Skip to content
← Back to job listings

Senior Officer - Compliance & Assurance (Outsource)

ADIB · United Arab Emirates

Corporate LawExternal listingfull-timeabout 9 hours ago

About The Role

Role Purpose

The role is part of the Cyber Defense Center within Group Information Security Department (GISD) and is responsible for Data Loss Prevention monitoring, incident validation, governance and assurance activities to support ADIB's overall information security and data protection objectives.

The role supports the Head of Cyber Defense Center in ensuring effective monitoring and analysis of DLP events, performing L2 validation of incidents reviewed by L1 analysts, coordinating investigation and escalation of true-positive incidents, maintaining DLP dashboards and reporting, and continuously identifying opportunities to improve DLP monitoring and control effectiveness.

The role is also responsible for ensuring DLP monitoring processes and activities are performed in accordance with ADIB policies, approved procedures, privacy requirements and applicable regulatory obligations.

Key Accountabilities of the role

  • Monitor, analyze, and investigate DLP alerts and events across all relevant data transfer channels to identify potential data leakage, unauthorized transfers, policy violations, suspicious user activities, and information security risks, including detailed analysis of user activity, data classifications, transfer methods, destinations, historical behavior, related alerts, and potential business or customer impact.
  • Perform L2 review, validation, and quality assurance of DLP incidents handled by L1 analysts, ensuring accurate classification, risk assessment, evidence collection, incident disposition, adherence to procedures, escalation requirements, and investigation standards.
  • Review and validate false positives, permitted activities, and non-incidents, ensuring potentially material events are not closed without sufficient investigation, supporting evidence, and documented justification.
  • Identify, correlate, and conduct historical reviews of related DLP events involving common users, applications, destinations, files, data types, or activity patterns to detect recurring, linked, or previously unidentified incidents.
  • Escalate confirmed or suspected true-positive DLP incidents to relevant stakeholders, management, Security Incident Response Team, Privacy/Data Protection Team, Fraud Investigation Department (FID), and other parties in accordance with approved escalation and incident management procedures.
  • Coordinate investigations, containment, remediation, and closure activities with IT, business units, HR, Legal, Privacy, FID, Incident Response, and other stakeholders for DLP incidents and associated security, fraud, or privacy concerns.
  • Ensure appropriate containment, corrective, and preventive actions are implemented for confirmed incidents, including policy tuning, access restrictions, endpoint and network controls, data-transfer channel restrictions, compensating controls, and validation of remediation effectiveness.
  • Develop, maintain, and enhance DLP dashboards, reports, and management metrics covering alert volumes, incidents, severity trends, SLA performance, true/false positives, repeat violations, aging cases, business unit exposure, and monitoring effectiveness.
  • Perform trend, behavioral, and risk analysis to identify recurring violations, high-risk users, emerging data leakage threats, monitoring gaps, commonly abused transfer channels, and opportunities to strengthen preventive and detective controls.
  • Continuously improve DLP monitoring capabilities through policy enhancement, rule tuning, threshold optimization, use-case development, dashboard improvements, monitoring coverage validation, and assessment of technology limitations and compensating controls.
  • Conduct periodic validation and assurance reviews of monitoring filters, alert coverage, queues, workflows, and end-to-end DLP processes to ensure high-risk activities are detected, investigated, escalated, contained, and closed in accordance with defined requirements.
  • Capture lessons learned from incidents, audits, and assurance activities and incorporate them into DLP rules, procedures, awareness initiatives, training programs, and control enhancement efforts.
  • Provide guidance, coaching, and operational oversight to L1 analysts, identifying recurring quality issues and recommending procedural improvements, additional training, or monitoring enhancements.
  • Maintain governance and operational compliance of DLP monitoring activities, ensuring adherence to SOPs, SLAs, escalation matrices, incident classification criteria, investigation methodologies, and approved operating procedures.
  • Maintain comprehensive DLP documentation and evidence management practices, including procedures, use cases, escalation matrices, monitoring filters, investigation checklists, known limitations, incident records, audit trails, and supporting evidence throughout the incident lifecycle.
  • Support audits, regulatory reviews, assurance activities, and self-assessments, provide required evidence, identify compliance gaps, track remediation activities, and ensure timely closure of findings, observations, and corrective actions.
  • Ensure compliance with ADIB policies and applicable regulatory requirements, including Information Security, Data Classification, Acceptable Use, Incident Management, Privacy, Data Protection, CBUAE, UAE privacy regulations, approved exceptions, exclusions, and compensating control requirements.
  • Lead DLP awareness and technology enhancement initiatives, including targeted user awareness campaigns, secure data handling communications, testing and validation of new DLP capabilities, integrations, agents, policies, and maintaining awareness of emerging data exfiltration techniques, cloud services, collaboration platforms, and AI-related data leakage risks.

Specialist Skills / Technical Knowledge Required for this role

  • Strong expertise in Data Loss Prevention (DLP) monitoring, alert triage, incident analysis, investigation, validation, containment, remediation, governance, and control assurance.
  • In-depth understanding of data leakage and exfiltration risks across endpoint, email, web, network, cloud, collaboration platforms, removable media, and emerging technologies, with knowledge of sensitive-data classifications including customer, personal, confidential, and payment-card information.
  • Strong analytical and investigative capabilities with the ability to correlate security events, perform historical analysis, identify monitoring gaps, assess control weaknesses, and support security incident response and digital investigations.
  • Sound knowledge of cybersecurity frameworks, regulatory requirements, and industry best practices, including UAE banking regulations, data protection, privacy, and information security standards.
  • Hands-on knowledge of security technologies including DLP, SIEM, incident/case management, GRC platforms, and the ability to develop dashboards, metrics, trend analysis, and management reporting.
  • Strong stakeholder management, communication, documentation, and banking domain knowledge, with the ability to engage business and technical teams effectively and translate security risks into actionable outcomes.
  • Preferred Certifications: CISSP, CISM, CISA, CRISC, or other relevant information security certifications.

-

Education

  • Bachelor’s degree in engineering, Information Technology, Cybersecurity, Computer Science or any related technical discipline.

Previous Experience

  • More than 5 years of experience in information security, cybersecurity, information technology, risk or compliance, preferably within the banking or financial-services industry.
  • Relevant experience in Data Loss Prevention monitoring, data-security operations or information-security incident investigation.
  • Experience performing L2 review, incident validation or quality assurance of security alerts/incidents.
  • Experience in investigation, evidence review, incident escalation, containment coordination and corrective-action tracking.
  • Experience with information-security governance, control assurance, compliance assessments and audit support.
  • Experience preparing DLP/security dashboards and management reporting.
  • Experience coordinating with multiple stakeholders including Security Operations/Incident Response, Privacy, Fraud Investigation, business and technology teams.
  • Experience with DLP, SIEM, incident-management, case-management or GRC platforms.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing