Mashreq

AVP-Information Security Compliance.Information Security Group-ISG

Mashreq  •  Bengaluru, IN (Onsite)  •  5 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Purpose

The Assistant Vice President – Information Security Compliance is a senior leadership role within the Information Security Group, responsible for shaping, embedding, and sustaining the Bank’s Information Security Governance, Risk, and Compliance (IS GRC) framework.

Operating in an increasingly complex regulatory and threat environment, the role ensures that information security compliance is predictable, defensible, and risk‑aligned, enabling sustained regulatory confidence and strong governance outcomes. The AVP provides structured oversight across information security governance forums, regulatory obligations, audit readiness, policy and standards management, and compliance risk assurance.

The role acts as a key enabler of ISG’s compliance maturity, ensuring that information security risks are clearly articulated, obligations are traceable, controls are consistently designed and assured, and regulatory engagements are well‑governed. Through senior stakeholder engagement and leadership influence, the AVP strengthens enterprise confidence in the Bank’s information security compliance posture and supports secure business and technology growth.

Key Result Areas

Information Security Compliance & Governance Leadership

Hold overall responsibility for information security compliance governance within Information Security.

Define, maintain, and govern information security policies, standards, and compliance requirements across regions.

Provide structured second‑line oversight across governance, risk, and compliance to ensure consistency, traceability, and defensibility of controls.

Support Global ISG Governance and operational alignment mechanisms.

Regulatory & Audit Readiness

Act as the central coordination point for information security regulatory examinations, supervisory interactions, and internal/external audits.

Ensure timely, accurate, and defensible regulatory and audit responses, including evidence management, issue remediation tracking, and senior management reporting.

Maintain continuous regulatory readiness by embedding compliance assurance into BAU processes rather than point‑in‑time activity.

Regulatory Compliance & Assurance

Oversee compliance with all regulatory requirements related to information security across multiple jurisdictions.

Maintain and govern the Information Security regulatory obligations register, ensuring completeness and accuracy.

Manage the regulatory calendar and ensure timely execution of all compliance and assurance activities.

Govern security exception management, ensuring exceptions are documented, risk‑assessed, approved, monitored, and tracked to closure.

Support key regulatory programs and certifications (e.g., PCI‑DSS, SWIFT‑CSP, NESA IAS) from a second‑line oversight perspective.

Govern and support all regulatory submissions, ensuring accuracy, consistency, and data integrity from Security and Technology teams.

Monitor compliance with regulator‑mandated frameworks across regions, including (but not limited to) NESA, SWIFT‑CSP, PCI‑DSS, DFS500, FFIEC, HKMA‑CRAF, and country‑specific cyber security frameworks (India, Kuwait, Egypt, etc.).

Provide annual Information Security compliance updates to the Board (e.g., NESA IAS reporting as mandated by CBUAE).

Act as liaison with regulators and government entities to support the Bank’s information security agenda.

Govern the IS Regulatory Watch Forum and escalate emerging regulatory risks and changes to senior management.

Compliance Risk Oversight and Assurance

Oversee identification, assessment, and reporting of information security compliance risk.

Drive consistent control design, assurance approaches, and issue management across the Three Lines of Defence.

Provide senior management with transparent insight into compliance risk posture and emerging thematic issues.

Centre of Excellence (CoE) Leadership and Capability Building

Lead the Information Security Compliance Centre of Excellence, acting as the authoritative point for compliance interpretation and best practices.

Build and sustain T‑shaped expertise within the CoE, combining depth in information security compliance with breadth across IS GRC disciplines.

Drive standardization, reuse, and continuous maturity uplift of compliance and assurance processes.

Stakeholder Engagement and Governance Forums

Own and manage ISG governance forums related to information security compliance and assurance.

Engage proactively with senior stakeholders across ISG, Risk, Compliance, Legal, Technology, and Internal Audit.

Influence decision‑making on compliance priorities, remediation strategies, and governance decisions impacting regulatory posture and security risk exposure.

Navigating the Evolving Threat and Regulatory Landscape

Monitor and assess emerging cyber threats, regulatory developments, and industry trends impacting information security compliance.

Translate evolving threats and regulatory expectations into practical governance, policy, and control enhancements.

Enable proactive, intelligence‑driven compliance approaches that strengthen the Bank’s security posture and resilience.

General Management & Oversight

Maintain and present the progress of Information Security Compliance roadmap to the VP of Information Security & Head of IS GRC on regular basis.

Support ISG vision, mission, and key initiatives across the organization.

Manage IS GRC Run-the-Bank and Change-the-Bank agendas to deliver results on time and within budget.

Ensure readiness for regulatory examinations and audits, avoiding critical findings.

Drive timely closure of all legal, regulatory, and audit issues with required quality standards.

Key Principles

Alignment with Business Priorities: Ensure all actions and decisions support the organization’s strategic objectives and business goals.

Ownership and Accountability: Take full responsibility for outcomes, fostering accountability within the team and across all deliverables.

Focus on Outcomes and Impact: Deliver measurable results that enhance the bank’s security posture and promote a strong security culture.

Regulatory trust and defensibility over checklist compliance

Independent judgment with collaborative execution

Innovation and Automation: Continuously seek innovative approaches and leverage automation to improve efficiency and effectiveness.

Measurable impact on risk reduction and security posture

Continuous Learning and Improvement: Commit to ongoing learning, adapting to emerging challenges, and improving processes and performance.

Operating Environment, Framework and Boundaries, Working Relationships

HO (Head Office) and International Regulators and Supervisors across the bank is operating.

Information Security / Cyber Security Regulations and Industry best practices.

All business units including LOD 1-3 including LOD1 – Business, Tech GRC, Technology, LOD-2 Group Compliance, Fraud Prevention, Risk Management and LOD-3 Internal Audit.

Problem Solving

Address complex and ambiguous regulatory and compliance challenges across jurisdictions.

Balance regulatory expectations, security risk, and operational realities to deliver sustainable outcomes.

Resolve conflicts between control requirements and execution constraints through structured governance and influence.

Decision Making Authority & Responsibility

Authority to define and enforce information security compliance governance, standards, and assurance expectations within ISG.

Responsibility to escalate material compliance risks, control weaknesses, and regulatory concerns to senior management and governance bodies.

Influence decisions impacting regulatory standing, audit outcomes, and information security risk exposure.

Knowledge, Skills, and Experience

Knowledge

Strong expertise in information security compliance, governance, and regulatory frameworks within financial services.

Deep understanding of evolving cyber threats and global regulatory expectations.

Experience operating within a Three Lines of Defence model.

Skills

Senior stakeholder management and influencing capability.

Strong analytical capability combined with sound judgement for prioritization and decision-making under complex scenarios

Clear, concise communication of complex compliance and risk matters.

Solid understanding of evolving technology stacks, associated risks, and control environments.

Experience

Overall 12+ years of experience, with at least 2–3 years of dedicated responsibility in one or more GRC domains (Policy, Governance & Culture, Cyber Strategy & Program Management, Risk & Compliance)

Significant experience in the banking or financial services sector, with a deep understanding of regulatory requirements and security frameworks such as ISO 27001, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.

Proven track record of leading regulatory or compliance initiatives with enterprise impact.

Experience supporting regulatory examinations and Board‑level reporting.

Master’s degree in information technology, Information Security, or related discipline.

Certifications: Professional certifications such as CISA, CISM, CISSP, CRISC or equivalent are highly desirable.

The leading financial institution in MENA

While more than half a century old, we proudly think like a challenger, startup, and innovator

in banking and finance, powered by a diverse and dynamic team who put customers first.

Together, we pioneer key innovations and developments in banking and financial services.

Our mandate? To help customers find their way to Rise Every Day, partnering with them through

the highs and lows to help them reach their goals and unlock their unique vision of success.

Delivering superior service to clients by leading with innovation, treating colleagues with dignity and fairness while pursuing opportunities that grow shareholders value.

We actively contribute to the community through responsible banking in our mission to inspire more people to Rise.

Mashreq

About Mashreq

Disclaimer: Mashreq will never ask for your bank related information via phone call, SMS or email. We will also never contact you from a mobile number to resolve your query.

Welcome to the LinkedIn page of Mashreq. More than half a century old, we proudly think like a challenger, startup, and innovator in banking and finance, powered by a diverse and dynamic team who put customers first. Together, we pioneer key innovations and developments in banking and financial services. Our mandate? To help customers find their way to Rise Every Day, partnering with them through the highs and lows to help them reach their goals and unlock their unique vision of success. Join Mashreq and find your way to Rise Every Day.

Industry
Finance & Insurance
Company Size
5,001-10,000 employees
Headquarters
Dubai, AE
Year Founded
1967
Social Media