My Resume
Al Nuaimi Essa

ESSA AL NUAIMI

Profile

With over a decade of experience across cybersecurity, third-party risk, and technology governance, I have led large-scale cyber risk programs, vendor security assessments, and executive risk advisory initiatives supporting mission-critical, highly regulated environments.

I have built my career within leading global organizations, including HSBC Middle East (Dubai Head Office) and Airbus Defence and Space (Abu Dhabi), progressing from operational network and security roles into regional cybersecurity leadership. In these roles, I have overseen third-party risk across multiple markets, advised senior leadership, and governed cyber risk for hundreds of vendors supporting critical banking and government operations.

Fluent in English and Arabic and hold a Bachelor’s degree in Information and Cyber Security from Abu Dhabi Polytechnic. I work extensively with enterprise cyber risk frameworks and platforms, including ISO/IEC 27001, NESA, and the NIST Cybersecurity Framework.

Al Nuaimi Essa

Head of Third-Party Security

Name Al Nuaimi Essa
Phone +971552226429
Age 43 Years
Nationality Emiratis
Marital Status Married
Dependents 1
Current Occupation Regional Third-Party Security Consultant, Cyber Security Promoted from Senior Third Party Security Risk Manager
Languages Arabic English

Employment History

HSBC Middle East, Dubai Head Office, UAE

2017 - Present

Regional Third-Party Security Consultant, Cyber Security Promoted from Senior Third Party Security Risk Manager

HSBC Middle East is the regional arm of HSBC Group, delivering corporate, retail, and investment banking services across the Middle East.

  • Lead and oversee regional third-party cyber risk assessments across 3+ markets, governing security posture for 200–500+ vendors annually supporting mission-critical banking operations and digital platforms.
  • Provide executive-level cyber risk advisory to senior leadership and business heads, influencing risk acceptance and remediation decisions for high-risk vendors and strategic suppliers.
  • Develop and present Key Risk Indicators (KRIs) and third-party cyber risk dashboards to senior management, enabling quarterly and ad-hoc risk reporting.
  • Serve as a trusted cybersecurity advisor for 20+ strategic initiatives and transformation programs, embedding security-by-design into project approvals, vendor onboarding, and change governance.
  • Optimized third-party risk assessment workflows, improving assessment turnaround time by 30–40%.
  • Partner with Legal, Procurement, IT, and Compliance across 5+ enterprise functions to embed cyber risk controls into third-party governance.
  • Drove remediation governance and accountability, contributing to a 25–35% reduction in high-risk vendor findings and improving remediation closure timelines by 20–30%.
  • Built foundational innovation and governance frameworks earlier in tenure, supporting dozens of PoCs and vendor evaluations, accelerating secure technology adoption and reducing concept-to-validation timelines by 25–35%.

As a Regional Third-Party Security Consultant, I lead and oversee regional third-party cyber risk assessments across 3+ markets, governing the security posture for 200–500+ vendors annually that support mission-critical banking operations and digital platforms. I provide executive-level cyber risk advisory to senior leadership and business heads, influencing risk acceptance and remediation decisions for high-risk vendors and strategic suppliers.

I develop and present Key Risk Indicators (KRIs) and third-party cyber risk dashboards to senior management, enabling quarterly and ad-hoc risk reporting and supporting data-driven risk governance. I serve as a trusted cybersecurity advisor for 20+ strategic initiatives and transformation programs, embedding security-by-design into project approvals, vendor onboarding, and enterprise change governance.

I have optimized third-party risk assessment workflows, improving assessment turnaround time by 30–40%, while increasing operational efficiency and audit readiness. I partner with Legal, Procurement, IT, and Compliance across 5+ enterprise functions to embed cyber risk controls into third-party governance, strengthening contractual security requirements and enterprise risk accountability.

I drive remediation governance and accountability, contributing to a 25–35% reduction in high-risk vendor findings and improving remediation closure timelines by 20–30%. Earlier in my tenure, I built foundational innovation and governance frameworks, supporting dozens of PoCs and vendor evaluations, accelerating secure technology adoption and reducing concept-to-validation timelines by 25–35%.

Airbus Defence and Space, Abu Dhabi, UAE

2016 - 2017

Network Support Engineer

Airbus Defence and Space is a global leader in secure communications, satellite systems, and defense-grade technology solutions for government and enterprise clients.

  • Supported and secured mission-critical, multi-site network environments for government and mega-event operations, including Yas Formula 1 and Abu Dhabi Police Operations Center.
  • Served as the primary on-site technical escalation point during live operations, coordinating with 5+ cross-functional teams (government stakeholders, vendors, and internal engineering groups).
  • Resolved high-severity incidents within <60-minute critical SLAs during peak and high-risk windows.
  • Supported enterprise routing, switching, and perimeter security infrastructure, contributing to sustained >99.9% network availability and minimizing service disruption.
  • Implemented and enforced network security controls, privileged access processes, and structured change management, contributing to an estimated 25–40% reduction in unplanned outages.
  • Participated in incident response, root cause analysis, and post-incident reviews for high-severity events, improving mean time to resolution (MTTR) by ~20–30% and reducing repeat incident frequency.
  • Enabled secure connectivity for large-scale international events and sensitive law enforcement operations, reinforcing CIA triad principles.

Skills & Qualifications

Incident Response, Resilience & Operational Security

During my role at Airbus Defence and Space, I led and supported mission-critical network and security operations in high-risk government and mega-event environments.

Security-by-Design & Transformation Enablement

As a Regional Third-Party Security Consultant, I advise on strategic initiatives and transformation programs.

Cyber Risk Governance & Oversight

As a Regional Third-Party Security Consultant, I lead and govern third-party cyber risk across multiple markets.

Executive Cyber Risk Advisory & Stakeholder Influence

In HSBC Middle East, I provide executive-level cyber risk advisory to senior leadership and business heads.

Third-Party Risk Management (TPRM)

As a Regional Third-Party Security Consultant, I oversee large-scale third-party security assessment programs, driving governance, prioritization, and remediation.

Metrics, KRIs & Board-Level Risk Reporting

As a Regional Third-Party Security Consultant, I design and present Key Risk Indicators (KRIs) and executive dashboards.

Cross-Functional Leadership & Governance Integration

During my role in In HSBC Middle East, I partner with Legal, Procurement, IT, and Compliance across multiple enterprise functions.

Cyber Risk Remediation & Risk Reduction Leadership

As a Regional Third-Party Security Consultant, I lead remediation governance and accountability, driving measurable reductions in high-risk vendor findings.

Systems

GRC & TPRM Platforms.jfif
GCP.png
Azure.png
AWS.png

Education & Certifications

certificate.png

CRISC

Certified in Risk and Information Systems Control
ISACA

certificate.png

CCNA

Routing & Switching
Cisco Networking Academy

certificate.png

CCNA

Security
Cisco Networking Academy

certificate.png

CEH

Certified Ethical Hacker
EC-Council

certificate.png

CISSP

Certified Information Systems Security
International Information System Security Certification Consortium

certificate.png

Bachelor’s degree

Information and Cyber Security
Abu Dhabi Polytechnic, UAE

certificate.png

CISM

Certified Information Security Manager
ISACA

certificate.png

CCSP

Cloud Security
International Information System Security Certification Consortium

certificate.png

Digital Forensics Workshop


Cybersecurity Training Provider, USA

certificate.png

Cybersecurity Workshop


Cybersecurity Training Institute, USA

certificate.png

Wireless Security Training


Lockheed Martin, USA

certificate.png

Generative AI Program


Numo Al Ghurair, UAE

certificate.png

AI & Strategic Leadership Program

Saïd Business School
University of Oxford, Oxford, United Kingdom