving, analytical, and communication skills with the ability to work independently and collaboratively.</li></ul><br><p><strong>Good-to-Have Experience</strong></p><br><br><br><ul><li>Experience with physical security measures, such as facility access controls, video surveillance, and security monitoring systems.</li><li>Knowledge of IoT security, industrial control systems (ICS) security, and supply chain security.</li><li>Experience implementing Zero Trust and Secure Access Service Edge (SASE) architectures.</li><li>Understanding of AI security risks and model protection strategies</li><li>Prior experience working in high growth technology start ups.</li></ul><br><p>If you are passionate about cybersecurity and want to build and lead the security function in a high-growth, innovative organization, we would love to hear from you!</p><br><br><br><br><p><strong>What Working At Analog Offers</strong></p><br><br><br><ul><li>Culture: A collaborative, globally minded team building the future of physical intelligence. We value curiosity, courage, and creativity, and we’re united by a belief that technology should amplify human potential rather than replace it.</li><li>Impact: The opportunity to work on projects with national and global significance, from adaptive cities and resilient infrastructure to next generation sports, entertainment, healthcare, and energy. Every product you help build contributes to shaping a safer, smarter, more human centered world.</li><li>Growth: Outstanding opportunities for learning and career development. You’ll collaborate with leaders across AI, robotics, mixed reality, and systems engineering, while working on industry first, frontier scale solutions.</li><li>Rewards: A competitive compensation package with healthcare, education support, and generous leave benefits, reflecting the high value we place on our people and their families.</li></ul><br><br> </div>