Save Job Back to Search Job Description Summary Similar JobsLead ISO 27001, SOC 2 and security assurance for a FintechBuild and operate controls directly with tech teams.About Our ClientA growing FS organisation in the Middle East.Job DescriptionLead the day-to-day security governance, certification and assurance programme.Own the ISMS, including ISO 27001 certification, surveillance, recertification and continual improvement.Lead SOC 2 Type I / II readiness and examination activities, including control mapping, evidence management and auditor coordination.Build and maintain security control frameworks, policies, evidence programmes and remediation processes.Work directly with engineering, product and operational teams to implement and improve security controls.Perform control testing, identify deficiencies and drive remediation through to verified closure.Coordinate external audits, due diligence, security questionnaires and assurance requests.Develop clear reporting on certification status, control effectiveness, findings, exceptions and remediation.Improve assurance activities through automation, reusable evidence, continuous monitoring and appropriate GRC tooling.The Successful ApplicantAt least 10 years' experience across information security, security assurance, technology risk or a related discipline, including a minimum of five years in security GRC or assurance.Experience in fintech, payments, digital banking, investment, financial services or another regulated environment.Direct experience leading ISO 27001 certification and operating an ISMS.Direct experience leading SOC 2 Type I and/or Type II readiness and examinations.A track record of personally implementing controls, building evidence programmes and driving audits and remediation to successful outcomes.Experience working closely with engineering, cloud and product teams in cloud environments.Practical experience supporting external audits, client diligence and customer security assessments.Tangible experience in AI governance, AI risks or security assurance.Relevant qualifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM or CISSP would be advantageous.What's on OfferA senior individual contributor role with direct access to the leadership.The opportunity to build and operate the security governance and assurance architecture for a cloud native business.ContactRuwise SheriffQuote job refJN-092026-7102820Job summarySectorTechnologySubsectorSenior TechnicalIndustryTechnology & TelecomsWhereInternationalContract typePermanentConsultant nameRuwise SheriffJob referenceJN-092026-7102820