Department: Information Technology / Information Security Reports to: Chief Information Officer (CIO)
Job Responsibilities:Governance, Risk & Compliance (GRC) Develop, maintain, and enforce information security policies, standards, procedures, and guidelines aligned with business strategy and regulatory expectations. Establish and operate the enterprise information security risk management framework — identifying, assessing, treating, and monitoring cyber risks with defined risk appetite and tolerance thresholds. Maintain the risk register, track remediation plans, and report residual risk to executive management and relevant committees. Lead security awareness and training programs to embed a strong security culture across the organization. Coordinate internal and external audits, manage findings to closure, and serve as the primary liaison for security-related audit engagements. Oversee third-party and vendor risk management, including due diligence and contractual security requirements. ISO 27001 / ISMS Management Own the Information Security Management System (ISMS), driving initial certification and ongoing surveillance/recertification cycles. Define and maintain the ISMS scope, Statement of Applicability (SoA), and Annex A control implementation. Conduct risk assessments and gap analyses against ISO 27001 (and related standards such as ISO 27002, 27005, 27017/27018 where relevant). Manage internal ISMS audits, management reviews, corrective actions, and continual improvement cycles. Ensure control effectiveness through metrics, KPIs/KRIs, and periodic reporting. FRA & Regulatory Compliance Ensure full compliance with Financial Regulatory Authority (FRA) cybersecurity and IT governance requirements for non-banking financial institutions. Map regulatory controls to internal frameworks, conduct compliance gap assessments, and maintain evidence for regulatory inspections and submissions. Monitor changes in the regulatory landscape (FRA circulars, decrees, data protection law) and translate them into actionable controls. Prepare and submit required cybersecurity reports, self-assessments, and attestations to regulators within mandated timelines. Align the security program with complementary frameworks (NIST CSF, CIS Controls, PCI DSS where applicable). Penetration Testing & Vulnerability Management Establish and manage the vulnerability management lifecycle — scanning, prioritization, remediation tracking, and verification across infrastructure, applications, cloud, and endpoints. Plan and oversee regular internal and external penetration testing engagements (network, web/mobile application, API, wireless, social engineering). Manage relationships with third-party penetration testing providers and validate the quality and coverage of their work. Analyze findings, assign risk ratings, drive remediation with technical teams, and report on trends and closure rates. Oversee configuration/hardening reviews, secure baselines, and patch management governance. Support red team/blue team exercises and continuously improve detection and response capabilities. Leadership & Operations Lead, mentor, and develop the cybersecurity team, setting objectives and building technical capability. Manage the security budget, tooling roadmap, and technology investments. Coordinate incident response readiness, contribute to major incident handling, and support business continuity/disaster recovery planning. Report security posture, risk trends, and program maturity to senior management, audit, and board-level committees.
Qualifications & Experience:Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field (Master's preferred).7–10+ years of information security experience, with at least 3–5 years in a managerial or team-lead capacity. Proven experience in a regulated industry — financial services or fintech strongly preferred. Demonstrated success in achieving and maintaining ISO 27001 certification. Hands-on background in vulnerability management and penetration testing oversight. Working knowledge of FRA regulatory requirements (or equivalent financial-sector regulatory frameworks).
Certifications (one or more preferred):CISSP, CISM, or CISAISO 27001 Lead Implementer / Lead Auditor CEH, OSCP, or GPEN (for offensive security depth) CRISC or CGEIT (for GRC depth)
Skills & Competencies:Strong command of security frameworks (ISO 27001, NIST, CIS) and risk methodologies. Familiarity with security tooling: SIEM, vulnerability scanners, EDR/XDR, GRC platforms, cloud security (Azure/AWS). Excellent stakeholder management, able to translate technical risk into business language for executives and regulators. Analytical, detail-oriented, and outcome-driven, with strong documentation and reporting skills. Effective leadership, communication, and cross-functional collaboration.