Job description
Goodman Masson is partnering with a new financial markets infrastructure venture under formation in Oman.
Backed by prominent institutional investors, the business is building a greenfield platform from the ground up, and is now hiring at the build stage.
This is a rare chance to help stand up critical market infrastructure from a blank sheet and then run what you have built.
The role As Cyber Security Lead you keep the platform safe from attack and make sure it stays that way.
In the build phase you design the security architecture from the ground up.
In the run phase you operate that estate, watch it around the clock, and lead the response to any incident.
What you will do Design the security architecture from a blank sheet: identity and access, encryption at rest and in transit, network and endpoint controls, and the monitoring and detection stack Build and run security monitoring and threat detection, set and tune detection rules, and run threat-hunting exercises Own identity, privileged access, and encryption to the standard a regulated financial platform requires Run the vulnerability management cycle, coordinate penetration testing, and drive remediation to close Own security incident response end to end, from detection through containment, recovery, and review Design the run-phase security operating model, author the playbooks, and build and lead the security team Location and terms Based in Muscat, Oman.
Permanent for Omani nationals; two-year fixed-term contract for expatriate hires.
If this is your kind of build, apply through this posting or message me directly for a confidential conversation.
What you will bring Degree in computer science, engineering, information security, or a related field At least ten years in cyber and information security, with real time owning the security of a mission-critical platform end to end Direct experience designing and standing up the security capability of a mission-critical regulated platform from a blank sheet, not only running one built by others Direct experience as a senior security authority in financial services or a comparable mission-critical regulated setting such as capital markets, banking, payments, or financial market infrastructure Deep expertise in security monitoring, threat detection, and incident response, including running or directing a SOC or managed security service Strong grasp of identity and access management, privileged access, and encryption for a regulated platform Hands-on technical credibility and sound judgement under a live incident Fluent English, written and spoken Also of interest Experience with financial market infrastructure such as a central securities depository, central counterparty, exchange, or payment system Familiarity with the CPMI-IOSCO Principles for Financial Market Infrastructures, especially the operational and cyber resilience principles Experience securing connectivity to industry networks and market data services such as SWIFT, Bloomberg, and the international central securities depositories Relevant certifications such as CISSP, CISM, CEH, or GIAC
This job post has been translated by AI and may contain minor differences or errors.