About the Role
The Assistant Vice President (AVP) – Information Security in IS GRC is a cross-functional role responsible for designing, embedding, and operating foundational IS GRC capabilities across the organization under the strategic direction of the Head of IS GRC. This role acts as a central orchestrator and Centre of Excellence (CoE) enabler, creating scalable frameworks, common approaches, and enabling platforms that ensure consistent risk decision-making, regulatory confidence, and measurable improvement in the organization’s security posture.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
In a threat landscape shaped by accelerating digitization, cloud adoption, expanded third-party dependency, and heightened regulatory scrutiny, the AVP ensures that IS GRC remains predictable, defensible, and intelligence-driven—moving the organization from compliance activity to risk-based outcomes. The role leads risk culture change by driving “shift-left / shift-up” security risk integration into business and technology decision-making and enables structured visibility into cyber risk exposure and cyber risk quantification.
Key Responsibilities
- Lead InfoSec Risk Management orchestration and sustained risk culture change, ensuring risk is managed consistently across ISG and aligned stakeholder groups.
- Define and implement the Information Security Risk Management Strategy & Framework (under Head of IS GRC direction), including the end-to-end InfoSec Risk Management Lifecycle (identify → assess → treat → monitor → report).
- Design, maintain, and govern foundational risk assets: InfoSec Risk Register, risk heatmap, risk/control library, and decisioning artefacts that enable consistent senior risk decisions.
- Provide risk decisioning direction through clear risk narratives, aggregation logic, concentration risk insights, and remediation prioritization aligned to risk appetite.
- Develop and maintain the bank’s multi-year Information Security GRC strategy, updating annually to reflect business priorities, objectives, and emerging threats.
- Oversee delivery of strategic cyber security initiatives, ensuring alignment with approved budgets and business objectives.
- Define and embed KPIs and KRIs that measure the effectiveness of the Information Security program, enabling leadership to track risk reduction, control health, and cultural adoption over time.
- Align the cyber security workforce and organizational structure with business needs.
- Ensure cyber security policies and practices are integrated with business objectives across all departments.
- Regularly assess and benchmark the bank’s security posture against industry standards and peers.
- Share and promote best practices in cyber security across teams.
- Manage Information Security services under IS GRC and review other ISG services to ensure risk mitigation and regulatory compliance.
Requirements
- Experience: Overall 12+ years of experience, with at least 2–3 years of dedicated responsibility in one or more GRC domains (Policy, Governance & Culture, Cyber Strategy & Program Management, Risk & Compliance).
- Leadership Exposure: Proven track record of managing enterprise-level projects and maintaining direct and indirect relationships with senior and executive management.
- Domain Expertise: Strong knowledge across Information Security and Cyber Security disciplines, including governance, policy development, compliance management, risk assessment, Risk management strategy.
- Industry Background: Significant experience in the banking or financial services sector, with a deep understanding of regulatory requirements and security frameworks such as ISO 27001, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT.
- Technical Acumen: Solid understanding of evolving technology stacks, associated risks, and control environments.
- Risk Assessment Skills: Demonstrated ability to conduct comprehensive risk assessments and translate findings into actionable mitigation strategies.
- Analytical & Decision-Making Skills: Strong analytical capability combined with sound judgement for prioritization and decision-making under complex scenarios.
- Interpersonal Skills: Excellent communication and stakeholder management skills to influence and collaborate across diverse teams.
- Education: Master’s degree in information technology, Information Security, or related discipline.
- Certifications: Professional certifications such as CISA, CISM, CISSP, CRISC or equivalent are highly desirable.