Line of Service
Internal Firm ServicesIndustry/Sector
Not ApplicableSpecialism
IFS - Risk & Quality (R&Q)Management Level
DirectorJob Description & Summary
As the PwC Middle East CISO you will work across the Middle East firms to continue to drive the maturation of the member firm information security risk posture based on global strategy, member firm business requirement and risk appetite. You will be responsible for driving the Network Information Security (NIS) strategy within the Middle East territories and will act as the common link between local leadership and global NIS functions for all information security-related topics.Define, develop and maintain an information security strategy and operating model that is aligned to our Network Information Security strategy and local business requirements;
Drive and deliver change to our information and cyber security systems, processes and procedures by identifying growth opportunities, continuously analysing and reviewing new security technologies and practices as informed by industry best practice;
Identify, plan for and communicate projects/work packages to stakeholders and governance groups;
Regularly report to leadership stakeholders via various governance forums on information and cyber security matters;
Lead a team of security professionals at various grade levels, across multiple specialisms, to deliver expertise to provide security assurance to the ME firm, whilst supporting our technology growth ambitions;
Provide coaching and feedback to foster a culture of innovation and continuous improvement that encourages a high level of professional development and personal responsibility;
Ensure that the culture, policies, structures and reporting systems are in place to allow the CISO team to achieve the highest standards of quality, legal and regulatory compliance and corporate governance in all areas;
Establish and maintain clear and measurable Information and cyber security performance indicators and deliver measurable service improvements to ensure that all elements of our services represent the best value for money;
Ensure that information and cyber security risks are identified and managed appropriately;
Lead on development and delivery of measures and metrics to support the assessment, reporting and ongoing improvement of our information security posture;
Ensure and promote an appropriate level of information security culture and awareness across the firm;
Direct, and assist as necessary, investigations into information security incidents.
The right candidate will possess the following skills:
A collaborative leader with strategic acumen and problem-solving skills, able to inspire and motivate;
Proven people management experience to provide coaching and development for others to maximise their potential.
A self starter with the ability to lead and drive change through an organisation - cutting through organisational and political barriers to achieve the desired goal;
Problem-solver who can prioritise and identify problems and make quick, sound decisions by applying independent judgement and by collaborating with others;
Proven record of managing multi-function relationships throughout major transformation and collaborating with multiple stakeholders across functional and technical skill sets to identify, build and maintain security capabilities or controls.
Build consensus and collaborate with a range of stakeholders including global information security experts, technology specialists and risk teams;
Ability to be pragmatic while balancing the needs of the firm against security;
Proven record of success, supporting and/or coordinating Information Security Governance to enhance to decrease repeat findings and issues, and make other process efficiency improvements.
Extensive understanding of technology and how security is applied to technology in an enterprise setting;
An ability to think and plan strategically and systematically while recognising the need to deliver to the business; requirements;
Excellent communication skills – both oral (for interviews/meetings/presentations) and written (for designing and writing engaging reports which communicate findings succinctly and clearly convey the message);
Able to present complex or highly technical issues in simple and easy-to-understand formats;
Inquisitive nature and intuition regarding what questions to ask, when, and their relative significance;
Ability to frame threats and exposures in a business context recognised by non-technical staff and executives;
Understanding of PwC’s business model, service offerings, and business operating environment as it pertains to the firm’s threat landscape;
Experience providing expert strategy, risk and technical advice, guidance and support on cyber security matters.
Education (if blank, degree and/or field of study not specified)
Degrees/Field of Study required:Degrees/Field of Study preferred:Certifications (if blank, certifications not specified)
Required Skills
Optional Skills
Desired Languages (If blank, desired languages not specified)
Travel Requirements
Up to 20%Available for Work Visa Sponsorship?
NoGovernment Clearance Required?
NoJob Posting End Date
At PwC, our purpose is to build trust in society and solve important problems. We’re a network of firms in 152 countries with over 327,000 people who are committed to delivering quality in assurance, advisory and tax services. Find out more and tell us what matters to you by visiting us at www.pwc.com. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity.
Content on this page has been prepared for general information only and is not intended to be relied upon as accounting, tax or professional advice. Please reach out to your advisors for specific advice.