Assistant Vice President – Information Security.RMG Information Security & Technology.Risk Management
mashreq
وصف الوظيفة
Role Overview
Assistant Vice President – Information Security within IS GRC at Mashreq. This is a cross-functional role responsible for designing, embedding, and operating foundational Information Security Governance, Risk, and Compliance (IS GRC) capabilities across the organization under the strategic direction of the Head of IS GRC.
Company Overview
Mashreq is a banking and financial services organization operating in an environment shaped by accelerating digitization, cloud adoption, expanded third-party dependency, and heightened regulatory scrutiny.
Role Purpose
The AVP acts as a central orchestrator and Centre of Excellence enabler, creating scalable frameworks, common approaches, and enabling platforms that ensure consistent risk decisioning, regulatory confidence, and measurable improvement in the Bank's security posture. The role moves the organization from compliance activity to risk-based outcomes and enables structured visibility into cyber risk exposure and quantification.
Key Responsibilities
Strategy & Framework Development
- Define and implement the Information Security Risk Management Strategy and Framework under Head of IS GRC direction, including the end-to-end InfoSec Risk Management Lifecycle: identify, assess, treat, monitor, and report.
- Develop and maintain the bank's multi-year Information Security GRC strategy, updating annually to reflect business priorities, objectives, and emerging threats.
- Oversee delivery of strategic cyber security initiatives, ensuring alignment with approved budgets and business objectives.
Risk Management & Orchestration
- Lead InfoSec Risk Management orchestration and sustained risk culture change, ensuring risk is managed consistently across IS GRC and aligned stakeholder groups.
- Design, maintain, and govern foundational risk assets: InfoSec Risk Register, risk heatmap, risk/control library, and decisioning artefacts that enable consistent senior risk decisions.
- Provide risk decisioning direction through clear risk narratives, aggregation logic, concentration risk insights, and remediation prioritization aligned to risk appetite.
Governance & Policy
- Ensure cyber security policies and practices are integrated with business objectives across all departments.
- Align the cyber security workforce and organizational structure with business needs.
- Share and promote best practices in cyber security across teams.
Performance & Measurement
- Define and embed Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) that measure the effectiveness of the Information Security program, enabling leadership to track risk reduction, control health, and cultural adoption over time.
- Regularly assess and benchmark the bank's security posture against industry standards and peers.
Service & Compliance Management
- Manage Information Security services under IS GRC and review other IS GRC services to ensure risk mitigation and regulatory compliance.
Qualifications & Experience
- Overall 12 or more years of experience, with at least 2–3 years of dedicated responsibility in one or more GRC domains: Policy, Governance and Culture, Cyber Strategy and Program Management, or Risk and Compliance.
- Proven track record of managing enterprise-level projects and maintaining direct and indirect relationships with senior and executive management.
- Significant experience in the banking or financial services sector, with deep understanding of regulatory requirements and security frameworks including ISO 27001, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.
- Master's degree in Information Technology, Information Security, or related discipline.
- Professional certifications such as CISA, CISM, CISSP, or CRISC are highly desirable.
Skills & Competencies
- Strong knowledge across Information Security and Cyber Security disciplines, including governance, policy development, compliance management, and risk assessment.
- Solid understanding of evolving technology stacks, associated risks, and control environments.
- Demonstrated ability to conduct comprehensive risk assessments and translate findings into actionable mitigation strategies.
- Strong analytical capability combined with sound judgment for prioritization and decision-making under complex scenarios.
- Excellent communication and stakeholder management skills to influence and collaborate across diverse teams.