Security Assurance Specialist (Ref: 198074)
- eTail
- Hybrid, Dubai, United Arab Emirates
- contract
- د.إ 25000.00 per month
-
about the roleAbout UsJob Description
The Security Assurance Specialist will provide structured, independent oversight of information security controls across a diverse retail, distribution and marketing environment. The role will examine whether controls are appropriately designed, implemented and supported by reliable evidence, then translate findings into clear conclusions for risk owners and governance stakeholders.
Success in this position means bringing consistency and challenge to remediation assessment while keeping recommendations practical and proportionate to risk. Working across technical teams, business stakeholders and GRC colleagues, you will help validate corrective actions, assess residual exposure and strengthen the organisation’s transition from project-based remediation into repeatable business-as-usual assurance.
Based in Dubai, the role will contribute to assessments covering security governance, technology controls and operational safeguards. Your work will support readiness activity, improve traceability between risks and controls, and provide senior stakeholders with dependable insight into the state of security assurance.
Key Responsibilities- Develop risk-based assurance plans covering priority security controls, remediation commitments and readiness milestones.
- Review control design against internal policies, standards, risk expectations and applicable assurance frameworks.
- Test implementation and operating effectiveness where sufficient operating history is available.
- Examine evidence for accuracy, completeness, relevance, ownership and alignment to the control being assessed.
- Record structured working papers and maintain an auditable link between risks, controls, actions, evidence and conclusions.
- Challenge incomplete, outdated or inconclusive submissions and define the additional evidence required.
- Issue concise assurance findings that distinguish control gaps, evidence weaknesses and residual-risk considerations.
- Engage action owners constructively while preserving the independence and objectivity of assurance activity.
- Reassess corrected controls and confirm whether remediation addresses the underlying weakness rather than only the immediate symptom.
- Escalate material, recurring or systemic deficiencies through the appropriate governance channels.
- Contribute assurance input to consolidated security reporting, risk dashboards and management updates.
- Assess control areas including identity and access management, privileged access, segregation of duties, vulnerability management, network security and operational resilience.
- Review relevant safeguards for supplier security, data protection, security operations and technology change activity.
- Support security readiness assessments during hypercare, transformation releases and other significant implementation phases.
- Apply recognised practices from ISO/IEC 27001:2022, NIST CSF and internal information security requirements consistently.
- Coordinate with GRC, security, technology and business teams to embed a sustainable business-as-usual assurance model.
Requirements- Several years of experience in information security assurance, technology risk, IT audit, internal controls or GRC.
- Demonstrated ability to assess whether security controls are suitably designed, implemented and operating as intended.
- Strong working knowledge of risk-based assurance principles and control testing methodologies.
- Practical understanding of ISO/IEC 27001 and NIST Cybersecurity Framework concepts.
- Experience evaluating technical and governance evidence and forming balanced, well-supported conclusions.
- Knowledge of identity and access management, privileged access, segregation of duties, vulnerability management, network protection, resilience, supplier risk, data protection and security operations.
- Ability to work effectively with control owners, engineers, auditors, risk professionals and senior stakeholders.
- Excellent analytical skills, professional judgement and written communication capability.
- Confidence working independently, organising multiple assessments and maintaining accurate assurance records.
- Experience supporting ERP, SAP or complex technology transformation programmes would be advantageous.
- Exposure to retail, distribution, marketing services or other multi-site, customer-facing operating environments would be beneficial.
- Relevant certification such as CISA, CISM, CISSP, CRISC, ISO/IEC 27001 Lead Auditor or Lead Implementer is preferred.
BenefitsOther
-
SFCC Business Analyst (Ref: 198073)Hybrid, Dubai, United Arab Emirates
-
Security Delivery Manager (Ref: 198076)Dubai, United Arab Emirates
-
Scrum Master (Ref: 198072)Hybrid, Dubai, United Arab Emirates
-
Security Business Analyst (Ref: 198075)Dubai, United Arab Emirates
-
Lead Security Enterprise Architect (Ref: 197578)Dubai, United Arab Emirates
RELATED JOBS
-
Project Manager (Ref: 197822)About UsOperating in the energy, utilities and waste sector, our client supports the delivery and management of essential services within a complex and highly regulated environment ...
-
Director of Contact Centre & Customer Experience (Ref: 197896)About UsOperating across retail, consumer services and food and beverage manufacturing, our client serves customers through a business model where dependable service, accessible su ...
-
Forward Deployed Engineer (Ref: 198089)About UsOur client develops software that removes friction from medical billing, helping healthcare providers manage complex financial workflows and receive payment more efficientl ...