Specialist Cybersecurity Risk Management (UAE National Only)
Job Description
Specialist - Cybersecurity Risk Management
Embark on a journey where your unique contributions are celebrated, and your professional growth is embraced. At ADCB, we nurture a diverse, inclusive community where every voice is valued.
About the business area - Group Risk Management
ADCB prioritises a disciplined approach to risk, recognising its fundamental importance to the Bank's long-term organisational and financial resilience. Group Risk Management oversees the implementation of ADCB's risk objectives, identifying and addressing gaps in the bank's risk infrastructure/framework.Their responsibilities include nurturing the independence of the risk function, establishing provisioning policies, and introducing changes to energise risk awareness among front office personnel and decision-makers. Continuously tuning the risk organisation in line with market best practices, they manage ADCB's portfolio and associated risks to international standards, while establishing a clear risk culture across all areas of operation.
In this role, your key responsibilities include:
- Conduct risk assessments in line with the security risk management framework, compliance, regulatory requirements, global security best practices, threat profile and enterprise risk framework to ensure that business and system risk are managed/aligned with established framework.
- Ensure the Bank's information security risks are managed appropriately, defining the risk appetite to ensure they are maintained at an acceptable level within the Banks risk limits.
- Monitor and follow-up open risk issues with risk owners, validating the closure of risks and support identifying risk mitigation controls across all business units to ensure compliance and closures of all identified risks.
- Conduct Third party risk assessments as per established third party risk management framework, monitoring third party risk on a continuous basis to ensure that the information security risks related to outsourcing activities for ADCB are kept at an acceptable level.
- Assist in conducting offensive security related activities such a Red Teaming, Penetration Testing, Breach and Attack Simulation to ensure that controls are working as expected and no vulnerabilities are available to ensure that ADCB controls are working as intended and there are no vulnerabilities present.
- Co-ordinate with Risk Owners, conducting regular follow-up of the open risk issues to ensure line managers are updated on the status of open risk issues that enable the implementation of appropriate actions and ensure compliance with standards such as Payment Card Industry – Data Security Standard (PCI-DSS) and International Organisation for Standardisation (ISO) 27001.
- Assist in the production of dashboards, reporting on the risk status in order to provide necessary support on risk mitigation.
- Provide input and feedback to the Technology Security team for Business Projects, developing security policies, updating and creating security baseline documents for various IT Technologies to ensure accuracy of data provided.
- At least 4 years of experience in a Banking industry or similar environment.
- Bachelor's Degree in Computer Science/Cyber Security/Information Security or equivalent.
- Certification in Information Security such as CompTIA Security+, Systems Security Certified Practitioner (SSCP) Associate, Information Systems Audit and Control Association (ISACA) Cyber Security Fundamental Certificate or Certified Ethical Hacker.
- Knowledge in information security, specifically in risk/vulnerability assessment, cloud security, third party security assessment, and industry standard frameworks such as ISO 27001, PCI-DSS, UAE Information Assurance Standard, SWIFT Customer Security Controls Framework
- Knowledge of security and networking
- Knowledge of Banking operations
- Awareness of application security requirements and techniques
- Knowledge of enterprise security architecture design
- Understanding of Intellectual Property (IP), Transmission Control Protocol/Internet Protocol (TCP/IP), and other network administration protocols
- Knowledge and ability to apply Risk Management techniques to security policy enforcement and compliance
What we offer:
- Competitive Salary & Additionally, all employees are eligible to participate in one of our rewarding variable pay plans.
- Comprehensive Benefits Package: This includes market-leading medical insurance, group life and personal accident insurance, paid leave and leave airfare, employee preferential rates on loans and finance facilities, staff discounts and offers, and children education assistance (for certain job levels).
- Flexible and Remote Working Options: We understand the importance of work-life balance and offer flexible working arrangements, subject to eligibility and job requirements.
- Learning and Development Opportunities: We value and facilitate continuous learning and personal development through a variety of exciting learning opportunities, such as structured instructor-led courses, a comprehensive e-learning catalog, on-the-job training, and professional development programs.
At ADCB, we are dedicated to creating a respectful, caring and disciplined work environment that aligns with your career ambitions.