Manager – Cyber
2 weeks ago
Job Purpose:
The Manager – Cyber & Information Security (InfoSec) Operations supervises the bank's cyber defense operations, ensuring timely detection, response, and resolution of security incidents. He/ She operates incident handling, digital forensics, and third-party cybersecurity coordination while maintaining compliance with regulatory and internal security frameworks.
The Manager – Cyber & InfoSec Operations supports key operational security controls, drives continuous improvements in threat response, and collaborates with stakeholders to safeguard the bank's information assets across platforms and vendors.
Key Accountabilities:
- Manages the full lifecycle of cybersecurity incident response including detection, triage, containment, eradication, recovery, and post-incident review.
- Conducts forensic investigations of compromised systems and preserves digital evidence for compliance and legal use.
- Updates and tests the incident response plan and playbooks to ensure readiness.
- Investigates security incidents such as unauthorized access, insider threats, and external attacks.
- Interfaces with MSSPs and third-party vendors for alert triage, escalation, and monitoring performance.
- Optimizes SIEM rules, detection logic, and response workflows with vendors and internal teams.
- Conducts regular meetings with vendors to review SLAs, resolve issues, and improve service levels.
- Evaluates emerging cybersecurity technologies and engages with vendors to enhance capabilities.
- Conducts risk assessments, vulnerability scans, and penetration testing to identify and mitigate threats.
- Implements and maintains the Bank's information security program in compliance with regulatory and business standards.
- Develops and enforces cybersecurity policies, standards, and procedures in alignment with frameworks (ISO 27001, CBO, MTCIT).
- Manages ISO 27001 certification efforts and maintains ISMS documentation and audit readiness.
- Maintains the cybersecurity risk register, audit findings, and remediation tracking.
- Performs user access reviews and privileged access reviews for critical systems in compliance with RBAC and regulatory requirements.
- Manages enforcement of PAM controls and maintains evidence of periodic access reviews.
- Approves firewall, system, and administrative access changes as the designated ISO authority.
- Coordinates with HR to manage onboarding and offboarding access controls for staff, vendors, and contractors.
- Provides security input for new IT and business projects, ensuring risk mitigation is embedded in solution design.
- Conducts security assessments, architectural reviews, and integration support for new systems.
- Communicates incident updates, risks, and resolutions to stakeholders across IT, Legal, Compliance, and Business Units.
- Develops and delivers cybersecurity awareness and training programs to staff.
- Fosters a culture of accountability, proactive defense, and information security ownership.
- Leads cyber drill simulations and incident response exercises to improve response capabilities.
- Ensures compliance with data protection regulations and internal privacy policies.
- Develops and maintains privacy notices, consent forms, and data handling procedures.
- Manages data subject access requests and leads investigations into privacy-related incidents.
- Acts as the main liaison with Data Protection Authorities during audits or investigations.
- Executes the information security roadmap aligned with enterprise risk strategy.
- Ensures ongoing adherence to cybersecurity best practices, regulatory mandates, and corporate security policies.
- Maintains high standards of professionalism, accuracy, and integrity in all operational duties.
- Collaborates with internal functions to sustain an enterprise-wide security and privacy posture.
Qualifications and Experience:
- Bachelor Degree in Information Security, Cybersecurity, Information Systems or a related field.
- Professional certification in Information Security such as: GCIH, GCFA, GCFE, CISSP, CEH, CISM, ISO is preferred.
- Minimum of 4 years of experience with at least 2 years in a banking or a regulated environment.
- Familiarity with using cybersecurity tools such as SIEM, EDR and forensic platforms.
- Demonstrates familiarity with country-specific information security regulations and expertise.
- Strong knowledge of related ISO such as ISO 27001 and related global standards.
- Ability to conduct risk assessments, vulnerability assessments and penetration testing.
- Ability to develop IS standards, procedures and controls.
Applicants who are meeting the job requirements will be contacted.
** Applications will be accepted until 02-Nov-2025 at 2:00 P.M
Submissions received after this date and time will not be considered **
-
Autonomous Security Engineer
4 days ago
Muscat, Muscat, Oman Vodafone Oman Full time 40,000 - 120,000 per yearRole purpose:Vodafone is Oman's latest Network Operator. The presence of Vodafone in Oman will contribute to the development of all sectors, including the economic and educational sectors, and in line with Oman Vision 2040.Our purpose is to 'Connect for a Better Future 'which underpins everything we do. Our solutions will positively impact society as we...
-
Cyber Security Specialist
6 days ago
Muscat, Muscat, Oman AWASR Full time 30,000 - 60,000 per yearJob description:POSITION INFORMATIONDivision: Network & Digital Department:Security Role Designation: Cybersecurity SpecialistROLE PURPOSEThe Cybersecurity Specialist, under the supervision of the Manager Cybersecurity Operation, is in charge of developing, executing, and overseeing security measures to safeguard AWASR's infrastructure and data. This...
-
Manager
4 days ago
Muscat, Muscat, Oman RP International Full time 120,000 - 240,000 per yearManager of Technology Risk, Information Technology.The role is responsible for leading the identification, evaluation, and mitigation of technology-related risks within a banking environment. This includes ensuring that risks across the technology landscape are recognized, assessed, and managed in line with established risk management frameworks and...
-
Manager Digital Products
4 days ago
Muscat, Muscat, Oman Oman Investment Authority Full time 120,000 - 240,000 per yearOwn the digital products portfolio, including roadmap definition, lifecycle governance, and retirement planning.Develop business cases, pricing models, and platform value propositions for each product line.Monitor portfolio P&L (shadow revenue, margin contribution, product profitability) and present updates to leadership.Maintain alignment between Onetech s...
-
Lead SCS Engineer
1 week ago
Muscat, Muscat, Oman dc53e74d-498b-4796-94d0-82bf16d145d0 Full time 120,000 - 180,000 per yearJob Description SummaryThis position is responsible for handling all SCS/CS activities in the field for all GEV-GA projects, including on-shore, off-shore, in Oman.He will closely coordinate his activities with SCS Engineering & Field Service team, Project management, Application and After Sales.This position will report to GA Gulf Cluster Engineering &...
-
SOC Team Lead
2 weeks ago
Muscat, Muscat, Oman Oman Investment Authority Full timeDefine and execute the SOC strategy, ensuring alignment with MSSP objectives, MDR services, and client security needs while driving continuous service improvement.Oversee and optimize SOC service delivery, ensuring operational excellence, SLA compliance, and regulatory alignment.Review and approve SOC service proposals, ensuring alignment with business...
-
Lead SCS Engineer
1 week ago
Muscat, Muscat, Oman GE Vernova Full time 60,000 - 120,000 per yearJob Description SummaryThis position is responsible for handling all SCS/CS activities in the field for all GEV-GA projects, including on-shore, off-shore, in Oman.He will closely coordinate his activities with SCS Engineering & Field Service team, Project management, Application and After Sales.This position will report to GA Gulf Cluster Engineering &...
-
Specialist - Security Special Projects
4 days ago
Muscat, Muscat, Oman AWASR Full time 40,000 - 80,000 per yearJob description:POSITION INFORMATION :Division: Network & Digital Department:Security Role Designation: Specialist - Security Special Projects ROLE PURPOSE :The Security Special Projects Specialist, reporting to the Manager of Security Special Projects, is responsible for monitoring, deploying, and Managing security special projects solutions to ensure...
-
Sr. Specialist IDS Risk, DR
6 days ago
Muscat, Muscat, Oman OQ Full time 60,000 - 120,000 per yearJob purposeProvides end-to-end subject matter expertise and execution capabilities across the domains of technology risk management, disaster recovery, and regulatory compliance. The role supports the development and implementation of frameworks, policies, and practices that protect OQ's digital infrastructure and ensure operational resilience.The position...
-
Sr Specialist IDS Risk, DR
1 week ago
Muscat, Muscat, Oman OQ Full time 120,000 - 180,000 per yearJob titleSr. Specialist IDS Risk, DR& ComplianceGradeStreamPeople & TechnologyFunctionCorporate IDSLocationOman – Muscat Budget control*OPEX and/or CAPEX and/or Revenue amount asrelevant*Reporting toManager IDS Governance & ExcellenceDirect reports0Job purpose Provides end-to-end subject matter expertise and execution capabilities across the domains of...