Sr Information Security Governance & Assurance Manager
Må ha:CloudAIFinTechSecuritySeniorLead
The role of Sr Infosec Governance Manager, you will lead the day-to-day security governance, certification and assurance programme
Client Details
A growing FS organisation in the Middle East.
Description
- Lead the day-to-day security governance, certification and assurance programme.
- Own the ISMS, including ISO 27001 certification, surveillance, recertification and continual improvement.
- Lead SOC 2 Type I / II readiness and examination activities, including control mapping, evidence management and auditor coordination.
- Build and maintain security control frameworks, policies, evidence programmes and remediation processes.
- Work directly with engineering, product and operational teams to implement and improve security controls.
- Perform control testing, identify deficiencies and drive remediation through to verified closure.
- Coordinate external audits, due diligence, security questionnaires and assurance requests.
- Develop clear reporting on certification status, control effectiveness, findings, exceptions and remediation.
- Improve assurance activities through automation, reusable evidence, continuous monitoring and appropriate GRC tooling.
Job Offer
- A senior individual contributor role with direct access to the leadership.
- The opportunity to build and operate the security governance and assurance architecture for a cloud native business.
- At least 10 years' experience across information security, security assurance, technology risk or a related discipline, including a minimum of five years in security GRC or assurance.
- Experience in fintech, payments, digital banking, investment, financial services or another regulated environment.
- Direct experience leading ISO 27001 certification and operating an ISMS.
- Direct experience leading SOC 2 Type I and/or Type II readiness and examinations.
- A track record of personally implementing controls, building evidence programmes and driving audits and remediation to successful outcomes.
- Experience working closely with engineering, cloud and product teams in cloud environments.
- Practical experience supporting external audits, client diligence and customer security assessments.
- Tangible experience in AI governance, AI risks or security assurance.
- Relevant qualifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM or CISSP would be advantageous.