The Information Security Lead is responsible for driving the organization's information security program by acting as a supervisory and control organization on top of the security engineering division.
Requirements
- Supervise security engineering practices and ensure their secure, efficient operations.
- Lead the development, implementation, and continuous improvement of the organization's information security program.
- Oversee identity and access management (IAM) strategies, tooling, and implementation.
- Define and monitor key performance indicators to measure technical security maturity, control effectiveness, and overall capabilities progress of the security program.
- Lead on the security awareness training program, tooling, and continuous KPI improvement.
- Provide strategic guidance on the security implications of business initiatives, projects, and technology choices.
- Implement and maintain automated supervision tooling (e.g., Sprinto or custom integrations) to support governance reporting.
- Establish and maintain technical security guidelines, policies, standards, and procedures aligned with business needs, regulatory obligations (e.g., CMA, ADGM, FRA), and frameworks such as ISO 27001, NIST CSF, and PCI DSS.
- Manage, maintain, and evolve the information security risk register and risk management framework (e.g., NIST RMF).
- Lead, mentor, and develop members of the information security team.
- Serve as a trusted advisor to senior management on information security posture.
- Prepare clear, actionable reports and recommendations for executive stakeholders and governance committees.
