Most security hiring in the UAE happens reactively. A breach, an audit finding or a resignation creates urgency, a role is written quickly, and the organisation goes to market for a cyber security expert without a clear picture of which capability it is actually short of. The result is a function assembled from whoever was available, with overlapping strengths and unexamined gaps. A talent roadmap replaces that with a deliberate sequence: which capabilities the estate needs, which of them must sit inside, which can be contracted, and in what order to close the difference. This article sets out how to build one that survives contact with a competitive market. Our note on the UAE cybersecurity compliance checklist covers the obligations that shape the requirement.

Key Takeaways

  • Start from capabilities the estate needs rather than from job titles, because titles vary between organisations while capabilities are comparable and can be assessed.
  • Decide build, buy or borrow per capability. Anything requiring business context or decision authority should sit inside; anything requiring depth used occasionally is usually better contracted.
  • Retention is part of the roadmap, not a separate exercise. A plan that hires without a growth path refills the same roles every eighteen months.

Start With Capabilities, Not Job Titles

Security job titles are close to meaningless across organisations. A security analyst in one company writes detections and runs investigations; in another they review access requests. Building a roadmap from titles therefore produces a plan nobody outside your organisation can interpret, including the candidates you are trying to attract.

Capabilities are comparable. For most enterprises the list runs to about ten: identity and access engineering, endpoint and network defence, cloud security architecture, detection engineering, incident response, vulnerability management, governance and compliance, security architecture review, third-party risk, and awareness and training.

Assess each on two axes. How much does this estate need it, scored against your actual risk profile rather than a generic maturity model, and how much of it do you currently have. The gaps that emerge are usually different from the ones assumed, and the exercise routinely reveals over-investment in one area alongside a complete absence in another.

Score both axes with people who do the work rather than with the leadership team alone. Managers systematically overestimate coverage in areas they do not personally practise, and the resulting plan closes gaps that were never open while missing the ones that are. A short structured interview with each practitioner produces a far more accurate picture than a workshop.

Be honest about the second axis. Holding a tool that performs a function is not the same as holding the capability, because someone has to tune it, interpret its output and act on it. Many enterprises discover they own vulnerability scanning technology and no vulnerability management capability at all.

Frameworks help structure this. Mapping capabilities against the NIST Cybersecurity Framework functions gives a defensible structure for the assessment and a language that boards and auditors already recognise.

Deciding What Must Sit Inside

Deciding where each cyber security expert in your plan should sit starts with three tests applied to every capability. Does it require business context that an outsider cannot acquire quickly. Does it require decision authority during an incident. Is it needed continuously rather than periodically. A capability that answers yes to two or three of these belongs internally.

By that test, incident decision-making, identity governance, security architecture review and third-party risk almost always sit inside. Each requires knowing how the business actually works, and each involves saying no to a project in a way that only an employee can sustain.

Detection engineering, penetration testing, forensic investigation and specialist cloud architecture are usually better contracted, at least initially. They need depth rather than breadth, they are used intensively but not continuously, and the market rate for that depth is difficult to justify as a permanent role in a mid-sized enterprise.

Infographic showing the build, buy or borrow decision for each security capability

Governance and compliance sits in the middle and depends on regulatory intensity. Heavily regulated entities need it inside; others are served well by a retained cyber security consultant working a defined number of days per quarter against a fixed calendar.

Sequencing the Build

Order matters more than pace when you are adding each new cyber security expert to the function. The first internal hire in a growing function should be a generalist with breadth rather than a specialist with depth, because early on the function needs someone who can triage across every domain and identify where the real gaps are. Hiring a deep specialist first produces excellent coverage of one area and none elsewhere.

The second hire should close the largest assessed gap, informed by what the first person found rather than by the original plan. Roadmaps that specify five hires in advance are almost always wrong by the third, because the first two change the organisation's understanding of its own risk.

Around the fourth or fifth role, the function needs a manager rather than another practitioner. This is the transition most enterprises delay too long, and the symptom is a team of capable individuals with no shared prioritisation, no consistent quality bar and a lead who is still doing technical work full time.

Contracted capabilities should be reviewed at each stage. A capability contracted at year one may be worth internalising at year three once the volume of work justifies it, and the roadmap should name the trigger that prompts that review rather than leaving it to renewal season.

Our note on why fintech organisations consult a security specialist in the UAE covers how sector regulation shapes the sequence.

Growing People You Already Have

The fastest route to security capability in a tight market is usually internal movement. Infrastructure engineers, developers, network specialists and service desk staff already hold the technical foundation and the business context, which is the half that takes longest to acquire. The security knowledge on top is teachable.

Design the path explicitly rather than hoping people find it. A named security mentor, a defined set of certifications with the organisation paying for them, rotation into security work for a fixed proportion of their week, and a role to move into at the end. Internal transfer programmes without a destination role produce trained staff who then leave.

Published control catalogues such as NIST SP 800-53 are a useful curriculum backbone for this, because they describe what each capability is responsible for rather than what a vendor course covers. Certification has a place and is not the whole path. Certificates demonstrate structured knowledge and satisfy procurement requirements on client work; judgement comes from doing supervised work on a real estate. The most effective programmes pair a certification track with an apprenticeship on live cases.

Budget for the productivity dip and say so openly. Someone moving into security takes six to nine months to become independently useful, and pretending otherwise sets the individual up to be judged against an unrealistic curve. Organisations that plan for the dip retain the people they develop; those that do not lose them at month four.

Rotation works in both directions. Security staff spending time in infrastructure or application teams return with context that makes their security work sharper, and the receiving teams gain someone who understands the reasoning behind controls they previously experienced as obstruction.

The organisations that do this best treat becoming a cyber security expert as a route rather than a hire. It is slower than recruiting and considerably more durable, because people who were developed internally leave less often than people who were bought at market rate.

Retention as Part of the Plan

Every cyber security expert in the UAE market is approached regularly, and salary alone will not hold them because there is always a higher offer. What holds people is a combination of interesting work, visible growth, reasonable on-call demands and management that removes obstacles rather than adding them.

Interesting work needs deliberate protection. A function where senior people spend most of their time on access request approvals and audit evidence collection will lose them, regardless of pay. Automating routine work is a retention measure as much as an efficiency one, and it should be funded on that basis.

On-call load is the most common and least discussed reason for departure. Track how often each person is called outside hours and how many of those calls were avoidable, then fix the top causes. A rota that wakes the same engineer three nights a week is a resignation being written slowly.

Growth needs to be visible before it is available. People leave when they cannot see the next step, which means publishing what progression looks like, what each level requires and who has moved recently. Enterprise cybersecurity companies competing for the same people usually make this explicit, and organisations that do not are compared unfavourably without ever knowing it.

Finally, run structured exit conversations and act on them. Departure reasons cluster tightly in security teams, and three consistent answers usually name a fixable problem. Enterprises that collect this and change nothing lose the next person for the same reason.

Turning the Roadmap Into a Board Conversation

Present the roadmap as risk coverage rather than headcount. A board asked to approve three security hires will ask why three. A board shown which capabilities are absent, what that means for specific business risks, and what the alternatives cost has the information to make a real decision.

Show the contracted alternative honestly next to each internal role. This builds credibility, because a plan that recommends internal hiring for everything reads as empire building, while one that names the capabilities better bought than built reads as considered. It also gives the board a lever other than approve or reject.

Include the retention plan in the same paper. A hiring plan without one is a request to fund the same roles repeatedly, and boards that have seen this pattern will ask about it. Presenting both together shows the function is being designed rather than staffed.

Set review points rather than a fixed multi-year plan. Twelve months is the sensible horizon for specific roles, with a directional statement beyond that. Estates change, regulation changes, and a five-year talent plan in security is a document that will be quietly ignored by year two.

If you want an external assessment of where your capability gaps sit and which of them are best contracted, our team can run the capability mapping with you. You can also see how our professional services practice supports enterprises building internal functions, and our note on proven security outcomes across UAE estates.