| | Job Purpose |
| | The Vice President – ISG GRC is a senior leadership role responsible for building regulatory trust, ensuring global regulatory alignment, and driving efficiency and predictability through automation across the Information Security Governance, Risk, and Compliance landscape. This VP role provides global strategic leadership within InfoSec GRC function ensuring that information security risks are clearly articulated, obligations are traceable, controls are consistently designed and assured, and regulatory engagements are well‑governed. Through senior stakeholder engagement and leadership influence, the VP strengthens enterprise confidence in the Bank’s information security posture and supports secure business and technology growth. This role owns the end‑to‑end Information Security GRC capability, ensuring that regulatory obligations, risk management, technology risk remediation, and supplier security risks are well‑governed, defensible, automated, and consistently executed across regions. This role acts as a strategic bridge between regulators, technology, business, and risk functions, enabling secure growth while maintaining a strong, measurable, and auditable security posture. |
| | Dimensions |
| | Operating Budget | | Number of Staff | |
| | Capital Exp. Budget | Others | |
| | Key Result Areas |
Strategy, Planning & Governance - Define and execute the ISG GRC strategy and operating model, aligned to enterprise risk appetite and regulatory expectations.
- Lead annual and multi‑year GRC roadmap planning, with measurable outcomes and maturity targets.
- Embed common control, risk, and compliance frameworks across ISG and technology domains
Act as a strategic advisor to senior business leaders on risk-based decisions. Govern cyber risk identification, documentation, and reporting for board-level visibility.
Budget & Expense Management - Own ISG GRC operating and capital budgets, including automation investments.
- Ensure cost‑efficient delivery through standardization, tooling, and offshoring leverage.
- Track ROI for GRC automation and risk reduction initiatives.
Regulatory Compliance & Trust Management - Provide executive oversight of Information Security regulatory compliance across all jurisdictions.
- Ensure global compliance with regulatory requirements and frameworks across multiple jurisdictions
- Lead regulatory engagement, inspections, and examinations for InfoSec topics.
- Ensure predictable, high‑quality regulatory submissions, responses, and attestations.
- Govern regulatory interpretation, applicability decisions, and implementation tracking.
- Partner with regional CISOs and senior business leaders to enable BISOs in driving security.
Provide assurance to the Board on compliance posture and regulatory risk exposure. Oversee management of regulatory calendars and ensure completion of compliance tasks within deadlines. Provide strategic oversight for key regulatory programs (PCI-DSS, SWIFT CSP, NESA IAS, ISO 27001) and ensure alignment with business objectives
Incident Management & Regulatory Reporting - Govern information security incident management from a regulatory perspective.
- Ensure timely, accurate, and defensible regulatory incident notifications and reporting.
- Track and oversee post‑incident remediation commitments and regulator follow‑ups.
Technology Risk Remediation Governance - Provide senior governance over technology risk remediation through the ISGRC & Tech GRC Connect model.
- Ensure remediation actions are risk‑prioritized, time‑bound, and evidence‑driven.
- Oversee closure quality for audit findings, regulatory issues, and technology risk gaps.
Regulatory & GRC Process Automation - Drive automation of regulatory compliance, risk assessment, control assurance, and reporting.
- Sponsor and govern AI‑assisted / workflow‑driven GRC solutions to improve predictability and transparency.
- Reduce manual effort and dependency through tool‑led control testing and monitoring.
Common Control Framework - Design, maintain, and govern a single Common Control Framework (CCF) aligned to global regulations and standards.
- Ensure control re‑use across regulatory, audit, and risk assessments.
- Maintain clear traceability between risks, controls, regulations, and evidence.
Global Information Security Governance & Alignment - Ensure global consistency of InfoSec governance while respecting local regulatory requirements.
- Chair or represent ISG in enterprise governance forums and risk committees.
- Drive alignment between ISG, Technology, ORM, Legal, and Compliance.
Spot Checks & Floor Visits - Sponsor and oversee spot checks, floor visits, and on‑site assurance activities.
- Validate control effectiveness, policy adherence, and operational security practices.
- Use findings to drive practical risk reduction and awareness.
Offshoring Information Security Risk Management - Establish and govern offshore delivery models for InfoSec GRC services.
- Ensure offshore teams operate with clear accountability, quality standards, and risk ownership.
- Maintain strong second‑line oversight over offshore activities.
Risk Management Framework & Processes Risk Exception Management - Govern Information Security risk exceptions, ensuring proper justification, approval, and expiry.
- Track and report exception trends, concentration risks, and residual exposure.
Risk Assessments & Attestations - Oversee InfoSec Risk Control Self‑Assessments (RCSA).
- Govern Information Security Risk Assessments (IRA) for initiatives, locations, and technologies.
- Ensure outputs are actionable, risk‑aligned, and regulator‑defensible.
Supplier Information Security Risk Management General Management & Oversight Own and present the global GRC roadmap to senior leadership and the Board. Drive strategic initiatives across regions, ensuring timely delivery and risk mitigation. Ensure readiness for regulatory examinations and audits, avoiding critical findings. Govern closure of all legal, regulatory, and audit issues within agreed timelines and quality standards.
| |
| | Key Principles |
| | Alignment with Enterprise Strategy: Ensure all decisions and initiatives directly support the organization’s long-term business objectives and growth priorities. Executive Ownership and Accountability: Demonstrate full accountability for outcomes, driving a culture of responsibility across teams and regions. Strategic Risk Reduction: Lead enterprise-wide initiatives that significantly reduce security risks and strengthen organizational resilience. Outcome-Driven Leadership: Deliver measurable, high-impact results that advance the bank’s security posture and reinforce trust with stakeholders. Innovation and Digital Transformation: Champion innovative solutions and automation to optimize efficiency and enable scalable governance. Value Optimization: Ensure all investments and initiatives deliver maximum strategic value while balancing cost and benefit. Continuous Evolution: Commit to ongoing learning, anticipating emerging threats, and driving continuous improvement in processes, technology, and culture. Stakeholder Engagement: Build strong partnerships with executive leadership, regulators, and industry peers to influence security strategy and compliance outcomes.
|
| | Operating Environment, Framework and Boundaries, Working Relationships |
| | HO (Head Office) and International Regulators and Supervisors across the bank is operating. Information Security / Cyber Security Regulations and Industry best practices. All business units including LOD 1-3 including LOD1 – Business, Tech GRC, Technology, LOD-2 Group Compliance, Fraud Prevention, Risk Management and LOD-3 Internal Audit.
|
| | Problem Solving |
| | Design and Govern Frameworks: Establish and oversee enterprise-wide frameworks, solutions, and processes for proactive management of Information Security risks across regions. Regulatory Interpretation and Strategic Decisions: Analyze complex regulatory requirements and make informed decisions on applicability, compensating controls, and residual risk at a global scale. Risk Modelling and Control Strategy: Determine residual risk and define control measures based on defense-in-depth principles and systemic risk considerations, ensuring alignment with the organization’s risk appetite and strategic objectives. Executive Advisory Role: Provide strategic guidance to senior leadership and influence risk posture decisions that impact business growth and regulatory compliance.
|
| | Decision Making Authority & Responsibility |
| | Enterprise Leadership: Act as a senior executive with overarching responsibility for Information Security governance, risk, and compliance, ensuring alignment with organizational strategy and objectives. Strategic Risk Decisions: Validate and approve recommendations for mitigating business and technology risks, ensuring alignment with enterprise priorities. Risk Appetite Alignment: Provide authoritative guidance to ensure risk mitigation strategies adhere to the bank’s defined risk appetite and tolerance levels. Regulatory Assurance: Ensure compliance with complex regulatory requirements across jurisdictions, preventing penalties and safeguarding the organization’s reputation. Control Adequacy Oversight: Confirm the effectiveness and adequacy of controls against internal security policies, global standards, data privacy obligations, and local regulatory mandates. Executive Advisory Role: Influence executive-level decisions on security posture, risk management, and compliance priorities.
|
| | Knowledge, Skills, and Experience |
| | - Leadership Experience: Overall 14+ years of experience, including 4-5 years in InfoSec GRC, with proven ability to lead enterprise-level projects and influence senior and executive stakeholders.
- Domain Expertise: Deep knowledge across Information Security and Cyber Security disciplines, including governance, policy development, compliance, risk management, and incident response.
- Industry Background: Extensive experience in banking or financial services, with strong understanding of regulatory requirements and security frameworks such as ISO 27001 series, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.
- Technical Acumen: Solid grasp of evolving technology stacks, associated risks, and control environments, enabling informed strategic decisions.
- Risk & Compliance Skills: Expertise in conducting complex risk assessments and translating findings into actionable strategies aligned with enterprise risk appetite.
- Strategic Decision-Making: Strong analytical and prioritization skills, with the ability to make high-impact decisions under complex scenarios.
- Interpersonal & Influencing Skills: Exceptional communication and stakeholder engagement capabilities to drive alignment across regions and functions.
- Education: Master’s degree in information technology, Information Security, or related discipline.
- Certifications: Professional certifications such as CISA, CISM, CRISC, or CISSP equivalent are highly desirable.
|