Information Security Manager - MEA

Apex Group Ltd (India Branch)

Pune District

On-site

INR 3,500,000 - 6,500,000

Full time

29 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Apex Group Ltd (India Branch) is seeking an Information Security Manager to join the MEA technical risk team, overseeing risk exposure and compliance across GCC entities, aligning with Cyber Strategy and Group CISO directives, and integrating UAE PDPL, DIFC data protection, SAMA CSF, NCA ECC, POPIA and global frameworks.

You will drive regulatory mapping, lead risk assessments, maintain PCI DSS readiness, and collaborate with regulators and technology stakeholders to advance security maturity

Qualifications

  • 10+ years in cyber risk/compliance in GCC/Africa financial institutions.
  • Excellent communication and ability to influence diverse stakeholders.
  • Knowledge of cloud/hybrid security models (Azure, AWS).
  • Certs like CISM/CRISC or ISO 27001 Lead Auditor advantageous.
  • Familiarity with ISO 27001, SOC 2, and NIST/NIST MEA frameworks.
  • IAM/PAM concepts familiarity with CyberArk/SailPoint beneficial.
  • Strong analytical and problem‑solving skills for security engineering.
  • Ability to communicate technical concepts to diverse audiences.
  • Highly organized to manage multiple tasks in a global environment.
  • Passion for continuous learning and upskilling.

Responsibilities

  • Lead MEA regulatory alignment across PDPL, DIFC, SAMA CSF, NCA ECC, POPIA.
  • Map controls to Apex Gold Standard and international frameworks.
  • Define KRIs/KPIs and lead RCSA with remediation actions.
  • Coordinate with regulators, business heads, and technology stakeholders.
  • Maintain PCI DSS readiness for payments.
  • Ensure SOX 404 alignment where applicable and assist audits.
  • Drive SecurityScorecard activities.

Skills

Cyber risk
Regulatory compliance
Security governance
Cloud security
Stakeholder mgmt
Communication
Analytical skills

Education

Bachelor's degree
CISM/CRISC
ISO 27001 Lead Auditor

Tools

CyberArk
SailPoint
Azure
AWS

Job description

Information Security Manager

– Will be working as the MEA technical risk team to manage risk exposure and compliance across GCC entities. Align with Cyber Strategy and Group CISO directives; deliver inputs to the Global Technology Risk Forum and host local technology risk forums; and integrate UAE PDPL, Dubai International Financial Centre (DIFC) Data Protection, Saudi SAMA Cybersecurity Framework, Saudi NCA Essential Cybersecurity Controls (ECC), South Africa POPIA, plus global frameworks (NIST CSF 2.0, ISO/IEC 27001, ISO 31000, COBIT 2019, PCI DSS).

Key duties and responsibilities:
Security Engineering
  • MEA Regulatory Alignment: UAE (Federal PDPL): Govern consent/legal bases, DPO roles, breach reporting, cross border transfer requirements; coordinate with UAE Data Office guidance.
  • DIFC: Apply DIFC data protection and recent amendments; manage scope across controllers/processors and stable arrangements; ensure rights, transparency, and fines awareness.
  • Saudi Arabia: SAMA CSF for financial entities—governance, defense, response/recovery; maturity expectations.
  • NCA ECC (incl. ECC 2 updates): implement governance/defense/resilience/third party/cloud/ICS controls; follow national reporting obligations.
  • South Africa (POPIA): Enforce lawful processing, breach notification, and data subject rights under POPIA and Information Regulator oversight.
  • Framework Integration: Map controls to Apex Gold Standard, NIST CSF 2.0, ISO/IEC 27001:2022, ISO 31000, COBIT 2019; maintain PCI DSS readiness for payments.
  • Metrics, RCSA, & TRF: Define MEA KRIs/KPIs; lead RCSA; drive remediation; publish Technology Risk Forum packs with clear risk narratives. Govern regional KRIs/KPIs and ensure fit-for-purpose metrics mapped to risk appetite.
  • Stakeholder Management & Communication: Coordinate with local regulators, business heads, and technology stakeholders; deliver concise executive-level presentations.
  • Lead annual RCSA with ISO 31000 risk principles: close remediation actions.
  • Maintain compliance to NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019; sustain PCI DSS v4.0/v4.0.1 for payments.
  • Feed clear, decision ready inputs to the Technology Risk Forum; coordinate with application/infra/service owners to turn metrics green.
  • Ensure SOX 404 (where applicable) alignment for ICFR/ITGCs, coordinate management assessment and external audit readiness.
  • Drive SecurityScorecard activities.
  • Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities.
  • Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.
Experience and Knowledge:
  • Min. 10 years in Cyber risk/ Technical Risk /Compliance in GCC/Africa financial institutions; practical delivery across UAE PDPL, DIFC, SAMA CSF, NCA ECC, POPIA landscapes.
  • Exceptional communication, presentation, and articulation skills; ability to influence diverse stakeholder groups.
  • Good knowledge of cloud and hybrid security models (Azure, AWS, or equivalent).
  • Industry certifications advantageous (e.g., CISM/ CRISC, ISO 27001 Lead Auditor; cloud security certs.).
  • Familiarity with frameworks such as ISO 27001, SOC 2, and NIST, MEA, PDPL,DIFC, NCA ECC, SAMA CSF, POPIA etc.
  • Experience with IAM/PAM concepts and platforms (CyberArk, SailPoint, etc.) is beneficial but not required.
  • Strong analytical and problem‑solving skills with a methodical approach to security engineering.
  • Ability to communicate technical concepts clearly to both technical and non‑technical audiences.
  • Highly organized, with the ability to manage multiple tasks in a fast‑paced global environment.
  • Passion for continuous learning, upskilling, and improving security capabilities.
What you will get in return:
  • High visibility within a fast‑growing global organization.
  • Opportunity to work with a diverse and international team of security professionals.
  • Exposure to leading security technologies across multiple environments and jurisdictions.
  • A role where your contributions directly improve the organization’s security maturity.
  • Professional development opportunities, including certifications and hands‑on learning.
  • A positive, supportive, and collaborative work environment.
  • A unique opportunity to grow within one of the world’s leading independent fund administrators.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager - MEA
Information Security Manager - MEA

Apex Group Ltd (UK Branch) • Pune District

On-site
INR 4,000,000 - 9,000,000
High visibility
Diverse team
Professional development
+1
Information Security Manager – MEA
Information Security Manager – MEA

Apex Group • Pune District

On-site
INR 1,800,000 - 2,800,000
Information Security Manager – MEA
Information Security Manager – MEA

CO_AFATI Apex Fund Services LLP • Pune District

On-site
INR 3,000,000 - 6,000,000
High visibility in a global org
Diverse international security team
Professional development & certs
Senior Manager–Cybersecurity & Cyber Defense Center
Senior Manager–Cybersecurity & Cyber Defense Center

Mashreq • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Information Security Risk Manager
Information Security Risk Manager

Riskpro India Ventures • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Principal Info Security Risk Engineer IND [T500-29476]
Principal Info Security Risk Engineer IND [T500-29476]

FM • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Manager - Information Security
Manager - Information Security

Ashok Maheshwary & Associates • Gurugram District

Hybrid
INR 2,000,000 - 3,800,000
GAIN Central IT - Information Security Manager
GAIN Central IT - Information Security Manager

GAIN • Maharashtra

On-site
INR 1,000,000 - 1,500,000
Senior Manager Information Security
Senior Manager Information Security

InterGlobe Enterprises • Gurugram District

On-site
INR 1,800,000 - 2,800,000
Information Security II-SUPPORT SERVICES-CTO - Support services
Information Security II-SUPPORT SERVICES-CTO - Support services

Kotak Mahindra Bank • Mumbai

On-site
INR 2,500,000 - 4,500,000