Senior Information Security Governance & Assurance Manager
Michael Page · Abu Dhabi
Job description
About the role
We are seeking a senior professional to lead the day‑to‑day security governance, certification and assurance programme for a fast‑growing financial services organisation in the Middle East. You will own the Information Security Management System (ISMS) and drive continuous improvement across ISO 27001 and SOC 2 compliance.
Key responsibilities
- Own the ISMS, manage ISO 27001 certification, surveillance, recertification and continual improvement.
- Lead SOC 2 Type I/II readiness, control mapping, evidence collection and auditor coordination.
- Build and maintain security control frameworks, policies, evidence programmes and remediation processes.
- Collaborate with engineering, product and operations teams to implement and enhance security controls.
- Perform control testing, identify gaps and drive remediation to verified closure.
- Coordinate external audits, due‑diligence requests, security questionnaires and assurance activities.
- Develop clear reporting on certification status, control effectiveness, findings and remediation.
- Automate assurance activities using GRC tooling, reusable evidence and continuous monitoring.
Required profile
- Minimum 10 years of experience in information security, security assurance or technology risk, with at least 5 years in security GRC or assurance.
- Background in fintech, payments, digital banking or other regulated financial environments.
- Proven experience leading ISO 27001 certification and operating an ISMS.
- Hands‑on experience with SOC 2 Type I/II readiness and examinations.
- Track record of implementing controls, building evidence programmes and driving successful audits.
- Experience working closely with engineering, cloud and product teams in cloud environments.
- Practical exposure to AI governance or AI‑related security risks.
- Relevant certifications (e.g., ISO 27001 Lead Implementer/Auditor, CISA, CRISC, CISM, CISSP) are a plus.
Required skills
- ISO 27001
- SOC 2
- GRC tooling
- Cloud environments
- AI governance
What we offer
- Senior individual contributor role with direct access to leadership.
- Opportunity to build and operate security governance and assurance architecture for a cloud‑native business.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United Arab Emirates.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 weeks ago
Expires 1 month from now
45 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Michael Page
Abu Dhabi
Related job offers
-
Audio-visual Engineer
Integrated Communication Network Abu Dhabi -
Product Manager – Investment Lifecycle SaaS
Inception42 Abu Dhabi -
Lead Consultant – GRC (Governance, Risk & Compliance)
CPX Piceance Abu Dhabi -
IT Project Manager
Employeur non precise Al Reem Island -
IT Support Specialist - Emirati
Mediclinic Mediclinic Corporate Office Du