Assistant Vice President – Information Security.RMG Information Security & Technology.Risk Management

Mashreq
United Arab Emirates
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 12+ yearsEducation: mastersSkills: ["Leadership","Communication","Stakeholder management","Analytical thinking","Risk-based judgment"]

Drive Mashreq’s Information Security GRC (governance, risk, and compliance) as a cross-functional orchestration role. Build and embed the InfoSec risk management strategy and lifecycle, govern risk assets like the risk register and heatmap, and provide risk decisioning through narratives and aggregation. Lead cyber security initiatives, define KPIs/KRIs for risk reduction, and align workforce, policies, and services with regulatory requirements and risk appetite.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Mashreq
Mashreq
3 days ago

Assistant Vice President – Information Security.RMG Information Security & Technology.Risk Management

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Drive Mashreq’s Information Security GRC (governance, risk, and compliance) as a cross-functional orchestration role. Build and embed the InfoSec risk management strategy and lifecycle, govern risk assets like the risk register and heatmap, and provide risk decisioning through narratives and aggregation. Lead cyber security initiatives, define KPIs/KRIs for risk reduction, and align workforce, policies, and services with regulatory requirements and risk appetite.
Location: United Arab Emirates
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Director level

Key Responsibilities

  • •Orchestrate Information Security GRC and drive sustained risk culture change across the organization.
  • •Define and implement the Information Security Risk Management Strategy & Framework, covering the end-to-end risk lifecycle (identify to report).
  • •Design, govern, and maintain foundational risk assets such as the InfoSec Risk Register, risk heatmap, risk/control library, and decisioning artifacts.
  • •Provide risk decisioning direction through risk narratives, aggregation logic, concentration risk insights, and remediation prioritization aligned to risk appetite.
  • •Define and embed KPIs/KRIs, oversee strategic cyber security initiatives, and benchmark security posture against industry standards and peers.

Key Requirements

  • •12+ years of overall experience, including 2–3 years of dedicated responsibility in one or more GRC domains.
  • •Strong knowledge across information security and cyber security governance, policy development, and risk assessment.
  • •Significant banking/financial services experience with familiarity of regulatory requirements and security frameworks.
  • •Demonstrated ability to conduct comprehensive risk assessments and translate findings into actionable mitigation strategies.
  • •Master’s degree in information technology, information security, or related discipline; CISA/CISM/CISSP/CRISC (or equivalent) are highly desirable.
Experience:12+ yearsBankingFinancial servicesGRCCyber security
Education:Master's in Information Technology, Information Security, or related discipline
Skills:LeadershipCommunicationStakeholder managementAnalytical thinkingRisk-based judgment
Certifications:CISACISMCISSPCRISC
Tech Stack:ISO 27001NIST 800 seriesPCI-DSSSWIFT CSPCOBIT

Company Brief

Mashreq
Mashreq Bank is a UAE-headquartered full-service bank offering retail, corporate, Islamic and digital banking, treasury, and capital markets services across the Middle East and internationally.
Industry: Banking
Company Size: Enterprise (1,001+ employees)
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Dubai, United Arab Emirates
Founded: 1967
Glassdoor
Glassdoor: 3.3
WebsiteLinkedInGlassdoor