Head of Information Security
Location: Ras-Al-Khaimah
Qualifications, Experience & Skills
- Minimum 12 years of overall IT experience, including at least 8 years in Information Security and 4 years in a senior leadership or managerial role with responsibility for driving security initiatives across multiple functions and managing security teams.
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Electrical Engineering, or a related technical field is required. A Master’s degree is preferred.
- Mandatory certification in at least one of the following: CISSP, OSCE3, or GSE. Candidates without these certifications must demonstrate equivalent hands-on technical expertise and may be evaluated accordingly.
- Preferred certifications include OSCP, GCIA, GCIH, GCFE, GCFA, CISM, ISO 27001 Lead Implementer/Auditor, and ISO 22301 Lead Implementer/Auditor.
- Microsoft Azure security certifications such as AZ-500 or SC-100 are highly desirable. Knowledge of IEC 62443 standards for OT security is an advantage.
Technical Competencies
- Security Architecture: Expertise in designing and assessing enterprise security architectures across hybrid and multi-cloud environments, including Zero Trust, SSE/SASE, API security, PKI, encryption, and attack-path modeling.
- Identity & Access Management: Strong hands-on experience with Active Directory hardening, privileged access management (PAM), Entra ID, cloud IAM solutions, and mitigation of advanced identity-based attacks such as DCSync, Kerberoasting, Golden Ticket, and Pass-the-Hash.
- SOC & Threat Detection: Proven experience leading Security Operations Centers (SOC), implementing and optimizing SIEM platforms (Microsoft Sentinel, Splunk, QRadar, etc.), EDR solutions, threat detection use cases, and incident response workflows.
- Incident Response: Extensive experience managing the full incident response lifecycle, including detection, containment, eradication, recovery, forensic evidence handling, stakeholder communication, and regulatory reporting.
- Vulnerability Management & Threat Hunting: Hands-on experience overseeing vulnerability assessments, penetration testing, remediation governance, threat hunting programs, and MITRE ATT&CK-based security operations.
- Digital Forensics & Incident Response (DFIR): Ability to lead compromise assessments, collaborate with forensic teams, analyze forensic findings, and translate outcomes into remediation programs.
- Security Governance & Business Continuity: Strong background in implementing and managing ISMS aligned with ISO 27001, conducting risk assessments, vendor risk management, policy development, and BCM programs aligned with ISO 22301.
- OT Security: Understanding of OT and operational infrastructure security requirements, including the application of risk-based controls while maintaining operational availability.
- Technology Stack Experience: Firewalls, IPS/IDS, F5 WAF, DDoS protection, email security gateways, Microsoft M365 E5, Defender, MDM, cloud security platforms, CASB, Palo Alto Prisma, Zscaler, CyberArk, BeyondTrust, Entra ID, Active Directory, SAP BTP security, API security, and awareness of OT/ICS protocols and IEC 62443 frameworks.
