Asst Manager, Cyber Org Alignment and Compliance
At a Glance
- Category
- 🏦 Finance & Banking
- Level
- Mid-Level
- Type
- Full-time
Check Your Format
- See if your CV format works for Mashreq Bank
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
The Information Security Cyber Organization Alignment and Compliance position focuses on aligning our information security practices with the bank’s overall risk management strategy, compliance requirements, and governance frameworks.
The role focuses on driving Information Security Governance, Risk, and Compliance (GRC) initiatives to strengthen the bank’s security posture while ensuring alignment with regulatory and business objectives. through effective processes i.e., risk tracking, compliance monitoring, RCSA, evaluating exceptions, and ensuring accurate reporting. The role ensures the right level of governance and compliance are in place and drives continuous improvement in risk management processes.
- Ensure compliance with policies, regulatory requirements, and industry standards.
- Identify, assess, and manage information security risks with business.
- Ensure adherence to internal and external compliance requirements.
- Perform risk trend analysis and reporting
- Develop and maintain a comprehensive process for managing policy exceptions, including documentation, expiration date and approval workflows.
- Ensure all policy exceptions are properly documented, reviewed, and approved in accordance with organizational standards.
- Drive risk assessments for proposed policy exceptions to evaluate their potential impact on compliance and security.
- Work with stakeholders to communicate policy exception process, develop compensating controls for policy exceptions, and ensure timely closure.
- Regularly review and monitor granted exceptions to ensure compliance with the terms and conditions.
- Conduct periodic review of approved exceptions and identify gaps for improvements.
- Develop and maintain a comprehensive service catalog that accurately reflects the services offered by ISG. Regularly review and update the service catalog to ensure it aligns with business needs and technological advancements
- Monitor the performance of ISG services to ensure they meet established service level agreements (SLAs) and key performance indicators (KPIs).
- Minimum 6–8 years of total professional experience, including 4–6 years of dedicated Information Security GRC experience.
- Familiarity with information security technologies, risk, threat and vulnerability assessments, and security measures.
- Experience with governance, risk management, and compliance frameworks (e.g., ISO 27001, NIST, GDPR, PDPL).
- Hold professional certifications such as CISA, CISM, CISSP, CRISC
- Skills and Application
- Strong communication and interpersonal skills.
- Ability to manage multiple projects and priorities.
- Proficiency in security tools and technologies.
- Strategic Insight
- Foster a culture of security awareness and compliance within the organization.
- Continuously improve the information security posture of the organization.
- Ensure that information security risks are effectively managed and mitigated.
Requirements
- •Minimum 6–8 years of total professional experience
- •4–6 years of dedicated Information Security GRC experience
- •Familiarity with information security technologies, risk, threat and vulnerability assessments
- •Experience with governance, risk management, and compliance frameworks (ISO 27001, NIST, GDPR, PDPL)
- •Hold professional certifications such as CISA, CISM, CISSP, or CRISC
- •Strong communication and interpersonal skills
- •Ability to manage multiple projects and priorities
- •Proficiency in security tools and technologies
Responsibilities
- •Drive Information Security Governance, Risk, and Compliance (GRC) initiatives
- •Perform risk trend analysis and reporting
- •Develop and maintain a comprehensive process for managing policy exceptions
- •Drive risk assessments for proposed policy exceptions to evaluate impact
- •Work with stakeholders to develop compensating controls for policy exceptions
- •Regularly review and monitor granted exceptions for compliance
- •Develop and maintain a comprehensive service catalog for ISG
- •Monitor the performance of ISG services against SLAs and KPIs
Related Jobs2 similar jobs
Browse Similar
- See if your CV format works for Mashreq Bank
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
Mashreq Bank offers a wide range of banking products and services, including retail, corporate, and investment banking. It serves individuals and businesses across the UAE and internationally.