تفاصيل الوظيفة
شركة Moneymoon، أول شركة تقنية مالية للتمويل من فرد إلى فرد في الرياض (مرخصة من البنك المركزي السعودي)، تبحث عن مدير أمن سيبراني (بمثابة CISO) لتولي مسؤولية إدارة وظيفة الأمن السيبراني بالكامل، وتعزيز الوضع الأمني في بيئة فينـتك سعودية خاضعة للتنظيم.
المهام والمسؤوليات
- 1. حوكمة الأمن السيبراني والجاهزية التنظيمية لـ SAMA: إدارة إطار الحوكمة، السياسات، الإجراءات، والمعايير. قيادة التوافق مع إطار SAMA CSF ومتطلبات MVC، CRFR، CFFR، NCA ECC، PDPL، ISO/IEC 27001. الإشراف على التدقيقات، التقييمات، وإعداد الأدلة التنظيمية.
- 2. إدارة مخاطر الأمن السيبراني والمقاييس والتقارير: إدارة دورة حياة المخاطر (التحديد، التقييم، المعالجة، الإغلاق). الحفاظ على سجل المخاطر. تحديد مؤشرات المخاطر الرئيسية (KRIs) ومؤشرات الأداء (KPIs). أتمتة جمع المقاييس. تقديم تقارير للإدارة العليا.
- 3. العمليات الأمنية والهندسة: إدارة وتحسين القدرات الأمنية عبر البنية التحتية السحابية، IAM/PAM، نقاط النهاية، EDR، أمان البريد الإلكتروني، الشبكات، التطبيقات، APIs، إدارة الثغرات، SIEM، كشف التهديدات. إدارة دورة حياة الوصول (الانضمام، النقل، المغادرة، مراجعات الوصول). أتمتة العمليات الأمنية المتكررة.
- 4. أمن الذكاء الاصطناعي وأتمتة الأمن: العمل مع فرق التقنية والبيانات لتطوير استخدامات عملية للذكاء الاصطناعي في الأمن (كشف الشذوذ، أتمتة التنبيهات، دعم الاستجابة للحوادث). إدارة مخاطر أمنية مرتبطة باستخدام LLMs (حقن الأوامر، تسرب البيانات، إساءة الاستخدام).
- 5. أمن المنتجات والتطبيقات و APIs والسحابة: دمج متطلبات الأمن في دورة حياة المنتج. إجراء نمذجة التهديدات ومراجعات الأمان للميزات الجديدة والعمارات. الشراكة مع فرق الهندسة في Secure SDLC، اختبار الأمان، إدارة الأسرار. ضمان معالجة المتطلبات الأمنية قبل الإنتاج.
- 6. ضوابط أمن الاحتيال والتحقق: العمل مع الفرق المعنية لتعزيز الضوابط التقنية ضد استيلاء الحسابات، إساءة استخدام الهوية، والأنشطة المشبوهة التي تؤثر على منصة الإقراض.
عرض النص الأصلي للإعلان
About Us
Moneymoon is a pioneering Fintech platform transforming short-term microlending through secure, compliant, and seamless peer-to-peer technology. We enable individuals to support one another through a one-month lending model built on transparency, safety, and trust.
As we progress through the Saudi Central Bank (SAMA) Regulatory Sandbox and prepare for full licensing, strong cybersecurity governance, operational resilience, and regulatory readiness are critical to how we operate and scale.
About The Role
Moneymoon is looking for a Cybersecurity Manager acting (CISO) to own and manage the cybersecurity function end to end and strengthen our security posture as we continue to grow within a regulated Saudi fintech environment.
This is a hands-on role that combines cybersecurity governance, SAMA regulatory readiness, cyber risk management, security operations, cloud and application security, incident response, resilience, and technical security oversight.
You will work closely with Technology, Product, Data & AI, Operations, Compliance, Risk, HR, Finance, and senior leadership to ensure cybersecurity is embedded across our products, infrastructure, systems, processes, and third-party relationships.
The role requires someone who can operate across both strategy and execution - translating cybersecurity and regulatory requirements into practical controls, measurable improvements, and effective security operations.
Why This Role Matters
Every security decision has a direct impact on the business.
- The lending business. Fraud, account takeover, identity abuse, API attacks, and security failures can create direct financial exposure. Your controls protect real money and real customers.
- Speed to market. Security reviews that happen too late slow down product delivery. Your role is to make secure design and secure delivery part of the normal engineering process.
- Regulatory readiness. SAMA cybersecurity requirements are not simply a documentation exercise. They are fundamental to our ability to operate, scale, and maintain regulatory readiness.
- Customer trust. Customers trust Moneymoon with their identity, financial information, and personal data. Protecting that trust is a core responsibility of this role.
We are looking for someone who sees cybersecurity not simply as a control checklist, but as a business-critical capability that must be built, operated, measured, and continuously improved.
What You’ll Own
1. Cybersecurity Governance & SAMA Regulatory Readiness
- Own and continuously enhance Moneymoon’s cybersecurity governance framework, policies, procedures, standards, controls, and security improvement plans.
- Drive readiness and ongoing alignment with the SAMA Cyber Security Framework (SAMA CSF) and applicable regulatory cybersecurity requirements.
- Manage applicable requirements across the wider regulatory landscape, including Minimum Verification Controls (MVC), Cyber Resilience Fundamental Requirements (CRFR), Counter-Fraud Fundamental Requirements (CFFR), NCA ECC, PDPL, and ISO/IEC 27001.
- Own the cybersecurity control environment, maturity and remediation plans, supporting evidence, and regulatory documentation.
- Lead cybersecurity assessments, regulatory reviews, internal and external audits, control testing, evidence preparation, findings management, and remediation.
- Work directly with auditors, assessors, and internal stakeholders to ensure findings are addressed effectively and within required timelines.
2. Cybersecurity Risk, Metrics & Reporting
- Own the cybersecurity risk management lifecycle, including risk identification, assessment, treatment, acceptance, escalation, monitoring, and closure.
- Maintain the Cybersecurity Risk Register and ensure material risks have clear owners, treatment plans, and target dates.
- Define and monitor meaningful cybersecurity Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and security metrics.
- Automate security metrics and evidence collection from relevant systems and security tooling wherever practical.
- Provide clear reporting to senior management and relevant governance committees on cybersecurity risks, control effectiveness, incidents, vulnerabilities, and remediation progress.
- Translate technical cybersecurity issues into clear business risks and actionable recommendations.
3. Security Operations & Engineering
- Manage and continuously improve security capabilities across cloud infrastructure, IAM/PAM, endpoints, EDR, email security, networks, applications, APIs, vulnerability management, logging, SIEM, and threat detection.
- Maintain hands-on involvement in security tooling, configurations, monitoring, detections, and automation.
- Own the access lifecycle end to end, including joiners, movers and leavers, segregation of duties, privileged accounts, elevated permissions, periodic access reviews, and access remediation.
- Strengthen privileged access controls and reduce unnecessary or excessive permissions across critical systems.
- Improve and automate repetitive security processes through scripting, integrations, and security tooling wherever practical.
- Ensure relevant security events are appropriately logged, monitored, investigated, and escalated.
4. AI Security & Security Automation
- Work closely with Technology and Data & AI teams to develop practical uses of AI and automation within cybersecurity.
- Explore and implement capabilities such as anomaly detection across access and transaction patterns, automated alert triage, evidence collection, security workflow automation, and incident-response support.
- Evaluate opportunities to improve detection and response capabilities using AI/ML where there is a clear security and business benefit.
- Manage security risks associated with Moneymoon’s own use of AI and Large Language Models (LLMs).
- Establish appropriate controls against risks such as prompt injection, sensitive data leakage, insecure integrations, unauthorized access, and model misuse.
5. Product, Application, API & Cloud Security
- Embed cybersecurity requirements throughout the product and technology lifecycle.
- Conduct threat modeling and security reviews for new products, features, applications, architecture, APIs, integrations, and significant technology changes.
- Partner directly with Technology and Engineering teams on Secure SDLC, application security, API security, cloud security, secrets management, security testing, and secure architecture.
- Ensure security requirements are identified early and addressed before production deployment.
- Assess cloud environments and infrastructure configurations and drive remediation of identified security weaknesses.
- Help make secure development the standard delivery path rather than a late-stage approval gate.
6. Fraud & Verification Security Controls
- Work with relevant teams on technical security controls addressing account takeover, identity abuse, suspicious access behavior, transaction anomalies, authentication weaknesses, and application/API abuse.
- Strengthen security controls around customer authentication, identity verification, and sensitive transactions.
- Support the effective implementation and monitoring of applicable SAMA Minimum Verification Controls and Counter-Fraud requirements.
- Ensure relevant controls are operating effectively in practice and supported by appropriate evidence.
- Collaborate with relevant business, technology, risk, and compliance stakeholders where cybersecurity and fraud risks overlap.
7. Vulnerability Management, Incident Response & Cyber Resilience
- Own the vulnerability management lifecycle, including vulnerability scanning, assessment, prioritization, remediation tracking, and closure.
- Coordinate penetration testing and ensure identified findings are assigned, prioritized, remediated, and verified.
- Prioritize vulnerabilities based on actual exposure, exploitability, asset criticality, and business impact rather than severity scores alone.
- Lead cybersecurity incident response across detection, containment, investigation, eradication, recovery, root-cause analysis, lessons learned, and corrective actions.
- Maintain and continuously improve cybersecurity incident response plans and procedures.
- Support Business Continuity, Disaster Recovery, Cyber Resilience, recovery objectives, resilience testing, tabletop exercises, and incident simulations.
- Ensure lessons learned from incidents, testing, and exercises result in measurable improvements.
8. Third-Party Cybersecurity
- Manage cybersecurity assessments for vendors, technology providers, cloud services, integrations, and other critical third parties.
- Assess third-party security controls, architecture, data access, dependencies, certifications, and material cybersecurity risks.
- Go beyond questionnaire-based assessments where higher-risk vendors require deeper technical or control review.
- Work with relevant stakeholders to ensure appropriate cybersecurity requirements and obligations are incorporated into vendor agreements.
- Monitor material third-party cybersecurity risks and ensure remediation actions are tracked through closure.
9. Cybersecurity Awareness & Culture
- Drive cybersecurity awareness and training initiatives across Moneymoon.
- Ensure employees understand their cybersecurity responsibilities and the risks relevant to their roles.
- Support cybersecurity awareness during employee onboarding and throughout the employee lifecycle.
- Develop targeted awareness activities based on emerging threats, incidents, identified risks, and regulatory requirements.
- Promote practical security ownership and accountability across business and technology teams.
10. Lead Our AI Defense Capability
- Design and build AI-driven detection and response capabilities within Moneymoon’s infrastructure, including anomaly detection across transaction and access patterns, automated alert triage, automated evidence collection, and agent-assisted incident handling.
- You will have the freedom to define the approach and the accountability to make it work effectively in production.
- You will also own the security of Moneymoon’s use of AI and Large Language Models (LLMs), including protecting against risks such as prompt injection, sensitive data leakage, unauthorized access, insecure integrations, and model abuse.
What We’re Looking For
- 3+ years of progressive experience in cybersecurity, security engineering, security operations, information security, cyber risk, or a related cybersecurity function.
- Strong practical knowledge of the SAMA Cyber Security Framework (SAMA CSF) and experience implementing, assessing, or maintaining cybersecurity controls in practice.
- Understanding of the wider Saudi cybersecurity and financial regulatory environment, including MVC, CRFR, CFFR, NCA ECC, PDPL, and ISO/IEC 27001.
- Genuine hands-on cybersecurity capability, with the ability to demonstrate security controls, configurations, automation, tooling, or technical improvements personally implemented or managed.
- Practical cloud security experience with OCI, AWS, Azure, GCP, or similar production cloud environments.
- Strong experience in cybersecurity governance and risk management, including risk assessments, cybersecurity risk registers, treatment plans, risk acceptance, KPIs, and KRIs.
- Practical experience across multiple security domains, including IAM/PAM, cloud security, application and API security, vulnerability management, SIEM and detection engineering, incident response, endpoint security, and Secure SDLC.
- Experience supporting cybersecurity audits, regulatory assessments, control testing, evidence preparation, and remediation activities.
- Good understanding of cybersecurity incident management, vulnerability remediation, security monitoring, and threat detection.
- Ability to work effectively with Technology and Engineering teams while communicating cybersecurity risks clearly to business stakeholders and senior management.
- Ability to independently prioritize, drive, and close cybersecurity initiatives in a fast-paced environment.
- Strong analytical thinking, problem-solving, ownership, and stakeholder management skills.
- Strong written and verbal communication skills in English.
Preferred / Must Have
- Previous experience within fintech, lending, banking, payments, financial services, or another regulated environment.
- Experience supporting a SAMA assessment, regulatory examination, licensing readiness exercise, or cybersecurity remediation program.
- Experience with SAMA BCMF, Operational Resilience, PCI DSS, Business Continuity, Disaster Recovery, or Cyber Resilience.
- Hands-on exposure to fraud detection, transaction monitoring, identity verification, or account-takeover controls.
- Experience with cybersecurity tooling across SIEM, EDR, MDM, IAM/PAM, vulnerability management, GRC, endpoint protection, cloud security, and security monitoring.
- Scripting or automation experience using Python, Bash, PowerShell, or similar technologies.
- Experience building or implementing security automation, detection engineering, AI-enabled security capabilities, or AI/LLM security controls.
- Previous experience coordinating cybersecurity team members, cross-functional initiatives, security vendors, or managed security service providers.
- Relevant professional certifications such as CISM, CISSP, CRISC, CCSP, Security+, CySA+, SecurityX, ISO 27001 Lead Implementer/Lead Auditor, GRCP/GRCA, or equivalent.
- Cybersecurity or AI/security projects that you have personally built, automated, implemented, or shipped are highly valued.
Why Join Moneymoon?
- Competitive salary package with performance-based bonus opportunities.
- VIP Medical insurance coverage
- Annual salary review based on performance and business considerations.
- Employee Stock Ownership Plan (ESOP) eligibility, subject to the company’s applicable plan, terms, and conditions.
- Professional development support, including selected training and certification opportunities.
- Join as a founding member of the cybersecurity function and help shape how security is built and scaled at Moneymoon.
- Direct exposure to senior leadership with meaningful ownership of high-impact regulatory, technology, and business priorities.
رقم الإعلان لدى المصدر: 4463556967