Jobs›Deputy Regional

Deputy Regional Information Security Officer

Kraken · Across India
PayPay not listed
WhereAcross India
TypeFull time
Posted1 Oct3 days ago, via Adzuna
Kaam checked
No fee, deposit or pay-to-apply signs
Good spoken and written English expected
Day work
No vehicle or licence needed
About this job

Home

/

Jobs

/

Kraken

Deputy Regional Information Security Officer

Kraken

United Arab Emirates

Posted yesterday

Apply

Building the Future of Open Finance

Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.

Before you apply, we encourage you to explore our culture page to understand what drives us and how we work.

The team

Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.

We are looking for a Deputy Regional Information Security Officer to own ICT security, operational resilience, and regulatory compliance across a portfolio of entities at different stages of maturity, from established licensed operations to new markets launching under frameworks. This is not a support function. You will be the named security officer for your entities, accountable to their boards and their regulators.

This is a high-visibility, high-trust role for a security governance professional who thrives at the intersection of technology, compliance, and financial services, and who is energised by the challenge of building from the ground up as much as sustaining what already exists.

Payward is one of the world's most trusted and secure digital asset platforms, operating across a growing network of regulated entities spanning Europe, the Middle East, and Asia Pacific. As we expand into new markets and deepen our regulatory footprint, the demand for embedded, senior-level ICT security leadership at the entity level has never been higher.

The Opportunity & Scope

Prepare, contribute and report to regional risk governance and board committee meetings, highlighting control status, risk exposure, and readiness

Execute risk assessments and control testing across UAE operations in line with VARA cybersecurity guidelines and security best practices

Maintain and review Business Impact Assessments (BIA), integrating findings into global resilience planning

Contribute to Business Continuity Plan (BCP) documentation, testing, and updates, including entity-specific scenarios

Collaborate with Group Security and IT to

Align UAE-specific regulatory controls with global policies and control frameworks

Contribute to the development of security policies to meet international and UAE compliance requirements

Conduct security control validation and document evidence for internal/external audits

Participate in remediation planning for audit findings and track progress to closure

Support the RISO in preparing and submitting regulatory documentation to regulators

Prepare and present security and resilience reports for internal governance committees and local entity management

Assist in responses to regulatory examinations, including due diligence and compliance queries

Liaise with compliance and legal teams to interpret regulatory changes and propose control adaptations

Participate in the regional incident response process, assist with post-incident reviews, and support continuous improvement activities

Coordinate with cross-functional stakeholders to embed security requirements into operational processes

Key Responsibilities

Regulatory Governance

Serve as the named ICT security officer for your appointed entities, with formal accountability for security risk, ICT governance, and resilience oversight at board level

Prepare and present security, risk, and compliance reporting to entity boards and senior management committees

Act as the primary point of contact for VARA and other relevant regulatory authorities on ICT and security matters -- including examinations, inspections, licensing interactions, and ongoing supervisory dialogue

Support entity go-live processes, including the establishment of ICT governance frameworks for new market launches from the ground up

As the portfolio evolves, engage with additional regulatory frameworks with support from the broader RISO team

ICT Risk and Security

Lead ICT and security risk assessments across your entity portfolio, maintaining live risk registers and tracking remediation against regulatory SLAs

Own entity-level ICT policies and ensure they remain aligned with VARA cybersecurity requirements, applicable local frameworks, and group standards

Coordinate control testing, evidence documentation, and audit preparation with global security and compliance teams

Manage the classification, escalation, and regulatory reporting of ICT-related incidents within the timeframes required by applicable regulators

Operational Resilience

Lead business impact assessments, critical function mapping, and business continuity planning at the entity level

Oversee continuity and recovery testing, ensuring outputs meet regulatory expectations and feed back into global resilience planning

Maintain oversight of ICT third-party dependencies and outsourcing arrangements in line with regulatory requirements

Group Liaison

Act as the primary interface between your entities and the RISO Lead, ensuring local regulatory requirements are accurately represented in group-level decisions

Drive local implementation of group frameworks, policies, and resilience standards, adapting them where jurisdiction-specific requirements demand

Represent entity priorities in group-led security initiatives and governance forums

Candidate Profile & Mindset

7+ years of experience in information security governance, ICT risk management, or regulatory compliance in a regulated financial services, fintech, or virtual asset environment

Direct experience as a named regulatory contact, involvement in regulatory examinations, sup

Never pay to get work. If a listing asks for a fee, it is a scam. The ten signs →

Apply on Adzuna
Opens hashtagweb3.com in a new tab