Quick Summary
Job Purpose Lead and manage the organization's information security function across hybrid infrastructure environments, including on-premises and Microsoft Azure platforms,
Job Purpose
Lead and manage the organization's information security function across hybrid infrastructure environments, including on-premises and Microsoft Azure platforms, by developing and implementing security strategies, governance frameworks, and risk management practices. Ensure the protection of business systems, data, and technology assets, maintain compliance with regulatory requirements, oversee the integration of security into IT operations and projects, and collaborate with stakeholders to strengthen cybersecurity resilience and support DP World's strategic business objectives.
Key Accountabilities
- IT Security Governance and Compliance
- Provide strategic leadership for the development, implementation, and continuous improvement of information security policies, standards, governance frameworks, and controls in alignment with the DP World cybersecurity program and corporate security strategy.
- Ensure organizational compliance with applicable cybersecurity governance frameworks, regulatory obligations, internal security standards, and all security requirements mandated by the Tartus Port Authority.
- Serve as the principal local representative for DP World cybersecurity, driving the adoption of corporate security strategies, policies, and initiatives across the organization.
- Provide governance and oversight for internal and external security audits, regulatory inspections, compliance assessments, and certification activities, ensuring timely closure of findings.
- Monitor and report on the organization's security compliance posture, governance maturity, key risk indicators, and control effectiveness to executive management and regional cybersecurity leadership.
- Ensure appropriate governance of security policies, standards, procedures, audit evidence, and compliance documentation.
- Partner with regional cybersecurity leadership and business stakeholders to strengthen governance, address compliance gaps, and drive continuous security improvement.
- Advise executive and operational management on security governance obligations, regulatory developments, and cybersecurity compliance risks affecting the business.
- Foster a culture of security awareness, accountability, and regulatory compliance throughout the organization.
2. Risk Management
- Lead the organization's cybersecurity risk management program in alignment with the DP World enterprise risk management framework and governance methodology.
- Direct cybersecurity risk assessments, control evaluations, and risk treatment activities to ensure effective identification and management of business and technology risks.
- Provide oversight of the identification, assessment, documentation, prioritization, and escalation of cybersecurity risks impacting business operations and critical infrastructure.
- Ensure cybersecurity risks are appropriately communicated, managed, and integrated into organizational decision-making processes.
- Oversee the development, maintenance, and reporting of cybersecurity risk registers while providing strategic input into enterprise risk governance.
- Monitor the evolving threat landscape and emerging cybersecurity risks, ensuring timely escalation and executive visibility where appropriate.
- Review the effectiveness of risk mitigation strategies and ensure accountability for the timely resolution of identified control deficiencies.
- Present cybersecurity risk posture, emerging threats, and mitigation progress to executive management and regional cybersecurity leadership.
3. Vulnerability Management
- Provide strategic oversight of the organization's vulnerability management program, ensuring alignment with DP World cybersecurity standards and enterprise risk objectives.
- Direct the planning and governance of vulnerability assessments, security scanning, penetration testing, and technical assurance activities across infrastructure, applications, operational technology, and cloud environments.
- Establish risk-based remediation priorities and ensure effective coordination between technology teams, business stakeholders, and regional cybersecurity functions.
- Monitor remediation performance against defined service levels, holding stakeholders accountable for the timely resolution of critical vulnerabilities.
- Ensure appropriate governance over vulnerability exceptions, residual risk acceptance, and remediation validation activities.
- Oversee vulnerability reporting, trend analysis, key performance indicators, and executive dashboards to measure program effectiveness and support informed decision-making.
- Drive continuous improvement of vulnerability management processes through governance, performance monitoring, and lessons learned.
4. Identity and Access Management (IAM)
- Provide governance of the organization's Identity and Access Management (IAM) framework in accordance with corporate security policies and industry best practices.
- Ensure effective governance of user lifecycle management, including access provisioning, modification, and de-provisioning across enterprise platforms.
- Oversee periodic user access reviews, privileged access governance, and certification activities to ensure compliance with the principle of least privilege and segregation of duties.
- Ensure effective governance of privileged account management, identity protection, Multi-Factor Authentication (MFA), Single Sign-On (SSO), Conditional Access, and related identity security capabilities.
- Review identity-related risks, policy exceptions, and access governance issues, ensuring appropriate remediation and executive visibility.
- Provide strategic guidance to business and technology leaders on identity governance and access control requirements to support secure business operations.
5. Security Operations
- Provide leadership and oversight for local cybersecurity operations in collaboration with the DP World Security Operations Center (SOC).
- Ensure effective governance of cybersecurity incident management, including incident reporting, escalation, response coordination, and post-incident reviews.
- Strengthen the organization's preparedness for cyber incidents by ensuring incident response processes, roles and responsibilities, and communication protocols remain effective and up-to-date.
- Monitor operational security performance, threat trends, and control effectiveness, ensuring risks are communicated to executive management.
- Ensure accurate governance of incident records, reporting, regulatory notifications, and management reporting requirements.
6. Cyber Resilience
- Ensure cybersecurity requirements are incorporated into resilience planning, critical service protection, backup strategies, and recovery capabilities.
- Sponsor and oversee cybersecurity participation in disaster recovery exercises, business continuity testing, and resilience validation activities.
- Review resilience assessment outcomes and ensure security-related findings are prioritized and addressed through appropriate governance processes.
- Support executive decision-making during significant cybersecurity incidents and major business disruptions.
- Collaborate with regional cybersecurity and business continuity leaders to align local resilience capabilities with enterprise objectives.
7. Stakeholder Management
- Serve as the subject matter expert and primary point of contact for cybersecurity governance, risk, and compliance matters.
- Build strong partnerships with executive management, regional cybersecurity leadership, business leaders, and technology teams to promote secure business operations.
- Influence business and technology decisions by providing strategic cybersecurity guidance for projects, operational initiatives, digital transformation, and technology investments.
- Represent the organization during regulatory engagements, customer security reviews, external audits, and interactions with third-party service providers.
- Promote a strong culture of cybersecurity awareness, accountability, and continuous improvement across all levels of the organization.
- Establish and monitor cybersecurity objectives, key performance indicators (KPIs), and key risk indicators (KRIs) to measure organizational security performance.
- Prepare and present executive-level security reports, dashboards, strategic updates, and recommendations to local management and regional cybersecurity leadership.
- Mentor, develop, and provide leadership to the IT Security Team while fostering collaboration, accountability, and professional growth.
Job Context
DPW SCO, CA, Levant and Egypt needs to ensure the efficient and effective use of IT resources, supports regulatory compliance, and enhances the overall performance and reliability of IT services and Infrastructure Across the region and business units. By establishing robust governance and service management frameworks, this role helps the organization leverage technology to achieve its strategic objectives and maintain a competitive edge in the industry.
Qualifications, Experience and Skills
Certifications:
- Bachelor's degree in computer science, information technology, or a related field
- Certifications in IT governance, service management, risk management, or project management (CISSP, CISM, ITIL, Microsoft Certified Azure Certifications, CISA, CompTIA Security+) are highly desirable.
Experience and Knowledge
- 5-6 years of experience in IT governance, service delivery management, IT infrastructure, network, and risk management roles, preferably in the port and terminal industry or a related field.
- Experience in managing IT compliance, data centers, and working with regulatory frameworks is beneficial.
- Familiarity with port and terminal operations, industry-specific IT systems and applications, and regulatory requirements related to the industry is advantageous
Skills and Abilities:
- Proficiency in Arabic and English
- V. Good Communication skills
- Strong understanding of IT infrastructure and architecture.
- In-depth knowledge of cybersecurity principles and best practices.
- Expertise in IT governance frameworks and compliance standards.
- Ability to manage multiple projects and priorities in a fast-paced environment.
- Strategic thinking with a focus on aligning IT operations with business goals.
- Strong problem-solving skills: address IT-related challenges and make informed decisions.
- Change Management: Experience in managing organizational change and driving adoption of new IT processes and technologies.
- Able to work with team
Location & Eligibility
Listing Details
- Posted
- July 30, 2026
- First seen
- July 30, 2026
- Last seen
- July 30, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 51%
- Scored at
- July 30, 2026
Signal breakdown
Please let The Peninsular and Oriental Steam Navigation Company know you found this job on Jobera.
3 other jobs at The Peninsular and Oriental Steam Navigation Company
View all →Explore open roles at The Peninsular and Oriental Steam Navigation Company.
Similar Security jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.