AVP, Information Security Compliance

Posted Sep 8

This is a fully remote position, open to applicants in India.

📋 Description

• Design, integrate, and uphold the Bank’s Information Security Governance, Risk, and Compliance framework.

• Assume overall accountability for information security compliance governance within the Information Security domain.

• Establish, maintain, and manage information security policies, standards, and compliance requirements across various regions.

• Provide second-line oversight for governance, risk, and compliance activities.

• Coordinate information security regulatory examinations, supervisory interactions, and both internal and external audits.

• Ensure prompt, accurate, and justifiable regulatory and audit responses, including management of evidence, tracking issue remediation, and reporting to senior management.

• Sustain continuous regulatory readiness by embedding compliance assurance within Business As Usual (BAU) processes.

• Supervise information security regulatory compliance across numerous jurisdictions.

• Maintain the Information Security regulatory obligations register and regulatory calendar.

• Administer security exception management and regulatory submissions.

• Assist with regulatory programs and certifications such as PCI-DSS, SWIFT-CSP, and NESA IAS.

• Monitor compliance with mandated frameworks from regulators, including NESA, SWIFT-CSP, PCI-DSS, DFS500, FFIEC, HKMA-CRAF, and specific country cyber security frameworks.

• Provide annual updates on Information Security compliance to the Board.

• Engage with regulators and government bodies.

• Govern the IS Regulatory Watch Forum and elevate emerging regulatory risks.

• Oversee the identification, assessment, and reporting of information security compliance risk.

• Propel consistent control design, assurance strategies, and issue management across the Three Lines of Defence.

• Lead the Information Security Compliance Centre of Excellence.

• Foster T-shaped expertise while promoting standardization and continuous improvement.

• Own and manage ISG governance forums related to information security compliance and assurance.

• Collaborate with senior stakeholders across ISG, Risk, Compliance, Legal, Technology, and Internal Audit.

• Keep track of emerging cyber threats, regulatory changes, and industry trends.

• Translate evolving threats and regulatory requirements into enhancements in governance, policy, and controls.

• Maintain and present the Information Security Compliance roadmap to the VP of Information Security & Head of IS GRC.

• Manage IS GRC Run-the-Bank and Change-the-Bank agendas.

• Ensure preparedness for regulatory examinations and audits while driving the resolution of legal, regulatory, and audit issues.


⛳️ Requirements

• A minimum of 12 years of relevant experience.

• At least 2–3 years of focused responsibility in one or more GRC areas: Policy, Governance & Culture, Cyber Strategy & Program Management, Risk & Compliance.

• Extensive experience within the banking or financial services industry.

• Profound understanding of regulatory requirements and security frameworks such as ISO 27001, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.

• Demonstrated success in leading regulatory or compliance initiatives with enterprise-wide impact.

• Experience in supporting regulatory examinations and reporting at the Board level.

• A Master’s degree in information technology, Information Security, or a related field.

• Strong expertise in information security compliance, governance, and regulatory frameworks within the financial services sector.

• In-depth knowledge of evolving cyber threats and global regulatory expectations.

• Experience functioning within a Three Lines of Defence model.

• Proven capability in senior stakeholder management and influence.

• Strong analytical skills and sound judgment for prioritizing and making decisions in complex scenarios.

• Ability to communicate complex compliance and risk issues clearly and concisely.

• Solid understanding of evolving technology stacks, associated risks, and control environments.

• Professional certifications such as CISA, CISM, CISSP, CRISC, or equivalent are highly desirable.


🏝️ Benefits

• No specific benefits, perks, or compensation extras are stated in the posting.

People also viewed

VMD Corp22 hours ago

Senior Cybersecurity Assessment Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GR8 Tech23 hours ago

Information Security Access Specialist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Modern Health23 hours ago

Product Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$101.4k – $140.4k/year
ApplyView job
Accumulus Technologies1 day ago

Head of Information Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$200k – $260k/year
ApplyView job
ShorePoint Inc1 day ago

Lead Security Architect

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Smile Digital Health1 day ago

Cloud Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security EngineerC$120k – C$140k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers