
Deputy Regional Information Security Officer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United Arab Emirates (UAE).
• Act as the designated ICT security officer for appointed entities, responsible for overseeing security risk, ICT governance, and resilience at the board level.
• Prepare, deliver, and report on issues related to security, risk, compliance, and resilience to entity boards, senior management committees, and regional governance forums.
• Serve as the main point of contact for VARA and other regulatory bodies regarding ICT and security concerns, including examinations, inspections, licensing communications, and supervisory discussions.
• Assist with entity go-live procedures and establish ICT governance frameworks for new market launches.
• Lead ICT and security risk assessments, maintain active risk registers, and monitor remediation against regulatory service level agreements (SLAs).
• Own and align entity-level ICT policies with VARA standards, local frameworks, and group guidelines.
• Coordinate control testing, documentation of evidence, audit preparation, and planning for remediation.
• Manage the classification, escalation, and regulatory reporting of ICT-related incidents.
• Lead business impact assessments, critical function mapping, business continuity planning, and testing for continuity and recovery.
• Oversee ICT dependencies on third parties and outsourcing arrangements.
• Collaborate with Group Security, IT, compliance, legal, and the RISO Lead to execute local and group security frameworks.
• Engage in regional incident response, post-incident evaluations, and ongoing improvement initiatives.
• Represent entity priorities in group-led security projects and governance meetings.
• Minimum of 7 years of experience in information security governance, ICT risk management, or regulatory compliance within a regulated financial services, fintech, or virtual asset environment.
• Direct experience as a designated regulatory contact, including participation in regulatory examinations, supervisory engagements, licensing processes, or equivalent activities.
• Understanding of UAE regulatory frameworks.
• Experience with VARA or other regulatory regimes related to virtual assets or cryptocurrencies is strongly preferred.
• Proven capability to develop compliance or governance programs from the ground up.
• Experience in conducting risk assessments, business impact analyses, and resilience planning at the entity level.
• Familiarity with ICT outsourcing and third-party risk management within organizational structures.
• Ability to convey technical risk in a narrative suitable for board-level discussions and regulatory-grade documentation.
• Capacity to operate across multiple jurisdictions simultaneously.
• Strong project management abilities and effectiveness in driving results across cross-functional, globally distributed teams.
• Preferred certifications include CISSP, CISM, CRISC, CISA, or ISO27001 Lead Implementer.
• Familiarity with EU regulations such as DORA and MiCA is strongly preferred.
• Candidates must specify the city and country from which they intend to work.
• Candidates must indicate whether they require current or future work sponsorship in their location.
• Remote-first, international team environment.
• Opportunity to engage with C-level executives and regulators across various jurisdictions.
• Chance to develop ICT governance programs from the ground up for new market entries.
• Visibility and accountability at the board level within a regulated entity.
• Opportunities for professional development as the entity's presence and regulatory scope grow.
• Commitment to equal opportunity employment.
• Consistent application of job-related skills or work-style assessments across all candidates.
• Consideration of criminal history in accordance with the San Francisco Fair Chance Ordinance.
GSB Solutions
GSB Solutions
Deep Fission
Veeam Software
Get handpicked remote jobs straight to your inbox weekly.