Job description
Role Overview
Information Security Governance Manager β Banking at VAM Systems, UAE operations.
Role Purpose
Lead information security governance, compliance, and risk management across banking operations, ensuring alignment with regulatory requirements, internal policies, and industry standards while managing concurrent security and technology projects.
Key Responsibilities
Governance & Compliance
- Develop and maintain information security policies in line with NESA requirements.
- Establish and oversee Information Security Governance and GRC frameworks covering policies, standards, risk assessments, risk registers, risk acceptance and exceptions.
- Manage PCI DSS, SWIFT CSP, VAPT and regulatory security assessments.
- Ensure policy and control alignment with UAE IA/NESA standards through implementation and assessments.
Risk & Audit Management
- Conduct risk assessments and maintain risk registers for information security exposures.
- Manage audit and regulatory findings through remediation and validated closure.
- Coordinate with Risk, Audit, Compliance and external parties on security and regulatory matters.
Project Leadership & Stakeholder Engagement
- Lead information security initiatives for major technology, digital, cloud, infrastructure and application projects.
- Manage multiple concurrent security and regulatory projects simultaneously.
- Coordinate effectively with IT, Business, Risk, Audit, Compliance, PMO and external stakeholders.
- Communicate security concepts to senior non-technical users without using technical language.
Qualifications & Experience
- Bachelor's degree.
- 10β12 years of relevant Information Security or Cyber Security experience in the banking and financial sector.
- Manager-level responsibilities within information security.
- Hands-on experience with UAE IA/NESA implementation, assessments and policy alignment.
- Professional certification: CISM, CRISC, CISA and/or CISSP required.
Skills & Competencies
- In-depth knowledge and understanding of information security and technology infrastructure.
- In-depth experience in NESA requirements implementation.
- Creative thinking; able to evaluate alternatives and develop conceptual frameworks for problem-solving.
- Strong communication skills; ability to convey complex security concepts to non-technical stakeholders.
- Ability to adapt to a fast-moving IT landscape and keep pace with latest security thinking and technologies.
- Multi-tasking capability; able to manage several concurrent projects and prioritize demands effectively.
Additional Information
- Joining timeframe: 30 days.
SalaryNot disclosed by the employer
Closingβ