Bengaluru · Director
Applicants who checked fit first are 3.1× more likely to hear back
Your score for this role already exists
ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.
No credit card · 1 tap with Google
HIGH
Mashreq is actively reviewing profiles and moving candidates through the pipeline right now.
First 72 hours
Still inside it - posted 3h agoEarly applicants get seen before the pile builds.
Not a repost
The first time we've seen this listing - it hasn't been closed and reopened.
You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.
Job Purpose
The Assistant Vice President – Information Security Compliance is a senior leadership role within the Information Security Group, responsible for shaping, embedding, and sustaining the Bank’s Information Security Governance, Risk, and Compliance (IS GRC) framework.
Operating in an increasingly complex regulatory and threat environment, the role ensures that information security compliance is predictable, defensible, and risk‑aligned, enabling sustained regulatory confidence and strong governance outcomes. The AVP provides structured oversight across information security governance forums, regulatory obligations, audit readiness, policy and standards management, and compliance risk assurance.
The role acts as a key enabler of ISG’s compliance maturity, ensuring that information security risks are clearly articulated, obligations are traceable, controls are consistently designed and assured, and regulatory engagements are well‑governed. Through senior stakeholder engagement and leadership influence, the AVP strengthens enterprise confidence in the Bank’s information security compliance posture and supports secure business and technology growth.
Key Result Areas
Information Security Compliance & Governance Leadership
Hold overall responsibility for information security compliance governance within Information Security.
Define, maintain, and govern information security policies, standards, and compliance requirements across regions.
Provide structured second‑line oversight across governance, risk, and compliance to ensure consistency, traceability, and defensibility of controls.
Support Global ISG Governance and operational alignment mechanisms.
Regulatory & Audit Readiness
Act as the central coordination point for information security regulatory examinations, supervisory interactions, and internal/external audits.
Ensure timely, accurate, and defensible regulatory and audit responses, including evidence management, issue remediation tracking, and senior management reporting.
Maintain continuous regulatory readiness by embedding compliance assurance into BAU processes rather than point‑in‑time activity.
Regulatory Compliance & Assurance
Oversee compliance with all regulatory requirements related to information security across multiple jurisdictions.
Maintain and govern the Information Security regulatory obligations register, ensuring completeness and accuracy.
Manage the regulatory calendar and ensure timely execution of all compliance and assurance activities.
Govern security exception management, ensuring exceptions are documented, risk‑assessed, approved, monitored, and tracked to closure.
Support key regulatory programs and certifications (e.g., PCI‑DSS, SWIFT‑CSP, NESA IAS) from a second‑line oversight perspective.
Govern and support all regulatory submissions, ensuring accuracy, consistency, and data integrity from Security and Technology teams.
Monitor compliance with regulator‑mandated frameworks across regions, including (but not limited to) NESA, SWIFT‑CSP, PCI‑DSS, DFS500, FFIEC, HKMA‑CRAF, and country‑specific cyber security frameworks (India, Kuwait, Egypt, etc.).
Provide annual Information Security compliance updates to the Board (e.g., NESA IAS reporting as mandated by CBUAE).
Act as liaison with regulators and government entities to support the Bank’s information security agenda.
Govern the IS Regulatory Watch Forum and escalate emerging regulatory risks and changes to senior management.
Compliance Risk Oversight and Assurance
Oversee identification, assessment, and reporting of information security compliance risk.
Drive consistent control design, assurance approaches, and issue management across the Three Lines of Defence.
Provide senior management with transparent insight into compliance risk posture and emerging thematic issues.
Centre of Excellence (CoE) Leadership and Capability Building
Lead the Information Security Compliance Centre of Excellence, acting as the authoritative point for compliance interpretation and best practices.
Build and sustain T‑shaped expertise within the CoE, combining depth in information security compliance with breadth across IS GRC disciplines.
Drive standardization, reuse, and continuous maturity uplift of compliance and assurance processes.
Stakeholder Engagement and Governance Forums
Own and manage ISG governance forums related to information security compliance and assurance.
Engage proactively with senior stakeholders across ISG, Risk, Compliance, Legal, Technology, and Internal Audit.
Influence decision‑making on compliance priorities, remediation strategies, and governance decisions impacting regulatory posture and security risk exposure.
Navigating the Evolving Threat and Regulatory Landscape
Monitor and assess emerging cyber threats, regulatory developments, and industry trends impacting information security compliance.
Translate evolving threats and regulatory expectations into practical governance, policy, and control enhancements.
Enable proactive, intelligence‑driven compliance approaches that strengthen the Bank’s security posture and resilience.
General Management & Oversight
Maintain and present the progress of Information Security Compliance roadmap to the VP of Information Security & Head of IS GRC on regular basis.
Support ISG vision, mission, and key initiatives across the organization.
Manage IS GRC Run-the-Bank and Change-the-Bank agendas to deliver results on time and within budget.
Ensure readiness for regulatory examinations and audits, avoiding critical findings.
Drive timely closure of all legal, regulatory, and audit issues with required quality standards.
Key Principles
Alignment with Business Priorities: Ensure all actions and decisions support the organization’s strategic objectives and business goals.
Ownership and Accountability: Take full responsibility for outcomes, fostering accountability within the team and across all deliverables.
Focus on Outcomes and Impact: Deliver measurable results that enhance the bank’s security posture and promote a strong security culture.
Regulatory trust and defensibility over checklist compliance
Independent judgment with collaborative execution
Innovation and Automation: Continuously seek innovative approaches and leverage automation to improve efficiency and effectiveness.
Measurable impact on risk reduction and security posture
Continuous Learning and Improvement: Commit to ongoing learning, adapting to emerging challenges, and improving processes and performance.
Operating Environment, Framework and Boundaries, Working Relationships
HO (Head Office) and International Regulators and Supervisors across the bank is operating.
Information Security / Cyber Security Regulations and Industry best practices.
All business units including LOD 1-3 including LOD1 – Business, Tech GRC, Technology, LOD-2 Group Compliance, Fraud Prevention, Risk Management and LOD-3 Internal Audit.
Problem Solving
Address complex and ambiguous regulatory and compliance challenges across jurisdictions.
Balance regulatory expectations, security risk, and operational realities to deliver sustainable outcomes.
Resolve conflicts between control requirements and execution constraints through structured governance and influence.
Decision Making Authority & Responsibility
Authority to define and enforce information security compliance governance, standards, and assurance expectations within ISG.
Responsibility to escalate material compliance risks, control weaknesses, and regulatory concerns to senior management and governance bodies.
Influence decisions impacting regulatory standing, audit outcomes, and information security risk exposure.
Knowledge, Skills, and Experience
Knowledge
Strong expertise in information security compliance, governance, and regulatory frameworks within financial services.
Deep understanding of evolving cyber threats and global regulatory expectations.
Experience operating within a Three Lines of Defence model.
Skills
Senior stakeholder management and influencing capability.
Strong analytical capability combined with sound judgement for prioritization and decision-making under complex scenarios
Clear, concise communication of complex compliance and risk matters.
Solid understanding of evolving technology stacks, associated risks, and control environments.
Experience
Overall 12+ years of experience, with at least 2–3 years of dedicated responsibility in one or more GRC domains (Policy, Governance & Culture, Cyber Strategy & Program Management, Risk & Compliance)
Significant experience in the banking or financial services sector, with a deep understanding of regulatory requirements and security frameworks such as ISO 27001, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.
Proven track record of leading regulatory or compliance initiatives with enterprise impact.
Experience supporting regulatory examinations and Board‑level reporting.
Master’s degree in information technology, Information Security, or related discipline.
Certifications: Professional certifications such as CISA, CISM, CISSP, CRISC or equivalent are highly desirable.
Free · no signup
Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.
No spam. Just jobs and resources.
Why people use ASAI
Scored, not searched. Every role ranked against your actual profile.
Alerts as often as hourly. Reach new roles while the pile is still small.
Skill gaps, spelled out. See exactly which requirements you don't meet yet.
Verified jobs, only. Say no to ghost jobs. Your time deserves respect.
More Security Engineer roles in Bengaluru
See allKeep browsing