Kraken
Deputy Regional Information Security Officer
United Arab Emirates
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Mid level
- Country
- AE
- Work mode
- Remote-friendly
- First seen by hirly
- 1 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Building the Future of Open Finance
Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.
Before you apply, we encourage you to explore our culture page to understand what drives us and how we work.
The team
Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.
We are looking for a Deputy Regional Information Security Officer to own ICT security, operational resilience, and regulatory compliance across a portfolio of entities at different stages of maturity, from established licensed operations to new markets launching under frameworks. This is not a support function. You will be the named security officer for your entities, accountable to their boards and their regulators.
This is a high-visibility, high-trust role for a security governance professional who thrives at the intersection of technology, compliance, and financial services, and who is energised by the challenge of building from the ground up as much as sustaining what already exists.
Payward is one of the world's most trusted and secure digital asset platforms, operating across a growing network of regulated entities spanning Europe, the Middle East, and Asia Pacific. As we expand into new markets and deepen our regulatory footprint, the demand for embedded, senior-level ICT security leadership at the entity level has never been higher.
The opportunity
Prepare, contribute and report to regional risk governance and board committee meetings, highlighting control status, risk exposure, and readiness
Execute risk assessments and control testing across UAE operations in line with VARA cybersecurity guidelines and security best practices
Maintain and review Business Impact Assessments (BIA), integrating findings into global resilience planning
Contribute to Business Continuity Plan (BCP) documentation, testing, and updates, including entity-specific scenarios
Collaborate with Group Security and IT to:
Align UAE-specific regulatory controls with global policies and control frameworks
Contribute to the development of security policies to meet international and UAE compliance requirements
Conduct security control validation and document evidence for internal/external audits
Participate in remediation planning for audit findings and track progress to closure
Support the RISO in preparing and submitting regulatory documentation to regulators
Prepare and present security and resilience reports for internal governance committees and local entity management
Assist in responses to regulatory examinations, including due diligence and compliance queries
Liaise with compliance and legal teams to interpret regulatory changes and propose control adaptations
Participate in the regional incident response process, assist with post-incident reviews, and support continuous improvement activities
Coordinate with cross-functional stakeholders to embed security requirements into operational processes
What You Will Do
Regulatory Governance
Serve as the named ICT security officer for your appointed entities, with formal accountability for security risk, ICT governance, and resilience oversight at board level
Prepare and present security, risk, and compliance reporting to entity boards and senior management committees
Act as the primary point of contact for VARA and other relevant regulatory authorities on ICT and security matters -- including examinations, inspections, licensing interactions, and ongoing supervisory dialogue
Support entity go-live processes, including the establishment of ICT governance frameworks for new market launches from the ground up
As the portfolio evolves, engage with additional regulatory frameworks with support from the broader RISO team
ICT Risk and Security
Lead ICT and security risk assessments across your entity portfolio, maintaining live risk registers and tracking remediation against regulatory SLAs
Own entity-level ICT policies and ensure they remain aligned with VARA cybersecurity requirements, applicable local frameworks, and group standards
Coordinate control testing, evidence documentation, and audit preparation with global security and compliance teams
Manage the classification, escalation, and regulatory reporting of ICT-related incidents within the timeframes required by applicable regulators
Operational Resilience
Lead business impact assessments, critical function mapping, and business continuity planning at the entity level
Oversee continuity and recovery testing, ensuring outputs meet regulatory expectations and feed back into global resilience planning
Maintain oversight of ICT third-party dependencies and outsourcing arrangements in line with regulatory requirements
Group Liaison
Act as the primary interface between your entities and the RISO Lead, ensuring local regulatory requirements are accurately represented in group-level decisions
Drive local implementation of group frameworks, policies, and resilience standards, adapting them where jurisdiction-specific requirements demand
Represent entity priorities in group-led security initiatives and governance forums
What you bring
7+ years of experience in information security governance, ICT risk management, or regulatory compliance in a regulated financial services, fintech, or virtual asset environment
Direct experience as a named regulatory contact, involvement in regulatory examinations, supervisory interactions, licensing processes, or equivalent
Familiarity with UAE regulatory frameworks. Experience with VARA or other virtual asset / crypto-native regulatory regimes is a significant advantage and strongly preferred
Demonstrated ability to build compliance or governance programs from the ground up, not only to maintain established ones
Experience conducting risk assessments, business impact analyses, and resilience planning at the entity level
Familiarity with ICT outsourcing and third-party risk management within group structures
Ability to translate technical risk into board-level narrative and regulatory-grade documentation
Comfortable operating across multiple jurisdictions simultaneously, each at a different stage of regulatory maturity
Strong project management skills and the ability to drive outcomes across cross-functional, globally distributed teams
Certifications such as CISSP, CISM, CRISC, CISA, or ISO27001 Lead Implementer preferred
Familiarity with EU frameworks such as DORA and MiCA is strongly preferred
Why this role
You will hold a named role within a regulated entity with accountability and board-level visibility
You will operate at the frontier of virtual asset regulation -- VARA is one of the most advanced and fastest-evolving crypto regulatory frameworks in the world, and you will be shaping how Kraken meets it from day one of market entry
You will build ICT governance programs from scratch for new market entries, not inherit and maintain what others have set up
You will work with direct exposure to C-level executives and regulators across multiple jurisdictions, in an environment that rewards ownership and technical depth equally
The scope of this role is intentionally designed to grow -- as Kraken's entity footprint expands, so does the portfolio and the regulatory breadth you will be exposed to, potentially including Asian and EU frameworks such as DORA
You will join a remote-first, international team shaping the future of crypto asset governance an
Similar jobs
- Security Officer - voco Dubai®IHG Career · United Arab EmiratesFirst seen 4d ago
- Security OfficerMarriott · Dubai, United Arab EmiratesFirst seen 4d ago
- Facility Security Officer Valaratomics · Torrance, California, United StatesFirst seen today
- Security Officer- Cleveland, TNWaldensecurity · ChattanoogaFirst seen today
- Court Security Officer, Cedar Rapids, IAWaldensecurity · Federal Services DivisionFirst seen today
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job