Seeking an Information Security & Data Privacy Specialist to be deployed onsite with a leading financial institution in support of the Bank s Non-Financial Risk function. The role delivers advisory and execution support across information security, data privacy, and data protection in alignment with CBK, CBUAE/DFSA, and international regulatory expectations.
Key Responsibilities:
- Review and segregate information security and data privacy policies in line with CBK and CBUAE/DFSA regulations, producing a policy review report highlighting jurisdictional differences and required amendments.
- Perform card discovery scans to identify cardholder data across approximately 3,500 Workstations and servers.
- Support information security risk assessments across 250+ information assets, per the ISMS Risk Assessment Methodology.
- Assist in conducting a CBUAE NESA current-state assessment and develop the associated remediation action plan.
- Support Information Security Risk Reviews aligned with ISO 27001, PCI DSS, and SWIFT CSP controls.
- Perform Privacy Impact Assessments (PIAs) across approximately 180 banking applications/systems.
- Perform Privacy by Design assessments as per CORF across the same application population.
- Document Records of Processing Activities (RoPA) across 20 divisions and 170 sub-divisions.
- Maintain and update the Bank s Data Privacy system records.
- Prepare weekly/monthly progress reports aligned with the Information Security/Data Privacy plan.
Desired Candidate Profile
- 5 – 7 years of experience in Information Security and 3 – 5 years in Data Privacy.
- ISO 27001 / ISO 27701 Lead Auditor or Lead Implementer certification (Information Security/Data Privacy).
- CIPM / CIPP certification (Privacy).
- CISM / CISA certification (Information Security).
- Working knowledge of PCI DSS, SWIFT CSP, and central bank regulations (CBK / CBUAE / DFSA) relating to information security and data privacy.
- Strong knowledge of the ISO 31000 standard and GDPR / regional data privacy requirements.