Role Purpose
The role is a senior technology leader responsible for defining and executing the cyber, information security, and data protection strategy across the organisation’s projects and corporate operations. This role works closely with the CIO leadership and regional executives to drive a unified global security posture while adhering to local regulatory requirements.
Key Accountabilities
- Develop and implement a Cyber and Information Security strategy aligned with business goals, regional and relevant laws.
- Establish and maintain an Information Security Management System (ISMS) based on ISO27001, NIST, and CIS framework.
- Ensure compliance with country-specific cybersecurity and data protection laws, including UAE PDPL, UK GDPR and NCSC guidelines
- Oversee cross-border data transfer governance and ensure Innovo policies comply with local restrictions and obligations.
- Build and maintain a cyber risk management framework, covering corporate, project sites and 3rd parties
- Establish consistent tools, playbooks, and escalation routes for incident and crisis management for cyber events
- Lead Innovo’s data protection and compliance strategy
- Implement and oversee 3rd party and supply chain security assessments, monitoring compliance through periodic reviews
- Build and lead a cyber and information security team, promoting a strong ‘cyber aware’ culture
Qualifications, Experience, Knowledge & Skills
- Bachelor’s degree in Information Security, Computer Science, Engineering or related field (Master’s preferred).
- 10-15 years of cybersecurity experience, with at least 5 years in a senior position
- Proven ability to manage cybersecurity across multiple regions and regulatory environments
- Experience in construction, engineering, real state development or OT heavy industries
- Strong knowledge of OT/IoT security, cloud security, SOC operations, and risk management
- Proven track record of building and leading distributed teams
- Strategic thinking with strong execution capability.
- Leadership presence and ability to influence at board and exec levels
- Crisis management and decision-making under pressure
- Effective communication and stakeholder management.
- Ability to work under pressure and manage multiple priorities.