AVP - Governance Risk & Compliance - Information Security Group

4 weeks ago


Bengaluru, India Mashreq Global Services Private Limited Full time

Key Responsibilities:1. Information Security Governance- Develop, implement, and maintain the Information Security Governance Framework in alignment with business strategy and regulatory requirements.- Define, review, and update security policies, standards, and guidelines to ensure relevance and effectiveness.- Establish and monitor key performance indicators (KPIs) and key risk indicators (KRIs) for the bank's information security posture.- Ensure that the bank's security initiatives are consistent with business goals, risk appetite, and industry best practices (e.g., ISO 27001, NIST, COBIT).- Lead governance forums and management reviews on information security matters, ensuring timely escalation and decision-making.2. Risk Management- Oversee and continuously enhance the Information Security Risk Management Program to identify, assess, mitigate, and monitor cyber and technology risks.- Conduct regular risk assessments of critical systems, processes, and third-party vendors to ensure proper risk treatment and remediation.- Support business and IT units in understanding and managing their security risks in line with enterprise risk management (ERM) principles.- Provide input into the bank's risk register and ensure alignment between technology and operational risk functions.- Promote a proactive risk culture that focuses on prevention, detection, and resilience.3. Compliance Management- Ensure compliance with applicable regulatory and legal requirements (e.g., UAE Central Bank, NESA, GDPR, PCI DSS) and internal security policies.- Liaise with regulators, auditors, and external assessors on all information security governance, risk, and compliance matters.- Coordinate and oversee periodic internal and external security audits, assessments, and certifications.- Drive remediation of audit findings and ensure timely closure of identified gaps.- Maintain awareness of emerging regulatory and compliance trends in cybersecurity and data protection.4. Cyber Strategy & Program Management- Support the Head of IS GRC in defining and executing the bank's cybersecurity strategy and roadmap.- Oversee program and project governance, ensuring alignment with security architecture, IT operations, and digital transformation initiatives.- Lead initiatives to embed security by design into all technology and business processes.- Drive continuous improvement through maturity assessments, benchmarking, and adoption of new technologies and frameworks.5. Culture, Awareness & Leadership- Promote a security-conscious culture by designing and implementing awareness and training programs across all levels of the organization.- Lead a Center of Excellence (CoE) within IS GRC, focusing on developing expertise, frameworks, and automation in governance and compliance processes.- Mentor and develop team members to become T-shaped professionals, capable of contributing across multiple domains of GRC.- Act as the deputy to the Head of IS GRC, representing the function in governance committees and strategic forums when required.Qualifications, Skills, and Experience:- Bachelor's or Master's degree in Information Security, Computer Science, Information Technology, or a related discipline.- 8-12 years of experience in Information Security Governance, Risk, and Compliance roles within the banking or financial services industry.- In-depth understanding of information security frameworks (ISO 27001, NIST CSF, COBIT, ITIL) and risk management methodologies.- Proven experience in managing security compliance programs across multiple jurisdictions.- Strong grasp of cybersecurity regulatory requirements in the UAE and other global markets.- Professional certifications such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor are highly desirable.- Excellent communication, stakeholder management, and influencing skills.- Demonstrated leadership and mentoring capabilities in a matrix or cross-functional environment.- Strong analytical and strategic thinking abilities with a focus on delivering measurable results. (ref:iimjobs.com)



  • Bengaluru, India MUFG Global Service (MGS) Full time

    About Us: MUFG Bank, Ltd. is Japans premier bank, with a global network spanning in more than 40 markets. Outside of Japan, the bank offers an extensive scope of commercial and investment banking products and services to businesses, governments, and individuals worldwide. MUFG Banks parent, Mitsubishi UFJ Financial Group, Inc. (MUFG) is one of the worlds...

  • AVP Governance Risk

    1 week ago


    Bengaluru, Karnataka, India Mashreq Careers Full time

    To develop, manage, and execute Information Security Governance, Risk and Compliance across Mashreq to – Contribute strategically to the bank's success and enable the business and technology strategy of the bank to expand with secure and reliable service offering.  Navigate compliance complexities and support compliance with information security...


  • Bengaluru, Karnataka, India Morae Global Corporation Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Information Security Governance Risk and Compliance – Associate ManagerJob Type: Full TimeReports to: Director of Information Security & IT GovernancePOSITION OVERVIEWThis Information Security GRC Expert – Associate Manager contributes to Morae success byimplementing, and maintaining people, process and technology-oriented policies, procedures,...


  • Bengaluru, India Navi Full time

    About the Team At Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams. Our mission: Protect what powers Navi -...

  • Senior Manager

    2 weeks ago


    Bengaluru, India Navi Full time

    About the TeamAt Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.Our mission: Protect what powers Navi -...

  • Senior Manager

    1 week ago


    Bengaluru, India Navi Full time

    About the TeamAt Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.Our mission: Protect what powers Navi -...

  • Senior manager

    2 weeks ago


    Bengaluru, India Navi Full time

    About the TeamAt Navi, the Info Sec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.Our mission: Protect what powers Navi -...

  • Senior manager

    3 days ago


    Bengaluru, India Navi Full time

    About the Team At Navi, the Info Sec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams. Our mission: Protect what powers Navi -...

  • Senior Manager

    1 week ago


    Bengaluru, India Navi Full time

    About the TeamAt Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams.Our mission: Protect what powers Navi -...

  • Senior Manager

    2 weeks ago


    Bengaluru, India Navi Full time

    About the Team At Navi, the InfoSec team safeguards our digital ecosystem - ensuring the confidentiality, integrity, and availability of critical systems and data. We lead the charge on cyber risk management, regulatory compliance, and data protection, while championing a security-first culture across all teams. Our mission: Protect what powers Navi -...