← Back to job listings
ER
Specialist, Data Privacy
Erel · Abu Dhabi, United Arab Emirates
About The Role
- Execute information security activities in accordance with approved policies, standards, and procedures.
- Perform assigned information security and governance tasks to support organizational compliance requirements.
- Contribute subject-matter expertise to information security initiatives within defined scope.
- Apply approved information security standards and controls across systems, processes, and documentation.
- Participate in information security awareness activities by providing domain input when required.
Information Security & Governance
- Perform information security and IT risk assessments within assigned scope and document results.
- Execute control checks against approved information security policies, standards, and regulatory requirements.
- Conduct third-party and vendor security assessments as assigned and document findings.
- Maintain compliance evidence and security documentation in line with regulatory and audit requirements.
- Analyze security control effectiveness and report observations through defined channels.
- Apply approved security policies and procedures in day-to-day operational activities.
Collaborate on Security Initiatives
- Coordinate with group-level stakeholders to support the implementation of security initiatives and action plans.
- Ensure alignment of security practices with industry standards and regulatory requirements.
- Apply group security playbooks and standards within the organization as directed.
- Provide technical and governance input related to information security controls and requirements.
- Identify control gaps or implementation issues and escalate through appropriate management channels.
- Contribute to continuous improvement by documenting lessons learned and operational observations.
Outsourced Cyber Security Services
- Support coordination with shared service providers responsible for IT and cybersecurity services.
- Monitor service delivery and assist in tracking compliance with contractual agreements and SLAs.
- Participate in security assessments and audits involving external service providers.
Data Protection & Privacy
- Perform data classification and protection activities in line with approved data protection requirements.
- Execute controls related to PII and PHI data security as defined by policies and procedures.
- Review data handling practices and document observations related to privacy compliance.
- Support identification and documentation of data protection risks and incidents.
Identity and Access Governance
- Preform Identity and Access Management governance activities, including onboarding, offboarding, access reviews, and recertification processes.
- Review privileged access and MFA controls and document compliance status.
- Maintain access governance records and supporting evidence.
Standard duties
- Execute information security tasks in accordance with approved group playbooks and operational procedures.
- Perform security monitoring, vulnerability tracking, and compliance checks within assigned scope.
- Maintain GRC documentation, risk registers, and compliance trackers.
- Perform control testing and evidence collection activities for audits and regulatory reviews.
- Track information security risks and remediation actions and report status through defined channels.
- Document information security incidents, root causes, and corrective actions as assigned.
- Prepare technical and governance inputs used by management for security reporting.
- Apply ISMS processes and contribute to continuous improvement activities.
- Coordinate operationally with shared services teams to execute assigned security activities.
- Support incident tracking, root cause analysis (RCA), and corrective action plans (CAPA).
- Bachelor’s degree in information technology, Information Security, or a related field.
- 3–6 years of experience in information security, IT governance, risk, or compliance roles.
- Knowledge of information security standards and frameworks such as ISO 27001, ADHICS, NESA IA, COBIT, or similar.
- Relevant professional certifications (e.g., ISO 27001, CISA, Security+, or equivalent) are an advantage.
- Strong execution capability in information security and governance activities.
- Ability to perform detailed assessments and document findings accurately.
- Good understanding of security controls, risk management, and compliance requirements.
- Ability to work within defined procedures, playbooks, and escalation paths.
- Strong analytical and documentation skills.
- Effective communication skills for reporting findings and observations.
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring