AVP, InfoSec Risk Management

Network International

United Arab Emirates

On-site

AED 300,000 - 540,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Network International is seeking a senior specialist in information security risk management to own risk identification, assessment, quantification and reporting across key regions. This role feeds into the ERM framework and risk appetite statements.

You will mature risk methodology, manage risk registers, and provide executive summaries to the Group Head, GRC, and Group CISO while monitoring risk appetite and governance processes.

Qualifications

  • Demonstrated experience operating risk-assessment methodologies (likelihood × impact, 5×5) at enterprise scale.
  • Proven ability to quantify and aggregate risk for executive audiences.
  • Experience presenting risk appetite and KRI reporting to boards and regulators.
  • MEA regulatory exposure preferred – multiple market central bank frameworks.

Responsibilities

  • Operate and mature the information security risk-assessment methodology and risk register across key regions.
  • Lead risk assessments for major projects, platforms, and third-party engagements, tracking changes through lifecycle.
  • Quantify risk and prepare executive reporting for Group Head, GRC, and Group CISO.
  • Monitor performance against appetite statements and escalate breaches per policy.

Skills

Security Risk Management Advanced
Cyber Risk Advanced
Cyber Security Policies Advanced
Information Governance Advanced
Risk Governance Intermediate
Third Party Risk Management Intermeda

Education

Bachelor's degree in information security or related discipline
Postgraduate qualification (advantage)

Job description

Network International is the leading enabler of digital commerce across the Middle East and Africa, providing payment technology and services to banks, merchants, fintechs and governments.

This role is Group Information Security's senior specialist individual contributor for information security risk management — the risk craft within the Group's second line of defence. It owns the identification, assessment, quantification, treatment tracking and reporting of information security risk across Network International's key regions, feeding directly into the Group's Enterprise Risk Management (ERM) framework and risk appetite statement.

2. Key Responsibilities

Operate and continuously mature the information security risk-assessment methodology (likelihood × impact, 5×5 scoring) and the Group's information security risk register, ensuring ratings, ownership and advisory content remain accurate and current across all key regions.

Lead risk assessments for major projects, platforms, technology changes and third-party engagements, identifying and rating information security risk at the point of initiation and tracking material changes through their lifecycle.

Perform risk quantification and aggregation — translating technical findings into business-relevant exposure — for executive reporting to the Group Head, GRC, the Group CISO and senior stakeholders.

Monitor performance against the Board-approved risk appetite statement and elevate breaches or near-breaches through the defined escalation path within agreed service levels.

Design and maintain the information security Key Risk Indicator (KRI) suite and own its reporting into the Technology Advisory Committee (TAC) and Enterprise Risk Management Committee (ERMC) cycles.

Own risk treatment and exception management, ensuring every open item carries a named owner, an agreed treatment plan and a target closure date, and that time-bound risk acceptances are properly authorised and tracked to expiry.

Maintain an emerging-risk watch — including AI, agentic systems and supply-chain exposure — working jointly with the AI & Data Security Governance domain to ensure novel risk types are captured, assessed and reported before they mature into incidents.

Support the security policy lifecycle and regulatory compliance activities — control testing, audit evidence and certification support — flexing across the wider risk and compliance agenda as required.

Identify opportunities to streamline and automate risk and compliance processes — automated evidence collection, workflow tooling and control-testing automation — and drive their adoption.

3. Governance & Interfaces

Operates within the second line of defence, providing independent risk challenge to the first line (Cyber Resilience Operations, Security Architecture & Engineering, Technology).

Reports information security risk assessments, KRIs and appetite-monitoring status to the Group's executive risk and technology committees.

Interfaces with the Group Enterprise Risk Management function under the Chief Risk Officer, ensuring information security risk is consistently represented in the Group's risk taxonomy and appetite statement.

Partners with AI & Data Security Governance on emerging AI and agentic risk, ensuring novel risk types are captured and reported through the standard risk channel.

Coordinates with Internal Audit on risk-register evidence and treatment-tracking progress.

4. Qualifications & Experience

Bachelor's degree in information security, risk management, business or a related discipline; a relevant postgraduate qualification is an advantage.

8–12 years of experience in information security or technology risk, with depth specifically in risk management; banking, payments or financial-services (BFSI) experience strongly preferred.

MEA regulatory exposure preferred — CBUAE, SAMA, CBJ, CBN, SARB or equivalent multi-market central bank frameworks.

Demonstrated experience operating a risk-assessment methodology (likelihood × impact, 5×5 scoring) and a risk register at group or enterprise scale, including risk quantification and aggregation for executive audiences.

Proven experience presenting risk-appetite status and KRI reporting to executive and Board-level committees, including regulator and audit engagements.

5. Professional Certifications

CRISC (Certified in Risk and Information Systems Control) or CISM (Certified Information Security Manager)

Preferred

CISSP (Certified Information Systems Security Professional)

FAIR (Open FAIR) risk quantification certification

ISO 27005

6. Skills (NI Security Functional Skills Framework)

Proficiency levels shown are calibrated to Job Level P4 in the Information Security functional skills framework.

Skill (NI Security Functional Skills Framework)

Security Risk Management Advanced

Cyber Risk Advanced

Cyber Security Policies Advanced

Information Governance Advanced

Risk Governance Intermediate

Third Party Risk Management Intermediate

Job Info
  • Job Identification 260000546
  • Job Category Managers
  • Posting Date 08/19/2026, 12:11 PM
  • Job Schedule Full time
  • Locations Al Barsha, Street 23, Al Mafraq Road, Opp. Al Salam Mosqu, Dubai, AE
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, AI & Data Security Governance
Manager, AI & Data Security Governance

HUMAN-AI-Z Nexus Technology • Dubai

On-site
AED 300,000 - 500,000
Manager AI And Data Security Governance
Manager AI And Data Security Governance

Network International • Dubai

On-site
AED 600,000 - 900,000
Assistant Manager, InfoSec Programme & Change Management
Assistant Manager, InfoSec Programme & Change Management

Network International • United Arab Emirates

On-site
AED 502,000 - 725,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

myZoi | Financial Inclusion Technologies • Dubai

On-site
AED 700,000 - 1,500,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

myZoi • Dubai

On-site
AED 1,000,000 - 1,500,000
Manager Security Implementation and Operations ( UAE National )
Manager Security Implementation and Operations ( UAE National )

DU UAE • United Arab Emirates

On-site
AED 180,000 - 220,000
Information Security Consultant
Information Security Consultant

United Al Saqer Group • Abu Dhabi

On-site
AED 180,000 - 260,000
Manager Security Implementation and Operations ( UAE National )
Manager Security Implementation and Operations ( UAE National )

FMS.AE • United Arab Emirates

On-site
AED 120,000 - 150,000
Senior InfoSec Risk Management Leader
Senior InfoSec Risk Management Leader

Network International • United Arab Emirates

On-site
AED 300,000 - 540,000
Senior Risk Solution Delivery Manager
Senior Risk Solution Delivery Manager

Abu Dhabi Islamic Bank PJSC • Abu Dhabi

On-site
AED 300,000 - 400,000