Information Security Manager – MEA

CO_AFATI Apex Fund Services LLP

Pune District

On-site

INR 3,000,000 - 6,000,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

High visibility in a global org
Diverse international security team
Professional development & certs

Job summary

Apex Group is seeking an Information Security Manager to lead MEA security risk and regulatory compliance for GCC entities from Pune. You will drive governance, posture improvements, and risk reporting across multiple jurisdictions, coordinating with senior stakeholders and regulators.

You will implement and map controls to international standards (NIST, ISO 27001, COBIT) and manage cross‑border data protection, incident response, and third‑party risk, while advancing the security program across

Qualifications

  • Min. 10 years in cyber risk/technical risk/compliance within GCC/Africa financial institutions.
  • Experience across UAE PDPL, DIFC, SAMA CSF, NCA ECC, POPIA landscapes.
  • Strong communication and presentation abilities; ability to influence diverse stakeholders.
  • Familiarity with cloud/hybrid security models (Azure/AWS or equivalent).
  • Industry certifications advantageous (e.g., CISM/CRISC, ISO 27001 Lead Auditor).

Responsibilities

  • Govern MEA regulatory alignment for security and data protection across jurisdictions.
  • Map controls to Apex standards and established frameworks (NIST CSF 2.0, ISO 27001:2022, COBIT 2019, PCI DSS).
  • Lead regional KRIs/KPIs, drive remediation, and publish risk narratives.
  • Coordinate with regulators, business heads, and tech stakeholders; present at executive level.
  • Oversee governance, defense, response, and recovery for security incidents and third-party risks.
  • Support SOX/ICFR/ITGC alignment where applicable and prep for audits.

Skills

Cyber risk management
Technical risk/compliance
Cloud security (Azure/AWS)
IAM/PAM concepts
Regulatory frameworks (PDPL, DIFC, SCS
Stakeholder management
Communication skills

Tools

CyberArk
SailPoint

Job description

Information Security Manager – Will be working as the MEA technical risk team to manage risk exposure and compliance across GCC entities.

The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers. Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion. That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience. Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities. For our business, for clients, and for you

Key duties and responsibilities:

Security Engineering MEA Regulatory Alignment: UAE (Federal PDPL): Govern consent/legal bases, DPO roles, breach reporting, cross border transfer requirements; coordinate with UAE Data Office guidance. DIFC: Apply DIFC data protection and recent amendments; manage scope across controllers/processors and stable arrangements; ensure rights, transparency, and fines awareness. Saudi Arabia: SAMA CSF for financial entities—governance, defense, response/recovery; maturity expectations. NCA ECC (incl. ECC 2 updates): implement governance/defense/resilience/third party/cloud/ICS controls; follow national reporting obligations. South Africa (POPIA): Enforce lawful processing, breach notification, and data subject rights under POPIA and Information Regulator oversight. Framework Integration: Map controls to Apex Gold Standard, NIST CSF 2.0, ISO/IEC 27001:2022, ISO 31000, COBIT 2019; maintain PCI DSS readiness for payments. Metrics, RCSA, & TRF: Define MEA KRIs/KPIs; lead RCSA; drive remediation; publish Technology Risk Forum packs with clear risk narratives. Govern regional KRIs/KPIs and ensure fit-for-purpose metrics mapped to risk appetite. Stakeholder Management & Communication: Coordinate with local regulators, business heads, and technology stakeholders; deliver concise executive-level presentations. Lead annual RCSA with ISO 31000 risk principles: close remediation actions. Maintain compliance to NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019; sustain PCI DSS v4.0/v4.0.1 for payments. Feed clear, decision ready inputs to the Technology Risk Forum; coordinate with application/infra/service owners to turn metrics green. Drive a Metric Rewrite Protocol for persistently failing metrics (RCA → redesign → pilot → cutover). Ensure SOX 404 (where applicable) alignment for ICFR/ITGCs, coordinate management assessment and external audit readiness. Drive SecurityScorecard activities. Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities. Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.

Experience and Knowledge:

Min. 10 years in Cyber risk/ Technical Risk /Compliance in GCC/Africa financial institutions; practical delivery across UAE PDPL, DIFC, SAMA CSF, NCA ECC, POPIA landscapes. Exceptional communication, presentation, and articulation skills; ability to influence diverse stakeholder groups. Good knowledge of cloud and hybrid security models (Azure, AWS, or equivalent). Industry certifications advantageous (e.g., CISM/ CRISC, ISO 27001 Lead Auditor; cloud security certs.). Familiarity with frameworks such as ISO 27001, SOC 2, and NIST, MEA, PDPL,DIFC, NCA ECC, SAMA CSF, POPIA etc. Experience with IAM/PAM concepts and platforms (CyberArk, SailPoint, etc.) is beneficial but not required. Strong analytical and problem‑solving skills with a methodical approach to security engineering. Ability to communicate technical concepts clearly to both technical and non‑technical audiences. Highly organized, with the ability to manage multiple tasks in a fast‑paced global environment. Passion for continuous learning, upskilling, and improving security capabilities.

What you will get in return:

High visibility within a fast‑growing global organization. Opportunity to work with a diverse and international team of security professionals. Exposure to leading security technologies across multiple environments and jurisdictions. A role where your contributions directly improve the organization’s security maturity. Professional development opportunities, including certifications and hands‑on learning. A positive, supportive, and collaborative work environment. A unique opportunity to grow within one of the world’s leading independent fund administrators.

About Apex Group

We are dedicated to driving positive change in financial services while fuelling the growth and ambitions of asset managers, allocators, financial institutions, and family offices. Established in Bermuda in 2003, the Group has continually disrupted the asset serving industry through our investment in innovation and talent. Today, we set the pace in asset servicing and stand out for our unique single-source solution and unified cross asset‑class platform which supports the entire value chain, harnesses leading innovative technology, and benefits from cross-jurisdictional expertise delivered by a long‑standing management team and over 13,000 highly integrated professionals. We’re a people‑powered business, and our people are full of ambition. Together, we’re inspired to lead the new era of data and tech enabled service. Bringing new products and services to market. Sharpening our client focus. Disrupting the market to exceed expectations. Innovating across a range of specialisms. With our focus on making a difference to our people, our planet and our society, you’ll experience more here than you would at most other companies. Prepare to accelerate. We’re a people‑powered business with a vision to inspire a new era of service‑led FinTech. We’re expanding globally and offering more to our clients. This means you get more opportunities to grow with us. So prepare to accelerate. We’ll make sure the time and effort you put in takes you further, faster. Positive change starts with you. We’re a people‑powered business with a vision to inspire a new era of service‑led FinTech. We’re expanding globally and offering more to our clients. This means you get more opportunities to grow with us. So prepare to accelerate. We’ll make sure the time and effort you put in takes you further, faster. The journey is yours to own. When you stretch yourself, you grow. We want you to explore ways of working that will see you thrive as part of something bigger. We’ll help you with a solid structure, challenging projects, vibrant networks, supportive colleagues and approachable leaders. All the things you need to own your unique journey. Find out more about us

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Manager - MEA
Information Security Manager - MEA

Apex Group Ltd (UK Branch) • Pune District

On-site
INR 4,000,000 - 9,000,000
High visibility
Diverse team
Professional development
+1
Information Security Manager - MEA
Information Security Manager - MEA

Theapexgroup • Pune District

On-site
INR 3,000,000 - 6,000,000
High visibility
Global exposure
Information Security Manager – MEA
Information Security Manager – MEA

Apex Group • Pune District

On-site
INR 1,800,000 - 2,800,000
Security Engineer II
Security Engineer II

CO_AFATI Apex Fund Services LLP • Pune District

On-site
INR 1,400,000 - 2,100,000
High visibility in a global org
Diverse international team
Exposure to leading security tech
+2
Vice President- Client KYC
Vice President- Client KYC

CO_AFATI Apex Fund Services LLP • Pune District

On-site
INR 4,500,000 - 7,000,000
Competitive remuneration
Training and development opportunities
Global delivery team
Head of Client KYC Operations - GCC (India)
Head of Client KYC Operations - GCC (India)

CO_AFATI Apex Fund Services LLP • Pune District

On-site
INR 1,800,000 - 3,200,000
Competitive remuneration in line with
Training and development opportunities
Exposure to global delivery team
Senior Governance and Compliance Manager
Senior Governance and Compliance Manager

Apex Group • Pune District

On-site
INR 900,000 - 1,500,000
Specialist - Transfer Agency Fund Integration
Specialist - Transfer Agency Fund Integration

CO_AFATI Apex Fund Services LLP • Pune District

On-site
INR 2,500,000 - 4,500,000
Market competitive remuneration
Senior Associate 2
Senior Associate 2

Apex Group • India

On-site
INR 600,000 - 1,200,000
Senior Security Engineer - Platform
Senior Security Engineer - Platform

Apex Group Ltd (UK Branch) • Pune District

On-site
INR 3,500,000 - 5,500,000
High visibility in a global org
Diverse international team
Leading security technologies exposure
+1