
1001 - 5000 employees
Founded 1967
🏦 Banking
💸 Finance
💳 Fintech
Banking • Finance • Fintech
Mashreq is a leading financial institution based in the UAE, offering a wide range of banking services including personal, corporate, and investment banking. The bank focuses on providing innovative financial solutions to its customers and has a strong digital banking presence.
🔥 2 hours ago
Improve your chances of getting an interview by checking your resume score before you apply.

1001 - 5000 employees
Founded 1967
🏦 Banking
💸 Finance
💳 Fintech
Banking • Finance • Fintech
Mashreq is a leading financial institution based in the UAE, offering a wide range of banking services including personal, corporate, and investment banking. The bank focuses on providing innovative financial solutions to its customers and has a strong digital banking presence.
• Shape, embed, and sustain the Bank’s Information Security Governance, Risk, and Compliance framework • Hold overall responsibility for information security compliance governance within Information Security • Define, maintain, and govern information security policies, standards, and compliance requirements across regions • Provide second-line oversight across governance, risk, and compliance • Coordinate information security regulatory examinations, supervisory interactions, and internal/external audits • Ensure timely, accurate, and defensible regulatory and audit responses, including evidence management, issue remediation tracking, and senior management reporting • Maintain continuous regulatory readiness through compliance assurance embedded in BAU processes • Oversee information security regulatory compliance across multiple jurisdictions • Maintain the Information Security regulatory obligations register and regulatory calendar • Govern security exception management and regulatory submissions • Support regulatory programs and certifications including PCI-DSS, SWIFT-CSP, and NESA IAS • Monitor compliance with regulator-mandated frameworks including NESA, SWIFT-CSP, PCI-DSS, DFS500, FFIEC, HKMA-CRAF, and country-specific cyber security frameworks • Provide annual Information Security compliance updates to the Board • Liaise with regulators and government entities • Govern the IS Regulatory Watch Forum and escalate emerging regulatory risks • Oversee identification, assessment, and reporting of information security compliance risk • Drive consistent control design, assurance approaches, and issue management across the Three Lines of Defence • Lead the Information Security Compliance Centre of Excellence • Build T-shaped expertise and drive standardization and continuous maturity improvement • Own and manage ISG governance forums related to information security compliance and assurance • Engage with senior stakeholders across ISG, Risk, Compliance, Legal, Technology, and Internal Audit • Monitor emerging cyber threats, regulatory developments, and industry trends • Translate evolving threats and regulatory expectations into governance, policy, and control enhancements • Maintain and present the Information Security Compliance roadmap to the VP of Information Security & Head of IS GRC • Manage IS GRC Run-the-Bank and Change-the-Bank agendas • Ensure readiness for regulatory examinations and audits and drive closure of legal, regulatory, and audit issues
• Overall 12+ years of experience • At least 2–3 years of dedicated responsibility in one or more GRC domains: Policy, Governance & Culture, Cyber Strategy & Program Management, Risk & Compliance • Significant experience in the banking or financial services sector • Deep understanding of regulatory requirements and security frameworks such as ISO 27001, NIST 800 series, PCI-DSS, SWIFT CSP, and COBIT • Proven track record of leading regulatory or compliance initiatives with enterprise impact • Experience supporting regulatory examinations and Board-level reporting • Master’s degree in information technology, Information Security, or related discipline • Strong expertise in information security compliance, governance, and regulatory frameworks within financial services • Deep understanding of evolving cyber threats and global regulatory expectations • Experience operating within a Three Lines of Defence model • Senior stakeholder management and influencing capability • Strong analytical capability and sound judgement for prioritization and decision-making under complex scenarios • Clear, concise communication of complex compliance and risk matters • Solid understanding of evolving technology stacks, associated risks, and control environments • Professional certifications such as CISA, CISM, CISSP, CRISC or equivalent are highly desirable
• No specific benefits, perks, or compensation extras are stated in the posting
Apply Now🕒 August 25
SAP security consultant leading brownfield S/4HANA migrations for enterprise transformations. Owning Fiori, role redesign, SU25, and Security Weaver-based SoD governance.
🕒 July 23
Senior Security Architect specializing in Data, Fabric, Governance, and AI Security solutions for client engagements. Leading architecture and pre-sales activities in Microsoft technologies.
Azure
Cloud
🕒 June 30
AI, Cybersecurity and Data Privacy Partner at Outside GC providing legal counsel for technology and corporate matters. Collaborating with the team to deliver exceptional legal services in a remote environment.
Cloud
Cyber Security
🕒 June 19
Security Engineer at XTIUM ensuring security standards for software development and AI solutions. Collaborating closely with engineering teams to integrate security practices in the development lifecycle.
Cloud
Java
JavaScript
Microservices
Python
TypeScript
Go
🕒 March 19
Oracle Cloud Security Technical Consultant working with a team to solve complex issues. Implementing Oracle security solutions and managing client projects in the cloud.
Cloud
ERP
Oracle
Go