Information Security Manager – MEA
Core
Manage technical risk exposure and regulatory compliance for Apex Group's Middle East and Africa (MEA) entities, aligning with global cyber strategy and local data protection laws.
Role type
Senior IC Information Security Manager (Technical Risk & Compliance)
Builds
Regional compliance posture and risk management frameworks for GCC and African financial entities
Domain
Financial Services / Cybersecurity / Regulatory Compliance
Deliverable
client delivery
Required skills
GCC/Africa financial sector cyber risk expertise, regulatory alignment (UAE PDPL, DIFC, SAMA CSF, NCA ECC, POPIA), risk assessment (RCSA), metrics definition (KRIs/KPIs), stakeholder management, executive presentation, framework integration (NIST, ISO 27001, COBIT), audit readiness (SOX 404)
Preferred skills
Cloud security (Azure/AWS), IAM/PAM platforms (CyberArk, SailPoint), ISO 27001 Lead Auditor, CISM/CRISC certifications
Technologies
Azure, AWS, CyberArk, SailPoint, NIST CSF 2.0, ISO/IEC 27001:2022, COBIT 2019, PCI DSS
Responsibilities
Govern consent/legal bases and breach reporting under UAE PDPL; Apply DIFC data protection amendments; Implement SAMA CSF and NCA ECC controls; Enforce POPIA compliance in South Africa; Map controls to Apex Gold Standard and global frameworks; Define and govern regional KRIs/KPIs; Lead annual RCSA and drive remediation; Coordinate with regulators and business heads; Prepare executive-level risk presentations; Ensure SOX 404 alignment for ICFR/ITGCs; Drive SecurityScorecard activities.
Seniority
Senior, hands-on IC