Company logo hidden

Deputy Regional Information Security Officer

Unlock employer United Arab Emirates Direct to Company 2 hours ago · 01 Oct 2026

Financial

  • Estimate: $80k - $140k*
  • Zero income tax location

Accessibility

  • Fully Remote
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional

Position

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

About the Role
We are seeking a Deputy Regional Information Security Officer to own ICT security, operational resilience, and regulatory compliance across a portfolio of entities at different stages of maturity, from established licensed operations to new markets launching under various frameworks. This high-visibility, high-trust role is designed for a security governance professional who thrives at the intersection of technology, compliance, and financial services, with an enthusiasm for building from the ground up while sustaining existing systems.
As a trusted player within the organization, you will operate across a growing network of regulated entities in Europe, the Middle East, and Asia Pacific, responding to increasing demands for senior-level ICT security leadership at the entity level as we expand into new markets and deepen our regulatory footprint.
The Opportunity

  • Prepare, contribute, and report to regional risk governance and board committee meetings, highlighting control status, risk exposure, and readiness.
  • Execute risk assessments and control testing across UAE operations in line with VARA cybersecurity guidelines and security best practices.
  • Maintain and review Business Impact Assessments (BIA) and integrate findings into global resilience planning.
  • Contribute to Business Continuity Plan (BCP) documentation, testing, and updates, including entity-specific scenarios.
  • Collaborate with Group Security and IT to align UAE-specific regulatory controls with global policies and control frameworks.
  • Contribute to the development of security policies to meet international and UAE compliance requirements.
  • Conduct security control validation and document evidence for internal/external audits.
  • Participate in remediation planning for audit findings and track progress to closure.
  • Support the RISO in preparing and submitting regulatory documentation to regulators.
  • Prepare and present security and resilience reports for internal governance committees and local entity management.
  • Assist in responses to regulatory examinations, including due diligence and compliance queries.
  • Liaise with compliance and legal teams to interpret regulatory changes and propose control adaptations.
  • Participate in the regional incident response process, assist with post-incident reviews, and support continuous improvement activities.
  • Coordinate with cross-functional stakeholders to embed security requirements into operational processes.
    What You Will Do
    Regulatory Governance
  • Serve as the named ICT security officer for your appointed entities, with formal accountability for security risk, ICT governance, and resilience oversight at board level.
  • Prepare and present security, risk, and compliance reporting to entity boards and senior management committees.
  • Act as the primary point of contact for VARA and other relevant regulatory authorities on ICT and security matters, including examinations, inspections, licensing interactions, and ongoing supervisory dialogue.
  • Support entity go-live processes, including the establishment of ICT governance frameworks for new market launches.
  • Engage with additional regulatory frameworks as your portfolio evolves, with support from the broader RISO team.
    ICT Risk and Security
  • Lead ICT and security risk assessments across your entity portfolio, maintaining live risk registers and tracking remediation against regulatory SLAs.
  • Own entity-level ICT policies and ensure they align with VARA cybersecurity requirements, applicable local frameworks, and group standards.
  • Coordinate control testing, evidence documentation, and audit preparation with global security and compliance teams.
  • Manage the classification, escalation, and regulatory reporting of ICT-related incidents within required timeframes.
    Operational Resilience
  • Lead business impact assessments, critical function mapping, and business continuity planning at the entity level.
  • Oversee continuity and recovery testing, ensuring outputs meet regulatory expectations and feedback into global resilience planning.
  • Maintain oversight of ICT third-party dependencies and outsourcing arrangements in line with regulatory requirements.
    Group Liaison
  • Act as the primary interface between your entities and the RISO Lead, ensuring local regulatory requirements are accurately represented in group-level decisions.
  • Drive local implementation of group frameworks, policies, and resilience standards, adapting them to specific jurisdictional requirements.
  • Represent entity priorities in group-led security initiatives and governance forums.
    What You Bring
  • 7+ years of experience in information security governance, ICT risk management, or regulatory compliance in a regulated financial services, fintech, or virtual asset environment.
  • Direct experience as a named regulatory contact and involvement in regulatory examinations, supervisory interactions, licensing processes, or equivalent.
  • Familiarity with UAE regulatory frameworks, with experience in VARA or other virtual asset/crypto-native regulatory regimes strongly preferred.
  • Proven ability to build compliance or governance programs from the ground up, as well as maintain them.
  • Experience conducting risk assessments, business impact analyses, and resilience planning at the entity level.
  • Familiarity with ICT outsourcing and third-party risk management within group structures.
  • Ability to translate technical risk into board-level narratives and regulatory-grade documentation.
  • Comfortable operating across multiple jurisdictions simultaneously, each at varying stages of regulatory maturity.
  • Strong project management skills and the ability to drive outcomes across cross-functional, globally distributed teams.
  • Preferred certifications include CISSP, CISM, CRISC, CISA, or ISO27001 Lead Implementer.
  • Familiarity with EU frameworks such as DORA and MiCA is strongly preferred.
    Why This Role
  • You will hold a named role within a regulated entity with accountability and board-level visibility.
  • Engage with one of the most advanced and rapidly evolving crypto regulatory frameworks globally—shaping the approach to VARA from day one of market entry.
  • Build ICT governance programs from scratch for new market entries, rather than inheriting existing structures.
  • Experience direct exposure to C-level executives and regulators across multiple jurisdictions in a work environment that rewards ownership and technical depth equally.
  • The role is designed to expand in scope as the entity footprint grows, potentially including additional regulatory frameworks from Asia and the EU such as DORA.
  • Join a remote-first, international team committed to shaping the future of crypto asset governance and resilience across demanding regulatory environments.
Apply Direct

Jobs you might like   View all jobs

Ready to apply for this role?

Apply Direct