Information Security Manager - MEA

theapexgroup

Cape Town

On-site

ZAR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Apex Group is seeking an Information Security Manager to lead MEA cyber risk, regulatory alignment, and security program governance across GCC and Africa financial institutions. You will coordinate with the Group CISO, regulators, and business heads to implement controls, drive remediation, and ensure alignment with international frameworks.

The role requires extensive experience in ISO 27001, NIST, and cross‑border data protection, with a focus on POPIA, DIFC, PDPL, SAMA CSF, and NCA ECC.

Qualifications

  • Min. 10 years in cyber risk/technical risk/compliance in GCC/Africa financial institutions; hands‑on delivery across UAE PDPL, DIFC, SAMA CSF, NCA ECC, POPIA.
  • Exceptional communication, presentation, and articulation skills; ability to influence diverse stakeholder groups.
  • Good knowledge of cloud and hybrid security models (Azure, AWS, or equivalent).
  • Industry certifications advantageous (e.g., CISM/CRISC, ISO 27001 Lead Auditor; cloud security certs.).

Responsibilities

  • Security engineering and risk governance across MEA entities.
  • Align with cyber strategy and group directives; deliver inputs to risk forums.
  • Coordinate with regulators & business heads; provide executive level updates.
  • Lead annual RCSA using ISO 31000 principles; drive remediation actions.
  • Maintain compliance with NIST CSF 2.0, ISO 27001:2022, COBIT 2019, PCI DSS readiness.

Job description

The Apex Group was established in Bermuda in 2003 and is now one of the world's largest fund administration and middle office solutions providers.

Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.

That's why, at Apex Group, we will do more than simply 'empower' you. We will work to supercharge your unique skills and experience.

Take the lead and we'll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.

For our business, for clients, and for you

Information Security Manager - Will be working as the MEA technical risk team to manage risk exposure and compliance across GCC entities. Align with Cyber Strategy and Group CISO directives; deliver inputs to the Global Technology Risk Forum and host local technology risk forums; and integrate UAE PDPL, Dubai International Financial Centre (DIFC) Data Protection, Saudi SAMA Cybersecurity Framework, Saudi NCA Essential Cybersecurity Controls (ECC), South Africa POPIA, plus global frameworks (NIST CSF 2.0, ISO/IEC 27001, ISO 31000, COBIT 2019, PCI DSS).

Key duties and responsibilities:

Security Engineering

MEA Regulatory Alignment: UAE (Federal PDPL): Govern consent/legal bases, DPO roles, breach reporting, cross border transfer requirements; coordinate with UAE Data Office guidance.

DIFC: Apply DIFC data protection and recent amendments; manage scope across controllers/processors and stable arrangements; ensure rights, transparency, and fines awareness.

Saudi Arabia: SAMA CSF for financial entities-governance, defense, response/recovery; maturity expectations.

NCA ECC (incl. ECC 2 updates): implement governance/defense/resilience/third party/cloud/ICS controls; follow national reporting obligations.

South Africa (POPIA): Enforce lawful processing, breach notification, and data subject rights under POPIA and Information Regulator oversight.

Framework Integration: Map controls to Apex Gold Standard, NIST CSF 2.0, ISO/IEC 27001:2022, ISO 31000, COBIT 2019; maintain PCI DSS readiness for payments.

Metrics, RCSA, & TRF: Define MEA KRIs/KPIs; lead RCSA; drive remediation; publish Technology Risk Forum packs with clear risk narratives. Govern regional KRIs/KPIs and ensure fit-for-purpose metrics mapped to risk appetite.

Stakeholder Management & Communication: Coordinate with local regulators, business heads, and technology stakeholders; deliver concise executive-level presentations.

Lead annual RCSA with ISO 31000 risk principles: close remediation actions.

Maintain compliance to NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019; sustain PCI DSS v4.0/v4.1 for payments.

Feed clear, decision ready inputs to the Technology Risk Forum; coordinate with application/infra/service owners to turn metrics green.

Drive a Metric Rewrite Protocol for persistently failing metrics (RCA → redesign → pilot → cutover).

Ensure SOX 404 (where applicable) alignment for ICFR/ITGCs, coordinate management assessment and external audit readiness.

Drive SecurityScorecard activities.

Execute delegated tasks as deemed appropriate by the Group CISO and other empowered Group Cyber leadership authorities, ensuring timely and effective completion in alignment with organizational priorities.

Support the Group Cyber Strategy end-to-end, driving alignment of all activities, decisions, and deliverables with strategic objectives and business outcomes.

Experience and Knowledge:

Min. 10 years in Cyber risk/ Technical Risk /Compliance in GCC/Africa financial institutions; practical delivery across UAE PDPL, DIFC, SAMA CSF, NCA ECC, POPIA landscapes.

Exceptional communication, presentation, and articulation skills; ability to influence diverse stakeholder groups.

Good knowledge of cloud and hybrid security models (Azure, AWS, or equivalent).

Industry certifications advantageous (e.g., CISM/ CRISC, ISO 27001 Lead Auditor; cloud security certs.).

Familiarity with frameworks such as ISO 27001, SOC 2, and NIST, MEA, PDPL,DIFC, NCA ECC, SAMA CSF, POPIA etc.

Experience with IAM/PAM concepts and platforms (CyberArk, SailPoint, etc.) is beneficial but not required.

Strong analytical and problem‑solving skills with a methodical approach to security engineering.

Ability to communicate technical concepts clearly to both technical and non‑technical audiences.

Highly organized, with the ability to manage multiple tasks in a fast‑paced global environment.

Passion for continuous learning, upskilling, and improving security capabilities.

What you will get in return:

High visibility within a fast‑growing global organization.

Opportunity to work

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

MEA Information Security & Risk Leader
MEA Information Security & Risk Leader

theapexgroup • Cape Town

On-site
ZAR 1,200,000 - 1,800,000
Senior Security Engineer
Senior Security Engineer

Apex Group Ltd • Cape Town

On-site
ZAR 900,000 - 1,600,000
Head of Application Security
Head of Application Security

Apex Group Ltd (UK Branch) • Cape Town

On-site
ZAR 1,000,000 - 1,500,000
Opportunity for career growth
Collaboration with senior leaders
Head of Enterprise Security Architecture & Projects
Head of Enterprise Security Architecture & Projects

theapexgroup • Cape Town

On-site
ZAR 3,000,000 - 4,600,000
Head of Application Security
Head of Application Security

theapexgroup • Cape Town

On-site
ZAR 2,400,000 - 4,200,000
Head of Enterprise Security Architecture & Projects
Head of Enterprise Security Architecture & Projects

Apex Group Ltd • Cape Town

On-site
ZAR 900,000 - 1,200,000
Leadership development opportunities
Exposure to large-scale transformation projects
Global collaboration with technology leaders
Security Support Analyst – Identity and Access Management
Security Support Analyst – Identity and Access Management

Apex Group Ltd • Cape Town

On-site
ZAR 600,000 - 900,000
Head of Enterprise Security Architecture & Projects
Head of Enterprise Security Architecture & Projects

Apex Group • Cape Town

On-site
ZAR 1,800,000 - 2,800,000
Senior Associate Information Security Analyst
Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 900,000 - 1,300,000
Security Operations Engineer
Security Operations Engineer

Parvana • South Africa

Hybrid
ZAR 700,000 - 900,000
Hybrid work model
Career development