About the Role
We are seeking a Deputy Regional Information Security Officer (RISO) to take ownership of ICT security, operational resilience, and regulatory compliance across a diverse portfolio of entities, ranging from established licensed operations to new markets launching within specific frameworks. In this high-visibility, high-trust role, you will not only sustain existing security measures but also have the opportunity to build from the ground up. Your work will be crucial as we expand into new markets and deepen our regulatory presence, demanding senior-level ICT security leadership at the entity level.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
The Opportunity
- Prepare, contribute to, and report on regional risk governance and board committee meetings, highlighting control status, risk exposure, and readiness.
- Execute risk assessments and control testing across UAE operations in accordance with VARA cybersecurity guidelines and security best practices.
- Maintain and review Business Impact Assessments (BIA), integrating findings into global resilience planning.
- Contribute to Business Continuity Plan (BCP) documentation, testing, and updates for entity-specific scenarios.
- Collaborate with Group Security and IT to:
- Align UAE-specific regulatory controls with global policies and control frameworks.
- Develop security policies that meet international and UAE compliance requirements.
- Conduct security control validation and document evidence for internal/external audits.
- Participate in remediation planning for audit findings and track progress to closure.
- Support the RISO in preparing and submitting regulatory documentation to relevant regulators.
- Prepare and present security and resilience reports for internal governance committees and local entity management.
- Assist in responses to regulatory examinations, including due diligence and compliance queries.
- Liaise with compliance and legal teams to interpret regulatory changes and propose control adaptations.
- Participate in the regional incident response process, assist with post-incident reviews, and support continuous improvement activities.
- Coordinate with cross-functional stakeholders to embed security requirements into operational processes.
What You Will Do
-
Regulatory Governance
- Serve as the named ICT security officer for your appointed entities, with accountability for security risk, ICT governance, and resilience oversight at the board level.
- Prepare and present security, risk, and compliance reporting to entity boards and senior management committees.
- Act as the primary point of contact for VARA and other relevant regulatory authorities on ICT and security matters, including examinations, inspections, licensing interactions, and ongoing supervisory dialogue.
- Support entity go-live processes, establishing ICT governance frameworks for new market launches from scratch.
- Engage with additional regulatory frameworks as the portfolio evolves, supported by the broader RISO team.
-
ICT Risk and Security
- Lead ICT and security risk assessments across your entity portfolio, maintaining live risk registers and tracking remediation against regulatory SLAs.
- Own entity-level ICT policies, ensuring alignment with VARA cybersecurity requirements and applicable local frameworks.
- Coordinate control testing, evidence documentation, and audit preparation with global security and compliance teams.
- Manage the classification, escalation, and regulatory reporting of ICT-related incidents within required timeframes.
-
Operational Resilience
- Lead business impact assessments, critical function mapping, and business continuity planning at the entity level.
- Oversee continuity and recovery testing, ensuring outputs meet regulatory expectations and integrate into global resilience planning.
- Maintain oversight of ICT third-party dependencies and outsourcing arrangements according to regulatory requirements.
-
Group Liaison
- Act as the primary interface between your entities and the RISO Lead, ensuring local regulatory requirements are well-represented in group decisions.
- Drive local implementation of group frameworks, policies, and resilience standards, adapting them as necessary to meet jurisdiction-specific requirements.
- Represent entity priorities in group-led security initiatives and governance forums.
What You Bring
- 7+ years of experience in information security governance, ICT risk management, or regulatory compliance within a regulated financial services, fintech, or virtual asset environment.
- Direct experience as a named regulatory contact, with involvement in regulatory examinations, supervisory interactions, or licensing processes.
- Familiarity with UAE regulatory frameworks; experience with VARA or other virtual asset/crypto-native regimes is highly preferred.
- Proven track record in building compliance or governance programs from the ground up.
- Experience conducting risk assessments, business impact analyses, and resilience planning at the entity level.
- Familiarity with ICT outsourcing and third-party risk management within group structures.
- Ability to translate technical risk into board-level narrative and regulatory-grade documentation.
- Comfortable operating across multiple jurisdictions, each at different regulatory maturity stages.
- Strong project management skills, capable of driving outcomes across cross-functional, globally distributed teams.
- Relevant certifications such as CISSP, CISM, CRISC, CISA, or ISO27001 Lead Implementer are preferred.
- Familiarity with EU frameworks such as DORA and MiCA is strongly preferred.
Why This Role
- Named role within a regulated entity with accountability and board-level visibility.
- Opportunity to operate at the forefront of virtual asset regulation with the rapidly evolving VARA framework.
- Build ICT governance programs for new market entries, not merely inherit established structures.
- Work directly with C-level executives and regulators across multiple jurisdictions, in an environment that values ownership and technical depth.
- The role is designed for growth, with expanding responsibilities as the company's entity footprint increases, potentially including Asian and EU frameworks.
- Join a remote-first, international team shaping the governance and resilience of crypto assets in demanding regulatory environments.