The Vice President – ISG GRC is a senior leadership role responsible for building regulatory trust, ensuring global regulatory alignment, and driving efficiency and predictability through automation across the Information Security Governance, Risk, and Compliance landscape.
This VP role provides global strategic leadership within InfoSec GRC function ensuring that information security risks are clearly articulated, obligations are traceable, controls are consistently designed and assured, and regulatory engagements are well‑governed. Through senior stakeholder engagement and leadership influence, the VP strengthens enterprise confidence in the Bank’s information security posture and supports secure business and technology growth.
This role owns the end‑to‑end Information Security GRC capability, ensuring that regulatory obligations, risk management, technology risk remediation, and supplier security risks are well‑governed, defensible, automated, and consistently executed across regions. This role acts as a strategic bridge between regulators, technology, business, and risk functions, enabling secure growth while maintaining a strong, measurable, and auditable security posture.
Operating Budget
Number of Staff
Capital Exp. BudgetOthersStrategy, Planning & Governance
Act as a strategic advisor to senior business leaders on risk-based decisions.
Govern cyber risk identification, documentation, and reporting for board-level visibility.
Budget & Expense Management
Regulatory Compliance & Trust Management
Provide assurance to the Board on compliance posture and regulatory risk exposure.
Oversee management of regulatory calendars and ensure completion of compliance tasks within deadlines.
Provide strategic oversight for key regulatory programs (PCI-DSS, SWIFT CSP, NESA IAS, ISO 27001) and ensure alignment with business objectives
Incident Management & Regulatory Reporting
Technology Risk Remediation Governance
Regulatory & GRC Process Automation
Common Control Framework
Global Information Security Governance & Alignment
Spot Checks & Floor Visits
Offshoring Information Security Risk Management
Risk Management Framework & Processes
Drive enterprise-level cyber risk quantification to inform strategic decisions and board reporting.
Risk Exception Management
Risk Assessments & Attestations
Supplier Information Security Risk Management
Oversee third-party risk management strategy and ensure resilience across critical vendor relationships.
General Management & Oversight
Own and present the global GRC roadmap to senior leadership and the Board.
Drive strategic initiatives across regions, ensuring timely delivery and risk mitigation.
Ensure readiness for regulatory examinations and audits, avoiding critical findings.
Govern closure of all legal, regulatory, and audit issues within agreed timelines and quality standards.
Alignment with Enterprise Strategy: Ensure all decisions and initiatives directly support the organization’s long-term business objectives and growth priorities.
Executive Ownership and Accountability: Demonstrate full accountability for outcomes, driving a culture of responsibility across teams and regions.
Strategic Risk Reduction: Lead enterprise-wide initiatives that significantly reduce security risks and strengthen organizational resilience.
Outcome-Driven Leadership: Deliver measurable, high-impact results that advance the bank’s security posture and reinforce trust with stakeholders.
Innovation and Digital Transformation: Champion innovative solutions and automation to optimize efficiency and enable scalable governance.
Value Optimization: Ensure all investments and initiatives deliver maximum strategic value while balancing cost and benefit.
Continuous Evolution: Commit to ongoing learning, anticipating emerging threats, and driving continuous improvement in processes, technology, and culture.
Stakeholder Engagement: Build strong partnerships with executive leadership, regulators, and industry peers to influence security strategy and compliance outcomes.
HO (Head Office) and International Regulators and Supervisors across the bank is operating.
Information Security / Cyber Security Regulations and Industry best practices.
All business units including LOD 1-3 including LOD1 – Business, Tech GRC, Technology, LOD-2 Group Compliance, Fraud Prevention, Risk Management and LOD-3 Internal Audit.
Design and Govern Frameworks: Establish and oversee enterprise-wide frameworks, solutions, and processes for proactive management of Information Security risks across regions.
Regulatory Interpretation and Strategic Decisions: Analyze complex regulatory requirements and make informed decisions on applicability, compensating controls, and residual risk at a global scale.
Risk Modelling and Control Strategy: Determine residual risk and define control measures based on defense-in-depth principles and systemic risk considerations, ensuring alignment with the organization’s risk appetite and strategic objectives.
Executive Advisory Role: Provide strategic guidance to senior leadership and influence risk posture decisions that impact business growth and regulatory compliance.
Enterprise Leadership: Act as a senior executive with overarching responsibility for Information Security governance, risk, and compliance, ensuring alignment with organizational strategy and objectives.
Strategic Risk Decisions: Validate and approve recommendations for mitigating business and technology risks, ensuring alignment with enterprise priorities.
Risk Appetite Alignment: Provide authoritative guidance to ensure risk mitigation strategies adhere to the bank’s defined risk appetite and tolerance levels.
Regulatory Assurance: Ensure compliance with complex regulatory requirements across jurisdictions, preventing penalties and safeguarding the organization’s reputation.
Control Adequacy Oversight: Confirm the effectiveness and adequacy of controls against internal security policies, global standards, data privacy obligations, and local regulatory mandates.
Executive Advisory Role: Influence executive-level decisions on security posture, risk management, and compliance priorities.
Job details are sourced from the employer's original posting.
Open job postingAbout the company
Mashreq Bank is a leading financial institution in the UAE, offering a wide range of banking and financial services.