Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Michael Page is seeking a Sr Infosec Governance Manager to lead the day-to-day security governance, certification and assurance programme across a fintech-like environment in the Middle East. You will own and improve the ISMS, including ISO 27001 surveillance, recertification and continual improvement.
You will drive SOC 2 Type I/II readiness, coordinate audits, mapping controls to evidence, and work with engineering, product and operations to strengthen security controls across cloud
The role of Sr Infosec Governance Manager, you will lead the day-to-day security governance, certification and assurance programme
A growing FS organisation in the Middle East.
Lead the day-to-day security governance, certification and assurance programme. Own the ISMS, including ISO 27001 certification, surveillance, recertification and continual improvement. Lead SOC 2 Type I / II readiness and examination activities, including control mapping, evidence management and auditor coordination. Build and maintain security control frameworks, policies, evidence programmes and remediation processes. Work directly with engineering, product and operational teams to implement and improve security controls. Perform control testing, identify deficiencies and drive remediation through to verified closure. Coordinate external audits, due diligence, security questionnaires and assurance requests. Develop clear reporting on certification status, control effectiveness, findings, exceptions and remediation. Improve assurance activities through automation, reusable evidence, continuous monitoring and appropriate GRC tooling.
At least 10 years' experience across information security, security assurance, technology risk or a related discipline, including a minimum of five years in security GRC or assurance. Experience in fintech, payments, digital banking, investment, financial services or another regulated environment. Direct experience leading ISO 27001 certification and operating an ISMS. Direct experience leading SOC 2 Type I and/or Type II readiness and examinations. A track record of personally implementing controls, building evidence programmes and driving audits and remediation to successful outcomes. Experience working closely with engineering, cloud and product teams in cloud environments. Practical experience supporting external audits, client diligence and customer security assessments. Tangible experience in AI governance, AI risks or security assurance. Relevant qualifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM or CISSP would be advantageous.
A senior individual contributor role with direct access to the leadership. The opportunity to build and operate the security governance and assurance architecture for a cloud native business.
ISO, SOC