
AVP, Information Security Compliance
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in India.
• Design, integrate, and uphold the Bank’s Information Security Governance, Risk, and Compliance framework.
• Assume overall accountability for information security compliance governance within the Information Security domain.
• Establish, maintain, and manage information security policies, standards, and compliance requirements across various regions.
• Provide second-line oversight for governance, risk, and compliance activities.
• Coordinate information security regulatory examinations, supervisory interactions, and both internal and external audits.
• Ensure prompt, accurate, and justifiable regulatory and audit responses, including management of evidence, tracking issue remediation, and reporting to senior management.
• Sustain continuous regulatory readiness by embedding compliance assurance within Business As Usual (BAU) processes.
• Supervise information security regulatory compliance across numerous jurisdictions.
• Maintain the Information Security regulatory obligations register and regulatory calendar.
• Administer security exception management and regulatory submissions.
• Assist with regulatory programs and certifications such as PCI-DSS, SWIFT-CSP, and NESA IAS.
• Monitor compliance with mandated frameworks from regulators, including NESA, SWIFT-CSP, PCI-DSS, DFS500, FFIEC, HKMA-CRAF, and specific country cyber security frameworks.
• Provide annual updates on Information Security compliance to the Board.
• Engage with regulators and government bodies.
• Govern the IS Regulatory Watch Forum and elevate emerging regulatory risks.
• Oversee the identification, assessment, and reporting of information security compliance risk.
• Propel consistent control design, assurance strategies, and issue management across the Three Lines of Defence.
• Lead the Information Security Compliance Centre of Excellence.
• Foster T-shaped expertise while promoting standardization and continuous improvement.
• Own and manage ISG governance forums related to information security compliance and assurance.
• Collaborate with senior stakeholders across ISG, Risk, Compliance, Legal, Technology, and Internal Audit.
• Keep track of emerging cyber threats, regulatory changes, and industry trends.
• Translate evolving threats and regulatory requirements into enhancements in governance, policy, and controls.
• Maintain and present the Information Security Compliance roadmap to the VP of Information Security & Head of IS GRC.
• Manage IS GRC Run-the-Bank and Change-the-Bank agendas.
• Ensure preparedness for regulatory examinations and audits while driving the resolution of legal, regulatory, and audit issues.
• A minimum of 12 years of relevant experience.
• At least 2–3 years of focused responsibility in one or more GRC areas: Policy, Governance & Culture, Cyber Strategy & Program Management, Risk & Compliance.
• Extensive experience within the banking or financial services industry.
• Profound understanding of regulatory requirements and security frameworks such as ISO 27001, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.
• Demonstrated success in leading regulatory or compliance initiatives with enterprise-wide impact.
• Experience in supporting regulatory examinations and reporting at the Board level.
• A Master’s degree in information technology, Information Security, or a related field.
• Strong expertise in information security compliance, governance, and regulatory frameworks within the financial services sector.
• In-depth knowledge of evolving cyber threats and global regulatory expectations.
• Experience functioning within a Three Lines of Defence model.
• Proven capability in senior stakeholder management and influence.
• Strong analytical skills and sound judgment for prioritizing and making decisions in complex scenarios.
• Ability to communicate complex compliance and risk issues clearly and concisely.
• Solid understanding of evolving technology stacks, associated risks, and control environments.
• Professional certifications such as CISA, CISM, CISSP, CRISC, or equivalent are highly desirable.
• No specific benefits, perks, or compensation extras are stated in the posting.
VMD Corp
GR8 Tech
Modern Health
Accumulus Technologies
Get handpicked remote jobs straight to your inbox weekly.