Назад
Company hidden
6 дней назад

Security Assurance Specialist

Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
UAE
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Assurance Specialist (Cybersecurity): Assessing the design, implementation, operation, and evidence of information security controls across retail, distribution, and marketing environments with an accent on risk-based assurance, control testing, and remediation validation. Focus on maintaining auditable links between risks, controls, evidence, and conclusions, evaluating residual exposure, and strengthening business-as-usual security assurance.

Location: Based in Dubai, United Arab Emirates

Company

Security assurance work supporting retail, distribution, marketing, technology, and business operations.

What you will do

  • Develop risk-based assurance plans covering priority security controls, remediation commitments, and readiness milestones.
  • Review control design and test implementation and operating effectiveness against internal policies, standards, risk expectations, ISO/IEC 27001:2022, and the NIST Cybersecurity Framework.
  • Evaluate the accuracy, completeness, relevance, ownership, and alignment of evidence, maintaining auditable links between risks, controls, actions, evidence, and conclusions.
  • Issue clear assurance findings, challenge incomplete submissions, assess residual exposure, and validate that remediation addresses underlying weaknesses.
  • Assess controls across identity and privileged access, segregation of duties, vulnerability management, network security, resilience, supplier security, data protection, security operations, and technology change.
  • Coordinate with GRC, security, technology, business, and control-owner teams while contributing to security reporting, dashboards, and readiness assessments.

Requirements

  • Several years of experience in information security assurance, technology risk, IT audit, internal controls, or GRC.
  • Ability to assess whether security controls are suitably designed, implemented, and operating as intended.
  • Strong knowledge of risk-based assurance principles, control testing methodologies, ISO/IEC 27001, and NIST Cybersecurity Framework concepts.
  • Experience evaluating technical and governance evidence and forming balanced, well-supported conclusions.
  • Knowledge of identity and access management, privileged access, segregation of duties, vulnerability management, network protection, resilience, supplier risk, data protection, and security operations.
  • Strong analytical, organisational, written communication, professional judgement, and stakeholder-management skills.

Nice to have

  • Experience supporting ERP, SAP, or complex technology transformation programmes.
  • Exposure to retail, distribution, marketing services, or other multi-site customer-facing environments.
  • Certifications such as CISA, CISM, CISSP, CRISC, ISO/IEC 27001 Lead Auditor, or Lead Implementer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →