FIND_THE_RIGHTJOB.
JOB_REQUIREMENTS
Hires in
Not specified
Employment Type
Not specified
Company Location
Not specified
Salary
Not specified
Accountable for establishing and governing the enterprise cybersecurity architecture. The role sets the target architecture, standards and roadmap, evaluates and introduces emerging security technologies, and assists in major incident response. The architecture team, under this leadership, conducts threat modeling, design reviews and risk assessments, maintains architecture artifacts, embeds security in the SDLC and change management processes, and handles routine system access and authorization requests. Together they ensure secure systems, stronger resilience and reduced risk. The role aligns all activities with recognised frameworks (ISO 27001, SANS/CIS Controls, NIST CSF, MITRE ATT&CK) and regulatory requirements (Dubai ISR, Dubai Data Privacy Law) to reduce risk and strengthen resilience.
Key ResponsibilitiesDefine and maintain the target security architecture, standards and multiyear roadmap aligned to business objectives and risk appetite.
Enforce design principles (e.g., secure by design, zero trust, least privilege) and evaluate high risk or exception designs, ensuring mitigations and acceptable residual risk before authorization.
Direct and quality assure threat modeling, solution design reviews and risk assessments performed by the architecture team using methodologies such as STRIDE and MITRE ATT&CK.
Embed security requirements, checkpoints and automation (DevSecOps) across the Software Development Life Cycle to ensure consistent secure delivery.
Integrate security review into change processes, ensuring risk assessment and appropriate controls for technology changes.
Monitor system access and authorization activities, intervening and approving complex or exceptional requests to enforce segregation of duties and least privilege.
Set architectural security requirements for suppliers and review designs to manage supply chain and integration risks.
Ensure architectures meet internal policies and external obligations including Dubai ISR, Dubai Data Privacy Law, ISO 27001 and related standards.
Define and report KPIs/KRIs on architecture adoption, risk reduction and control coverage to senior stakeholders.
Translate complex security architecture issues into clear business impact narratives for executives and project teams.
Lead, mentor and develop the security architecture team, fostering continuous improvement, knowledge sharing and succession readiness.
Similar jobs
MUFG – UAE – DIFC Branch
Dubai, United Arab Emirates
36 minutes ago
Johnson Controls
Dubai, United Arab Emirates
about 4 hours ago
ATHGADLANG
Dubai, United Arab Emirates
about 4 hours ago
Marsh McLennan
Dubai, United Arab Emirates
6 days ago
Ras Infotech Limited
Dubai, United Arab Emirates
6 days ago
Veloche Interior and Exhibition
Dubai, United Arab Emirates
6 days ago
© 2025 Qureos. All rights reserved.