SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Kraken, one of the world's longest-standing crypto platforms trusted by over 10 million individuals and institutions, is seeking a Deputy Regional Information Security Officer to own ICT security, operational resilience, and regulatory compliance across a portfolio of entities in the UAE and broader Middle East region.
This is a high-visibility, high-trust role for a security governance professional operating at the intersection of technology, compliance, and financial services. You will serve as the named ICT security officer for appointed entities, with formal accountability to their boards and regulators. This is not a support function—you will be the primary regulatory contact and accountable for security risk, ICT governance, and resilience oversight.
Key Responsibilities:
- Serve as the named ICT security officer for your entity portfolio, with board-level accountability for security risk and governance
- Prepare and present security, risk, and compliance reporting to entity boards and senior management committees
- Act as the primary point of contact for VARA (Virtual Asset Regulatory Authority) and other regulators on ICT and security matters, including examinations, inspections, and licensing interactions
- Lead ICT and security risk assessments across your entity portfolio, maintaining live risk registers and tracking remediation against regulatory SLAs
- Own entity-level ICT policies aligned with VARA cybersecurity requirements, local frameworks, and group standards
- Coordinate control testing, evidence documentation, and audit preparation with global security and compliance teams
- Manage classification, escalation, and regulatory reporting of ICT-related incidents within required timeframes
- Lead business impact assessments, critical function mapping, and business continuity planning at the entity level
- Oversee continuity and recovery testing to meet regulatory expectations
- Maintain oversight of ICT third-party dependencies and outsourcing arrangements
- Act as the primary interface between your entities and the Regional Information Security Officer Lead
- Drive local implementation of group frameworks, policies, and resilience standards, adapting them for jurisdiction-specific requirements
- Support entity go-live processes and establishment of ICT governance frameworks for new market launches
- Participate in regional incident response processes and post-incident reviews
- Coordinate with cross-functional stakeholders to embed security requirements into operational processes
You will operate at the frontier of virtual asset regulation, building ICT governance programs from scratch for new market entries while maintaining established operations. The role offers direct exposure to C-level executives and regulators across multiple jurisdictions, with intentional scope for growth as Kraken's entity footprint expands into additional regulatory frameworks (Asian, EU frameworks such as DORA).
Requirements:
- 7+ years of experience in information security governance, ICT risk management, or regulatory compliance in a regulated financial services, fintech, or virtual asset environment
- Direct experience as a named regulatory contact, involvement in regulatory examinations, supervisory interactions, licensing processes, or equivalent
- Familiarity with UAE regulatory frameworks; experience with VARA or other virtual asset/crypto-native regulatory regimes strongly preferred
- Demonstrated ability to build compliance or governance programs from the ground up, not only maintain established ones
- Experience conducting risk assessments, business impact analyses, and resilience planning at the entity level
- Familiarity with ICT outsourcing and third-party risk management within group structures
- Ability to translate technical risk into board-level narrative and regulatory-grade documentation
- Comfortable operating across multiple jurisdictions simultaneously, each at different stages of regulatory maturity
- Strong project management skills and ability to drive outcomes across cross-functional, globally distributed teams
- Certifications such as CISSP, CISM, CRISC, CISA, or ISO27001 Lead Implementer preferred
- Familiarity with EU frameworks such as DORA and MiCA strongly preferred