Senior IT Risk Analyst - Emiratisation

NEW

Emirates Group · Emirates Group Headquarters, United Arab Emirates

IT & Digital
Base
Emirates Group Headquarters, United Arab Emirates
Field
IT & Digital
Posted
Closes
Job Purpose

At Emirates, we believe in connecting the world, to and through, our global hub in Dubai, and in constantly innovating to ensure our customers ‘Fly Better’. Emirates Group IT thrives on the dynamic nature of technology. Being pioneers in aviation innovation, we're always at the forefront, pushing boundaries. We're on the lookout for exceptional IT professionals to fortify our position as leaders in the industry. Embark on a journey with the world’s largest international airline and become a vital part of our cutting-edge information and technology team as Senior IT Risk Analyst.

Join our CyberSecurity team where we ensure a world class CyberSecurity organisation based on the key principles of People, Process and Technology underpinned with executive endorsement of a multi-year strategy to continuously improve and develop. The team protects our digital assets by monitoring for threats, responding to incidents, managing vulnerabilities, and ensuring compliance with security policies and regulations. If you are passionate about CyberSecurity, we invite you to apply to play a crucial role in shaping the future of our technology initiatives at Emirates Group.

As Senior IT Risk Analyst, you will maintain the IT Risk Management framework, and perform risk assessments on CyberSecurity, third party, IT operations and project & programme risks. Maintain the CyberSecurity governance framework, review policies and standards, and conduct CyberSecurity awareness campaigns.
In the role you will:

  • Ensure a comprehensive IT Risk Management framework is established to identify, analyse, mitigate, monitor and communicate IT risks across Emirates IT.
  • Collect IT risks identified through various channels (e.g. risk assessments, incidents), log them in the IT Risk Register and perform continuous monitoring activities. Perform regular risk assessments on Third Party, CyberSecurity, Project & Programme and IT operations risks.
  • Perform risk assessment reports and present the results to Management.
  • Produce regular risk reports for all IT departments, and Top risks report for Senior Management.
  • Develop Key Risk Indicators (KRIs) for IT and create dashboards for continuous monitoring of the risks.
  • Conduct regular IT and CyberSecurity maturity assessments, bench-marking assignments and gap assessments against industry best practices to identify areas of improvement.
  • Periodically assess, improve and develop CyberSecurity controls, policies, processes and standards.
  • Design, develop and maintain a CyberSecurity scorecard by business area, to assess the CyberSecurity posture: Identify key metrics covering all CyberSecurit aeras, automate the data collection and scorecard production for all business areas, present the scorecard to the business.
  • Monitor and track IT regulatory requirements. Keep abreast of emerging risks and industry standards, and assess the potential impact on the organisation. Produce regular reporting to Senior Management.
  • Support / contribute to the IT security awareness campaign by organising roadshows, publishing articles, or conducting on-site CyberSecurity training. Conduct awareness training and workshops on IT Risk Management.
  • Manage daily security exceptions requests: Assess, review and action requests for exceptions to policies and standards from all levels of the organization, both corporate and IT users. Maintain an up-to-date repository of all the exceptions granted and communicate the exceptions to relevant business/ technical units.
Qualification

To be considered for this role, you must meet the below requirements:

  • Degree in Computer Science or a CyberSecurity related field.
  • 5+ Years of experience in IT Risk management, CyberSecurity and Governance within a large, complex enterprise environment, including risk framework development, risk assessments, and risk register management.
  • Strong CyberSecurity Governance, Risk and Compliance (GRC) experience, with the ability to assess cyber maturity, develop controls, and drive continuous improvement.
  • Demonstrated ability to create and present risk reports, KRIs, dashboards, and executive-level risk insights to senior stakeholders.
  • Experience managing third-party, operational, project, and regulatory risks, with a strong understanding of industry standards, compliance requirements, and risk monitoring practices.


Leadership Role: No

Salary & benefits

Join us in Dubai and enjoy an attractive tax-free salary and travel benefits that are exclusive to our industry, including discounts on flights and hotels stays around the world. Find out what it’s like to live and work in our fast-paced, cosmopolitan home city in the Dubai Lifestyle section of our website www.emirates.com/careers

From external.emiratesgroupcareers.com · seen 1 day ago