
Building the Future of Open Finance
Payward — the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks — has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.
We are looking for a Deputy Regional Information Security Officer to own ICT security, operational resilience, and regulatory compliance across a portfolio of entities at different stages of maturity, from established licensed operations to new markets launching under frameworks. This is not a support function. You will be the named security officer for your entities, accountable to their boards and their regulators.
What You Will Do
Regulatory Governance
- Serve as the named ICT security officer for your appointed entities, with formal accountability for security risk, ICT governance, and resilience oversight at board level.
- Prepare and present security, risk, and compliance reporting to entity boards and senior management committees.
- Act as the primary point of contact for VARA and other relevant regulatory authorities on ICT and security matters — including examinations, inspections, licensing interactions, and ongoing supervisory dialogue.
- Support entity go-live processes, including the establishment of ICT governance frameworks for new market launches from the ground up.
- As the portfolio evolves, engage with additional regulatory frameworks with support from the broader RISO team.
ICT Risk and Security
- Lead ICT and security risk assessments across your entity portfolio, maintaining live risk registers and tracking remediation against regulatory SLAs.
- Own entity-level ICT policies and ensure they remain aligned with VARA cybersecurity requirements, applicable local frameworks, and group standards.
- Coordinate control testing, evidence documentation, and audit preparation with global security and compliance teams.
- Manage the classification, escalation, and regulatory reporting of ICT-related incidents within the timeframes required by applicable regulators.
Operational Resilience
- Lead business impact assessments, critical function mapping, and business continuity planning at the entity level.
- Oversee continuity and recovery testing, ensuring outputs meet regulatory expectations and feed back into global resilience planning.
- Maintain oversight of ICT third-party dependencies and outsourcing arrangements in line with regulatory requirements.
Group Liaison
- Act as the primary interface between your entities and the RISO Lead, ensuring local regulatory requirements are accurately represented in group-level decisions.
- Drive local implementation of group frameworks, policies, and resilience standards, adapting them where jurisdiction-specific requirements demand.
- Represent entity priorities in group-led security initiatives and governance forums.
What You Bring
- 7+ years of experience in information security governance, ICT risk management, or regulatory compliance in a regulated financial services, fintech, or virtual asset environment.
- Direct experience as a named regulatory contact, involvement in regulatory examinations, supervisory interactions, licensing processes, or equivalent.
- Familiarity with UAE regulatory frameworks. Experience with VARA or other virtual asset / crypto-native regulatory regimes is a significant advantage and strongly preferred.
- Demonstrated ability to build compliance or governance programs from the ground up.
- Experience conducting risk assessments, business impact analyses, and resilience planning at the entity level.
- Familiarity with ICT outsourcing and third-party risk management within group structures.
- Ability to translate technical risk into board-level narrative and regulatory-grade documentation.
- Comfortable operating across multiple jurisdictions simultaneously, each at a different stage of regulatory maturity.
- Strong project management skills and the ability to drive outcomes across cross-functional, globally distributed teams.
- Certifications such as CISSP, CISM, CRISC, CISA, or ISO27001 Lead Implementer preferred.
- Familiarity with EU frameworks such as DORA and MiCA is strongly preferred.
Timezone overlap
UTC-8–-7
Open to
MENA · United Arab Emirates
Sign in to track applications and earn points.