Director of Information Security - GRC
by Chalhoub Group in Fashion & Luxury Retail
The Director of Information Security - GRC (Governance, Risk & Compliance) is a senior leadership role responsible for governing and institutionalizing cybersecurity risk, regulatory compliance, and control frameworks across global operations within a luxury retail environment. The role leads the design, implementation, and continuous enhancement of enterprise-wide GRC programs to enable risk-informed decision-making, regulatory confidence, and security accountability across all business units. It involves defining and executing the Information Security GRC strategy aligned with corporate risk management, technology transformation, and global expansion, including operating model design, team structure, and KPIs. The position develops and maintains Group-wide security policies, standards, and procedures aligned with ISO 27001, NIST CSF, COBIT, and integrates governance with HR, Legal, and IT service management. It owns the Information Security Risk Management Framework (ISRMF), covering identification, assessment, prioritization, treatment, and monitoring of risks, leveraging risk quantification models such as FAIR and GRC platforms. The role ensures compliance with global and regional regulations including UAE PDPL, KSA PDPL, EU GDPR, PCI-DSS, ISO 27001/22301, and leads internal and external audits, ISO certification efforts, regulatory inspections, and audit evidence management. It oversees Third-Party Cybersecurity Risk Management (TPCRM), including due diligence, onboarding controls, contract clauses, and reassessments, working with Procurement and Legal. Additionally, it manages GRC technology and automation, integrating GRC systems with ITSM, Risk Registers, and Incident Management platforms, while driving workflow automation, dashboards, and metrics. The role also leads cybersecurity awareness programs including simulated phishing and executive training, partnering with Legal, Internal Audit, Data Privacy, Procurement, HR, Retail Operations, and Technology to embed policies and ensure adherence to global and regional standards.