VP & Head of Audit, Information Security

First Abu Dhabi Bank FAB

Abu Dhabi

On-site

AED 360,000 - 600,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

FAB seeks a subject matter expert to plan and execute audits across Information Security, BCM, Data Domain (Governance, Privacy, Analytics & AI), GT and System Integration projects domestically and internationally. You will assess risk, ensure compliance with regulatory expectations, and escalate major findings with action plans.

The role requires in-depth IS/IT domain knowledge, strong communication with management, and leadership in guiding junior staff while aligning with FAB's risk

Qualifications

  • Bachelor's degree required.
  • CISA, CISSP, CISM or CSX certifications desirable.
  • Strong knowledge of information security, data governance, BCM and IT risk management.

Responsibilities

  • Lead audits of Information Security, BCM, IT, Data Domain and System Integration within FAB Group and subsidiaries.
  • Ensure audits meet Annual Plan objectives and are completed efficiently and on schedule.
  • Communicate potential delays or changes to the Head of Audit.
  • Provide guidance and on-the-job training to junior colleagues.
  • Promote ethics and values within the team and bank culture.
  • Develop risk-based audit programs and maintain audit universe across jurisdictions.

Skills

CISA Certification
CISSP
CISM
CSX
Information Security
Data Governance
Risk Management

Education

Bachelor's degree

Job description

JOB PURPOSE: A subject matter expert responsible for planning and executing audits covering the activities and processes of Group Security Office (GSO), Business Continuity Management (BCM), Data Domain (Data Governance, Data Privacy, Data Analytics & AI), Group Technology (GT) & System Integration Projects domestically and in all international locations as well as related peripheral activities across the FAB Group. Thorough understanding of IS, IT, BCM, Data & Integration domains, business/ relationship aspects, risk management processes and the regulatory environment, both in UAE and other relevant jurisdictions where FAB operates and apply them to auditable areas to provide assurance to Management by identifying weaknesses; reporting and escalating significant Audit findings in a timely manner; and agreeing action plans to address the issues raised. Act as the day-to-day contact with Management in GSO, GT and Data Functions and related areas influencing change through providing advice. As part of the GIA Extended Management Team (EMT), provide input to GIA on issues that have impact on the FAB Group as a whole. Conduct special investigations, reviews, additional tasks as and when required by GCAO / EVP / SVP.

KEY ACCOUNTABILITIES:

Strategic Contribution

  • Lead audits of FAB Group s Information Security, BCM, Information Technology, Data Domain (Data Governance, Data Privacy, Data Analytics & AI) & System Integration functions and related activities in the UAE and across the international network (functional). Furthermore, Group Subsidiaries with Information Security, Technology, BCM, Data Domain and System Integration presence will be covered.
  • Ensure that audits in Information Security, BCM, Data Domain (Data Governance, Data Privacy, Data Analytics & AI) & System Integration areas are conducted in accordance with the objectives laid down in the Annual Plan and ensure that the work program is completed in an efficient and effective manner on or ahead of schedule.
  • Inform Head of Audit of any potential delays and/or changes to the Annual Plan.

People Management

  • In undertaking audits: Provide guidance and on the job training for junior colleagues and conduct knowledge sharing to facilitate achievement of team objectives and completion of tasks in an efficient manner which is consistent with operating procedures and policy.
  • Promote the organization s values and ethics in all activities within the team to support the establishment of a value driven culture within the bank.

Budgeting and Financial Performance

  • Monitor the financial performance of given areas of activities versus budgets and ensure all activities are carried out in line with the approved guidelines while promptly reporting on any variances to management.

Policies, Systems, Processes & Procedures

  • Execute to established GIA Policies, Guidance Notes, Procedures and Practice Notes in undertaking all tasks.
  • Provide input to the development of GIA practices as per industry standards and regulatory expectations.
  • Review all the activities of the Units within Information Security, Technology, Data Domain and System Integration related activities in all the jurisdictions in which the groups operate to define and maintain the Audit Universe. Coordinate with other teams to ensure efficient and effective coverage.
  • Prepare and maintain a Risk Assessment of each of the Process Streams within Information Security, Technology, Data Domain and System Integration related Units and applicable subsidiaries (e.g. international entity) as identified in the Audit Universe. In this respect, work with the businesses to promote periodic self-assessment of risks and controls.
  • Establish/update and maintain Audit programs in the central audit management tool.
  • Conduct audits of the Processes within Information Security, Technology, Data Domain and System Integration related activities and assess if:
    • Divisional/Unit Line management have identified and classified the risks in their activities.
    • Governance, risk management and control procedures are adequate, effective and efficient to reduce risks of errors, omissions and loss to acceptable levels at an acceptable cost.
    • Improvements/enhancements to the governance, risk management and internal control structure are required.
    • Data and transaction processing meet the required standards of reliability, integrity and availability.
    • The Division s/Unit s assets are being safeguarded.
    • The use of resources is efficient and effective.
    • Draft audit report submitted by auditors are properly reviewed and finalized.
    • Audit report is discussed and finalized with GIA management/client within 6 weeks of completion of fieldwork.
  • Negotiate with Unit management to agree a documented Management Action Plan to resolve the issues raised.

Continuous Improvement

  • Lead the identification of change through continuous improvement of processes and practices considering global standards and changes in the business environment which demand proactive action plans.

Relationship Management

  • Develop and maintain effective business relationships with all relevant external/internal entities and stakeholders with the highest standards of business ethics, whilst promptly attending to all critical issues in-order to ensure the services required by the organization are delivered in the most effective manner.
  • Act as the Audit Business Partner for Line Managers within Information Security, Technology, Data Domain and System Integration Functions and actively manage the relationship through regular meetings with Line Managers to promote this concept and identify emerging risks. Such meetings should also be used to discuss any material gaps between audit assessment or risks and controls and the businesses self-assessment.
  • Ongoing consultancy/advice is provided to Unit management from a governance, risk management and control perspective for improvements in their processes to ensure effective and efficient controls, on the basis of market best practices.
  • On an ongoing basis, ensure pending audit issues are followed up with Unit management and that all corrective actions are fully and properly implemented.
  • Conduct any investigations/special reviews assigned by Head of Audit/GCAO.

Reporting

  • Ensure that all functional reports are prepared timely and accurately and meet Group requirements, policies and quality standards.

Desired Candidate Profile

  • Minimum Qualification Bachelor s degree.
  • Relevant post-graduate qualification and/or relevant professional qualification and/ or certification desirable.
  • CISA Certification is essential and any additional relevant certifications such as CISSP, CISM & CSX.
  • Minimum 10 years relevant experience with an International Bank or Big 4.
  • Internal Audit experience strongly preferred (but not mandatory).
  • At least 5 years similar positions of progressively increasing managerial responsibilities in the Bank Operations, Risk Management and/or Audit function.
  • Expert knowledge of operational activities and processes and associated risks within the Information Security, Cyber Security, BCM, Technology and Data domains, including the control frameworks and standards commonly used to design and assess controls in those domains.
  • Strong working knowledge and demonstrable ability to interpret regulatory expectations across multiple jurisdictions in the domains of Information security, Technology, BCM and Data Management.
  • Strong leadership capability and team-oriented with highly developed problem-solving skills.
  • Self-directed, able to manage multiple tasks and ability to work under pressure.
  • Excellent analytical skills.
  • Exceptional verbal and written communication skills, with a strong ability to comprehend, articulate, and translate complex technology, cybersecurity, and business concepts for diverse stakeholders.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP And Head Of Audit Information Security
VP And Head Of Audit Information Security

First Abu Dhabi Bank (FAB) • Abu Dhabi

On-site
AED 280,000 - 360,000
AVP & Audit Manager- Operations & Support Functions (Emiratised Role)
AVP & Audit Manager- Operations & Support Functions (Emiratised Role)

First Abu Dhabi Bank • Abu Dhabi

On-site
AED 300,000 - 480,000
Specialist, Audit - Operations & Support Functions (Emiratized Role)
Specialist, Audit - Operations & Support Functions (Emiratized Role)

First Abu Dhabi Bank (FAB) • Abu Dhabi

On-site
AED 180,000 - 300,000
VP & Head of Audit, Information Security
VP & Head of Audit, Information Security

First Abu Dhabi Bank • Abu Dhabi

On-site
AED 300,000 - 460,000
VP & Senior Audit Manager, Enterprise Risk Management
VP & Senior Audit Manager, Enterprise Risk Management

First Abu Dhabi Bank (FAB) • Abu Dhabi

On-site
AED 240,000 - 420,000
AVP & Audit Manager, Personal Banking (Emiratized)
AVP & Audit Manager, Personal Banking (Emiratized)

First Abu Dhabi Bank (FAB) • Abu Dhabi

On-site
AED 300,000 - 480,000
AVP & Audit Manager- Consumer Banking (Emiratized)
AVP & Audit Manager- Consumer Banking (Emiratized)

First Abu Dhabi Bank • Abu Dhabi

On-site
AED 250,000 - 360,000
AVP & Audit Manager, Personal Banking
AVP & Audit Manager, Personal Banking

First Abu Dhabi Bank FAB • Abu Dhabi

On-site
AED 536,000 - 837,000
Associate Vice President - IT Audit
Associate Vice President - IT Audit

Rakbank • United Arab Emirates

On-site
AED 350,000 - 520,000
Audit Manager - Business Credit
Audit Manager - Business Credit

First Abu Dhabi Bank • Al Ruways Industrial City

On-site
AED 45,000 - 65,000