Sr Security Analyst
# Sr Security Analyst **Tayseer G T** · Dubai · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role Role SummaryThe Senior Security Analyst will own and drive an end-to-end banking security compliance program, spanning gap assessment, risk assessment and treatment, ISO/IEC 27001 implementation, internal audit, corrective action management, and certification readiness. The role requires deep expertise in banking security controls, regulatory compliance, and the ability to translate technical risk into executive-level reporting and action. Technical Skills· ISO/IEC 27001 Lead Auditor certification with practical experience leading or managing ISMS audits. ·Proven ability to manage an end-to-end banking security compliance program: gap assessment, scope definition, risk assessment and treatment, Statement of Applicability, policies, evidence management, internal audit, corrective actions, management review, and certification readiness. ·Strong knowledge of banking security, data protection, third-party risk, business continuity, incident management, and regulatory compliance. ·Good working understanding of SIEM/SOC, IAM/MFA/PAM, network and endpoint security, vulnerability management, cloud security, DLP, encryption, backup/DR, and secure SDLC. ·Working knowledge of PCI DSS, ISO 22301, NIST CSF, CIS Controls, SWIFT CSP, or comparable banking frameworks. ·Exposure to Microsoft Sentinel/Defender, Azure/AWS security, GRC platforms, vulnerability scanners, and audit/evidence automation preferred Soft Skills· Strong ownership, judgement, and integrity, with the confidence to constructively challenge control gaps. · Clear written and verbal communication skills; able to translate technical risk into practical actions and management-level reporting. · Experience presenting to executives, audit committees, regulators, external auditors, and bank stakeholders. · Ability to coach junior analysts and coordinate control owners without relying on formal authority. · Comfortable working with multicultural and remote teams under tight audit deadlines. · Strong planning, stakeholder management, evidence discipline, and follow-through across distributed teams. Qualifications (Education & Certifications)· Bachelor’s degree in cyber security, Information Security, Computer Science, IT, or related discipline. A master’s degree in cyber security, Information Security or Risk Management is preferred. · Valid ISO/IEC 27001 Lead Auditor certification from a recognized training/certification body. · Should have minimum one of the following certifications CISA, CISSP, CISM, CRISC, · ISO 27001 Lead Implementer, ISO 22301, or PCI DSS. Experience· 5–8 years in information security, including at least 3 years in security governance, risk, compliance, or audit within banking or financial services. · Demonstrated experience managing an ISO 27001 program through implementation, internal audit, remediation, and external certification or surveillance audit. · Experience maintaining risk registers, compliance plans, audit evidence, corrective-action tracking, and executive reporting. · Experience with PCI DSS, central-bank requirements, privacy compliance, third-party assessments, BIA/BCP/DR, incident exercises, or regulatory reporting. · Practical involvement in SOC, vulnerability management, penetration testing, IAM, cloud-security, or architecture reviews. Language Requirements· English – professional working proficiency, including formal reports, policies, and executive presentations. Arabic is an advantage Pay: From AED1,000.00 per month Work Location: In person
Наблюдалась 2026-09-21, впервые 2026-09-20, источник — Indeed.