Verified current Job

AVP, InfoSec Risk Management

AVP, InfoSec Risk Management at Network International — United Arab Emirates. **1. Role Purpose** Network International is the leading enabler of digital commerce across the Middle East and Africa, providing payment technology and...

Job Full source details
Network International Source published Aug 19, 2026 Verified 2 weeks ago
✓ 100% verification score · Source: Network International Careers (Oracle) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.

Overview

AVP, InfoSec Risk Management at Network International — United Arab Emirates. **1. Role Purpose** Network International is the leading enabler of digital commerce across the Middle East and Africa, providing payment technology and services to banks, merchants, fintechs and governments. This role is Group Information Security's senior specialist individual contributor for information security risk management — the risk craft within the Group's second line of defence.

Full job description

1. Role Purpose

Network International is the leading enabler of digital commerce across the Middle East and Africa, providing payment technology and services to banks, merchants, fintechs and governments.

This role is Group Information Security's senior specialist individual contributor for information security risk management — the risk craft within the Group's second line of defence. It owns the identification, assessment, quantification, treatment tracking and reporting of information security risk across Network International's key regions, feeding directly into the Group's Enterprise Risk Management (ERM) framework and risk appetite statement.

2. Key Responsibilities

  • Operate and continuously mature the information security risk-assessment methodology (likelihood × impact, 5×5 scoring) and the Group's information security risk register, ensuring ratings, ownership and advisory content remain accurate and current across all key regions.
  • Lead risk assessments for major projects, platforms, technology changes and third-party engagements, identifying and rating information security risk at the point of initiation and tracking material changes through their lifecycle.
  • Perform risk quantification and aggregation — translating technical findings into business-relevant exposure — for executive reporting to the Group Head, GRC, the Group CISO and senior stakeholders.
  • Monitor performance against the Board-approved risk appetite statement and escalate breaches or near-breaches through the defined escalation path within agreed service levels.
  • Design and maintain the information security Key Risk Indicator (KRI) suite and own its reporting into the Technology Advisory Committee (TAC) and Enterprise Risk Management Committee (ERMC) cycles.
  • Own risk treatment and exception management, ensuring every open item carries a named owner, an agreed treatment plan and a target closure date, and that time-bound risk acceptances are properly authorised and tracked to expiry.
  • Maintain an emerging-risk watch — including AI, agentic systems and supply-chain exposure — working jointly with the AI & Data Security Governance domain to ensure novel risk types are captured, assessed and reported before they mature into incidents.
  • Support the security policy lifecycle and regulatory compliance activities — control testing, audit evidence and certification support — flexing across the wider risk and compliance agenda as required.
  • Identify opportunities to streamline and automate risk and compliance processes — automated evidence collection, workflow tooling and control-testing automation — and drive their adoption.

3. Governance & Interfaces

  • Operates within the second line of defence, providing independent risk challenge to the first line (Cyber Resilience Operations, Security Architecture & Engineering, Technology).
  • Reports information security risk assessments, KRIs and appetite-monitoring status to the Group's executive risk and technology committees.
  • Interfaces with the Group Enterprise Risk Management function under the Chief Risk Officer, ensuring information security risk is consistently represented in the Group's risk taxonomy and appetite statement.
  • Partners with AI & Data Security Governance on emerging AI and agentic risk, ensuring novel risk types are captured and reported through the standard risk channel.
  • Coordinates with Internal Audit on risk-register evidence and treatment-tracking progress.

4. Qualifications & Experience

  • Bachelor's degree in information security, risk management, business or a related discipline; a relevant postgraduate qualification is an advantage.
  • 8–12 years of experience in information security or technology risk, with depth specifically in risk management; banking, payments or financial-services (BFSI) experience strongly preferred.
  • MEA regulatory exposure preferred — CBUAE, SAMA, CBJ, CBN, SARB or equivalent multi-market central bank frameworks.
  • Demonstrated experience operating a risk-assessment methodology (likelihood × impact, 5×5 scoring) and a risk register at group or enterprise scale, including risk quantification and aggregation for executive audiences.
  • Proven experience presenting risk-appetite status and KRI reporting to executive and Board-level committees, including regulator and audit engagements.

5. Professional Certifications

Essential

  • CRISC (Certified in Risk and Information Systems Control) or CISM (Certified Information Security Manager)

Preferred

  • CISSP (Certified Information Systems Security Professional)
  • FAIR (Open FAIR) risk quantification certification
  • ISO 31000 familiarity
  • ISO 27005

6. Skills (NI Security Functional Skills Framework)

Proficiency levels shown are calibrated to Job Level P4 in the Information Security functional skills framework.

Skill (NI Security Functional Skills Framework)****Expected ProficiencySecurity Risk ManagementAdvancedCyber RiskAdvancedCyber Security PoliciesAdvancedInformation GovernanceAdvancedRisk GovernanceIntermediateThird Party Risk ManagementIntermediate

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

Imported from freehire's public, keyless open-job API after the index reported the posting open. The upstream record supplied this canonical employer, ATS, or official public-board URL; repost-only sources and protected portal URLs are excluded. No login, CAPTCHA, private candidate data, or protected job-board session was accessed.

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Network International Careers (Oracle) ↗

Browse current Job and Scholarship listings from Network International Careers (Oracle) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books