Skip to content

Open nowPosted 29 hours ago

Deputy Regional Information Security Officer

kraken.com80 open roles

Where
United Arab Emirates
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDeputy Regional Information Security Officerkraken.com · United Arab Emirates
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on kraken.com's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market. kraken.com postings stay open a median of 1 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 29 hours ago

kraken.com median: 1 days open

The posting

BUILDING THE FUTURE OF OPEN FINANCE

Payward - the parent company behind Kraken, NinjaTrader, Breakout, xStocks, Payward Services and CF Benchmarks - has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.

Before you apply, we encourage you to explore our culture page https://www.kraken.com/culture to understand what drives us and how we work.

THE TEAM

Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.

We are looking for a Deputy Regional Information Security Officer to own ICT security, operational resilience, and regulatory compliance across a portfolio of entities at different stages of maturity, from established licensed operations to new markets launching under frameworks. This is not a support function. You will be the named security officer for your entities, accountable to their boards and their regulators.

This is a high-visibility, high-trust role for a security governance professional who thrives at the intersection of technology, compliance, and financial services, and who is energised by the challenge of building from the ground up as much as sustaining what already exists.

Payward is one of the world's most trusted and secure digital asset platforms, operating across a growing network of regulated entities spanning Europe, the Middle East, and Asia Pacific. As we expand into new markets and deepen our regulatory footprint, the demand for embedded, senior-level ICT security leadership at the entity level has never been higher.

THE OPPORTUNITY

- Prepare, contribute and report to regional risk governance and board committee meetings, highlighting control status, risk exposure, and readiness

- Execute risk assessments and control testing across UAE operations in line with VARA cybersecurity guidelines and security best practices

- Maintain and review Business Impact Assessments (BIA), integrating findings into global resilience planning

- Contribute to Business Continuity Plan (BCP) documentation, testing, and updates, including entity-specific scenarios

  • Collaborate with Group Security and IT to:
  • Align UAE-specific regulatory controls with global policies and control frameworks
  • Contribute to the development of security policies to meet international and UAE compliance requirements

- Conduct security control validation and document evidence for internal/external audits

- Participate in remediation planning for audit findings and track progress to closure

- Support the RISO in preparing and submitting regulatory documentation to regulators

- Prepare and present security and resilience reports for internal governance committees and local entity management

- Assist in responses to regulatory examinations, including due diligence and compliance queries

- Liaise with compliance and legal teams to interpret regulatory changes and propose control adaptations

- Participate in the regional incident response process, assist with post-incident reviews, and support continuous improvement activities

- Coordinate with cross-functional stakeholders to embed security requirements into operational processes

WHAT YOU WILL DO

  • Regulatory Governance
  • Serve as the named ICT security officer for your appointed entities, with formal accountability for security risk, ICT governance, and resilience oversight at board level
  • Prepare and present security, risk, and compliance reporting to entity boards and senior management committees
  • Act as the primary point of contact for VARA and other relevant regulatory authorities on ICT and security matters -- including examinations, inspections, licensing interactions, and ongoing supervisory dialogue
  • Support entity go-live processes, including the establishment of ICT governance frameworks for new market launches from the ground up
  • As the portfolio evolves, engage with additional regulatory frameworks with support from the broader RISO team
  • ICT Risk and Security
  • Lead ICT and security risk assessments across your entity portfolio, maintaining live risk registers and tracking remediation against regulatory SLAs
  • Own entity-level ICT policies and ensure they remain aligned with VARA cybersecurity requirements, applicable local frameworks, and group standards
  • Coordinate control testing, evidence documentation, and audit preparation with global security and compliance teams
  • Manage the classification, escalation, and regulatory reporting of ICT-related incidents within the timeframes required by applicable regulators
  • Operational Resilience
  • Lead business impact assessments, critical function mapping, and business continuity planning at the entity level
  • Oversee continuity and recovery testing, ensuring outputs meet regulatory expectations and feed back into global resilience planning
  • Maintain oversight of ICT third-party dependencies and outsourcing arrangements in line with regulatory requirements
  • Group Liaison
  • Act as the primary interface between your entities and the RISO Lead, ensuring local regulatory requirements are accurately represented in group-level decisions
  • Drive local implementation of group frameworks, policies, and resilience standards, adapting them where jurisdiction-specific requirements demand
  • Represent entity priorities in group-led security initiatives and governance forums

WHAT YOU BRING

- 7+ years of experience in information security governance, ICT risk management, or regulatory compliance in a regulated financial services, fintech, or virtual asset environment

- Direct experience as a named regulatory contact, involvement in regulatory examinations, supervisory interactions, licensing processes, or equivalent

- Familiarity with UAE regulatory frameworks. Experience with VARA or other virtual asset / crypto-native regulatory regimes is a significant advantage and strongly preferred

- Demonstrated ability to build compliance or governance programs from the ground up, not only to maintain established ones

- Experience conducting risk assessments, business impact analyses, and resilience planning at the entity level

- Familiarity with ICT outsourcing and third-party risk management within group structures

- Ability to translate technical risk into board-level narrative and regulatory-grade documentation

- Comfortable operating across multiple jurisdictions simultaneously, each at a different stage of regulatory maturity

- Strong project management skills and the ability to drive outcomes across cross-functional, globally distributed teams

- Certifications such as CISSP, CISM, CRISC, CISA, or ISO27001 Lead Implementer preferred

- Familiarity with EU frameworks such as DORA and MiCA is strongly preferred

WHY THIS ROLE

- You will hold a named role within a regulated entity with accountability and board-level visibility

- You will operate at the frontier of virtual asset regulation -- VARA is one of the most advanced and fastest-evolving crypto regulatory frameworks in the world, and you will be shaping how Kraken meets it from day one of market entry

- You will build ICT governance programs from scratch for new market entries, not inherit and maintain what others have set up

- You will work with direct exposure to C-level executives and regulators across multiple jurisdictions, in an environment that rewards ownership and technical depth equally

- The scope of this role is intentionally designed to grow -- as Kraken's entity footprint expands, so does the portfolio and the regulatory breadth you will be exposed to, potentially including Asian and EU frameworks such as DORA

- You will join a remote-first, international team shaping the future of crypto asset governance and resilience across some of the world's most demanding regulatory environments

Unless a specific application deadline is stated in the job posting, applications are accepted on an ongoing basis.

Please note, applicants are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.

We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.

OUR COMMITMENT

Payward is powered by people from around the world and we celebrate the diverse talents, backgrounds, contributions, and unique perspectives that everyone brings to the table. We hire based on merit, seeking out people with the right abilities, knowledge, and skills for the job. We encourage you to apply for roles where you don't fully meet the listed requirements, especially if you're passionate or knowledgeable about crypto.

We may ask candidates to complete job-related skills or work-style assessments as part of our hiring process. These assessments evaluate competencies relevant to the role and are applied consistently across candidates for similar positions. Results are considered alongside experience and interviews, and are not the sole basis for any employment decision.

As an equal opportunity employer, we don't tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, or local laws.

Stay connected

Follow us on Twitter https://twitter.com/krakenfx

Learn on the Kraken Blog https://blog.kraken.com/#:~:text=Enter%20your%20email%20address

Connect on LinkedIn https://www.linkedin.com/company/kraken-exchange/

Candidate Privacy Notice https://www.kraken.com/legal/candidate-privacy-notice

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against kraken.com's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on kraken.com's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    kraken.com's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.