Talentmate
United Arab Emirates
20th August 2026
2608-3191-214
1. Role Purpose
Network International is the leading enabler of digital commerce across the Middle East and Africa, providing payment technology and services to banks, merchants, fintechs and governments.
This role is Group Information Securitys senior specialist individual contributor for information security risk management — the risk craft within the Groups second line of defence. It owns the identification, assessment, quantification, treatment tracking and reporting of information security risk across Network Internationals key regions, feeding directly into the Groups Enterprise Risk Management (ERM) framework and risk appetite statement.
2. Key Responsibilities
Operate and continuously mature the information security risk-assessment methodology (likelihood × impact, 5×5 scoring) and the Groups information security risk register, ensuring ratings, ownership and advisory content remain accurate and current across all key regions.
Lead risk assessments for major projects, platforms, technology changes and third-party engagements, identifying and rating information security risk at the point of initiation and tracking material changes through their lifecycle.
Perform risk quantification and aggregation — translating technical findings into business-relevant exposure — for executive reporting to the Group Head, GRC, the Group CISO and senior stakeholders.
Monitor performance against the Board-approved risk appetite statement and escalate breaches or near-breaches through the defined escalation path within agreed service levels.
Design and maintain the information security Key Risk Indicator (KRI) suite and own its reporting into the Technology Advisory Committee (TAC) and Enterprise Risk Management Committee (ERMC) cycles.
Own risk treatment and exception management, ensuring every open item carries a named owner, an agreed treatment plan and a target closure date, and that time-bound risk acceptances are properly authorised and tracked to expiry.
Maintain an emerging-risk watch — including AI, agentic systems and supply-chain exposure — working jointly with the AI & Data Security Governance domain to ensure novel risk types are captured, assessed and reported before they mature into incidents.
Support the security policy lifecycle and regulatory compliance activities — control testing, audit evidence and certification support — flexing across the wider risk and compliance agenda as required.
Identify opportunities to streamline and automate risk and compliance processes — automated evidence collection, workflow tooling and control-testing automation — and drive their adoption.
3. Governance & Interfaces
Operates within the second line of defence, providing independent risk challenge to the first line (Cyber Resilience Operations, Security Architecture & Engineering, Technology).
Reports information security risk assessments, KRIs and appetite-monitoring status to the Groups executive risk and technology committees.
Interfaces with the Group Enterprise Risk Management function under the Chief Risk Officer, ensuring information security risk is consistently represented in the Groups risk taxonomy and appetite statement.
Partners with AI & Data Security Governance on emerging AI and agentic risk, ensuring novel risk types are captured and reported through the standard risk channel.
Coordinates with Internal Audit on risk-register evidence and treatment-tracking progress.
4. Qualifications & Experience
Bachelors degree in information security, risk management, business or a related discipline; a relevant postgraduate qualification is an advantage.
8–12 years of experience in information security or technology risk, with depth specifically in risk management; banking, payments or financial-services (BFSI) experience strongly preferred.
MEA regulatory exposure preferred — CBUAE, SAMA, CBJ, CBN, SARB or equivalent multi-market central bank frameworks.
Demonstrated experience operating a risk-assessment methodology (likelihood × impact, 5×5 scoring) and a risk register at group or enterprise scale, including risk quantification and aggregation for executive audiences.
Proven experience presenting risk-appetite status and KRI reporting to executive and Board-level committees, including regulator and audit engagements.
5. Professional Certifications
Essential
CRISC (Certified in Risk and Information Systems Control) or CISM (Certified Information Security Manager)
Preferred
CISSP (Certified Information Systems Security Professional)
FAIR (Open FAIR) risk quantification certification
ISO 31000 familiarity
ISO 27005
6. Skills (NI Security Functional Skills Framework)
Proficiency levels shown are calibrated to Job Level P4 in the Information Security functional skills framework.
| Skill (NI Security Functional Skills Framework) | Expected Proficiency |
|---|---|
| Security Risk Management | Advanced |
| Cyber Risk | Advanced |
| Cyber Security Policies | Advanced |
| Information Governance | Advanced |
| Risk Governance | Intermediate |
| Third Party Risk Management | Intermediate |
| Role Level: | Executive-Level | Work Type: | Full-Time |
|---|---|---|---|
| Country: | United Arab Emirates | City: | Dubai |
| Company Website: | https://www.network.ae | Job Function: | Security & Risk Management |
| Company Industry/ Sector: |
IT Services and IT Consulting | ||
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.