Chief Specialist - Information Security
Dubai Culture & Arts Authority ·
- Seniority
- C level
- Category
- Security
Senior information-security specialist at Dubai Culture & Arts Authority who sets Authority-wide security strategy and risk frameworks, runs SOC and incident-response operations, oversees VAPT and audits, governs access, and maintains security policies and compliance.
Strategy
- Develop and implement information-security strategies and operating models aligned with laws, regulations, and Authority needs.
- Define the risk framework\: maintain registers, scenarios, and response plans with accountable owners and escalation paths.
- Set Authority-wide security programs and technical standards across sectors to embed best practices consistently.
- Evaluate emerging technologies and threat trends and issue strategic recommendations to improve security systems and infrastructure.
- Coordinate with departments to align cybersecurity strategies and work plans with organizational objectives.
Operations
- Lead in-depth analysis of security incidents, direct incident-response activities, and strengthen digital forensics and investigation quality.
- Plan and coordinate Security Operations Centre (SOC) operations and response workflows with internal and external stakeholders.
- Support and advise team leads in the development and management of the organization’s Vulnerability Assessment and Penetration testing (VAPT) plan and building VAPT tools and frameworks.
- Oversee the conduct of readiness evaluations and penetration tests; recommend preventive and corrective actions and track closure.
- Review architectures for new initiatives and system changes; prescribe security controls during design and implementation.
- Govern access and privileges\: apply eligibility/approval procedures, review entitlements, monitor network/system activity, and report compliance.
- Execute risk-based audits of technical systems and projects; evaluate control effectiveness and drive corrective plans.
- Assess new technology projects for alignment with cybersecurity strategy and risk profile; provide improvement recommendations.
- Manage security assessments of external suppliers and partners and ensure compliance with required security standards.
- Execute additional Information Security duties assigned by leadership beyond the defined Section scope.
Product/Process Improvement
- Maintain risk registers and mitigation plans; analyse performance metrics and report system effectiveness and residual risks.
- Manage and update cybersecurity documentation, including policies, procedures, contingency plans, and ensure legal and regulatory compliance.
- Prepare and refine emergency/incident response and recovery plans via exercises and lessons learned.