Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Client of Michael Page is seeking a senior Information Security professional to lead governance, risk and compliance across ISO 27001 and SOC 2 readiness. You will own the ISMS, coordinate audits, and drive remediation with engineering and product teams in a fintech/regulatory environment.
The role requires 10+ years in information security or risk, with five+ years in GRC or assurance, and relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISA or CISSP desirable.
A growing FS organisation in the Middle East
Lead the day-to-day security governance certification and assurance programme Own the ISMS including ISO 27001 certification surveillance recertification and continual improvement Lead SOC 2 Type I II readiness and examination activities including control mapping evidence management and auditor coordination Build and maintain security control frameworks policies evidence programmes and remediation processes Work directly with engineering product and operational teams to implement and improve security controls Perform control testing identify deficiencies and drive remediation through to verified closure Coordinate external audits due diligence security questionnaires and assurance requests Develop clear reporting on certification status control effectiveness findings exceptions and remediation Improve assurance activities through automation reusable evidence continuous monitoring and appropriate GRC tooling
At least 10 years experience across information security security assurance technology risk or a related discipline including a minimum of five years in security GRC or assurance Experience in fintech payments digital banking investment financial services or another regulated environment Direct experience leading ISO 27001 certification and operating an ISMS Direct experience leading SOC 2 Type I and or Type II readiness and examinations A track record of personally implementing controls building evidence programmes and driving audits and remediation to successful outcomes Experience working closely with engineering cloud and product teams in cloud environments Practical experience supporting external audits client diligence and customer security assessments Tangible experience in AI governance AI risks or security assurance Relevant qualifications such as ISO 27001 Lead Implementer or Lead Auditor CISA CRISC CISM or CISSP would be advantageous At least 10 years' experience across information security, security assurance, technology risk or a related discipline, including a minimum of five years in security GRC or assurance. Experience in fintech, payments, digital banking, investment, financial services or another regulated environment. Direct experience leading ISO 27001 certification and operating an ISMS. Direct experience leading SOC 2 Type I and/or Type II readiness and examinations. A track record of personally implementing controls, building evidence programmes and driving audits and remediation to successful outcomes. Experience working closely with engineering, cloud and product teams in cloud environments. Practical experience supporting external audits, client diligence and customer security assessments. Tangible experience in AI governance, AI risks or security assurance. Relevant qualifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM or CISSP would be advantageous.