6 дней назад
Security Assurance Specialist
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Assurance Specialist (Cybersecurity): Assessing the design, implementation, operation, and evidence of information security controls across retail, distribution, and marketing environments with an accent on risk-based assurance, control testing, and remediation validation. Focus on maintaining auditable links between risks, controls, evidence, and conclusions, evaluating residual exposure, and strengthening business-as-usual security assurance.
Location: Based in Dubai, United Arab Emirates
Company
Security assurance work supporting retail, distribution, marketing, technology, and business operations.
What you will do
- Develop risk-based assurance plans covering priority security controls, remediation commitments, and readiness milestones.
- Review control design and test implementation and operating effectiveness against internal policies, standards, risk expectations, ISO/IEC 27001:2022, and the NIST Cybersecurity Framework.
- Evaluate the accuracy, completeness, relevance, ownership, and alignment of evidence, maintaining auditable links between risks, controls, actions, evidence, and conclusions.
- Issue clear assurance findings, challenge incomplete submissions, assess residual exposure, and validate that remediation addresses underlying weaknesses.
- Assess controls across identity and privileged access, segregation of duties, vulnerability management, network security, resilience, supplier security, data protection, security operations, and technology change.
- Coordinate with GRC, security, technology, business, and control-owner teams while contributing to security reporting, dashboards, and readiness assessments.
Requirements
- Several years of experience in information security assurance, technology risk, IT audit, internal controls, or GRC.
- Ability to assess whether security controls are suitably designed, implemented, and operating as intended.
- Strong knowledge of risk-based assurance principles, control testing methodologies, ISO/IEC 27001, and NIST Cybersecurity Framework concepts.
- Experience evaluating technical and governance evidence and forming balanced, well-supported conclusions.
- Knowledge of identity and access management, privileged access, segregation of duties, vulnerability management, network protection, resilience, supplier risk, data protection, and security operations.
- Strong analytical, organisational, written communication, professional judgement, and stakeholder-management skills.
Nice to have
- Experience supporting ERP, SAP, or complex technology transformation programmes.
- Exposure to retail, distribution, marketing services, or other multi-site customer-facing environments.
- Certifications such as CISA, CISM, CISSP, CRISC, ISO/IEC 27001 Lead Auditor, or Lead Implementer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →