
Vice President – Information Security
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in India.
• Develop and implement the ISG GRC strategy and operating model in alignment with enterprise risk appetite and regulatory standards.
• Direct the planning of annual and multi-year GRC roadmaps with clear metrics and maturity objectives.
• Integrate standardized control, risk, and compliance frameworks across ISG and technology sectors.
• Provide counsel to senior business executives on risk-informed decision-making and oversee cyber risk reporting for board-level transparency.
• Manage the ISG GRC operating and capital budgets, including investments in automation, while tracking return on investment.
• Offer executive oversight for Information Security regulatory compliance across various jurisdictions.
• Lead regulatory interactions, inspections, examinations, submissions, responses, and attestations.
• Oversee the interpretation of regulations, applicability assessments, implementation tracking, and regulatory timelines.
• Provide strategic guidance for PCI-DSS, SWIFT CSP, NESA IAS, and ISO 27001 programs.
• Oversee the management of information security incidents, regulatory notifications, reporting, and post-incident corrective actions.
• Supervise technology risk remediation, audit outcomes, regulatory challenges, and technology risk deficiencies.
• Propel the automation of regulatory compliance, risk assessments, control assurance, and reporting, including AI-driven and workflow-oriented GRC solutions.
• Design, maintain, and govern a global Common Control Framework with traceability linking risks, controls, regulations, and evidence.
• Ensure the global consistency of Information Security governance while accommodating local regulatory requirements.
• Chair or represent ISG in enterprise governance forums and risk committees.
• Sponsor and oversee spot checks, floor visits, and on-site assurance activities.
• Establish and manage offshore delivery models for Information Security GRC services.
• Own and enhance the Information Security Risk Management Framework to incorporate InfoSec risks into enterprise risk management.
• Govern risk exceptions, risk evaluations, control self-assessments, and initiative/location/technology risk evaluations.
• Supervise third-party and supplier Information Security risk management, continuous monitoring, breach incidents, and remediation obligations.
• Present the global GRC roadmap to senior leadership and the Board, driving strategic initiatives across regions.
• A total of 14+ years of experience, with 4–5 years specifically in InfoSec GRC.
• Demonstrated capability to lead enterprise-level initiatives and influence senior and executive stakeholders.
• Extensive knowledge across Information Security and Cyber Security areas, including governance, policy formulation, compliance, risk management, and incident response.
• Significant experience in the banking or financial services industry.
• Strong comprehension of regulatory mandates and security frameworks such as the ISO 27001 series, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.
• Solid understanding of developing technology stacks, related risks, and control environments.
• Proficient in conducting intricate risk assessments and converting findings into actionable strategies that align with enterprise risk appetite.
• Excellent analytical and prioritization abilities, with a talent for making impactful decisions in complex situations.
• Outstanding communication and stakeholder engagement skills.
• Master’s degree in information technology, Information Security, or a related field.
• Professional certifications such as CISA, CISM, CRISC, or equivalent CISSP are highly preferred.
• No benefits, perks, or compensation extras are specified in the posting.
Primer
Akamai Technologies
Alice
Flodesk
Get handpicked remote jobs straight to your inbox weekly.