تفاصيل الوظيفة
تابي تبحث عن أخصائي أمن معلومات (GRC) للعمل في الرياض، السعودية. سيتولى المرشح الناجح تنفيذ أنشطة الحوكمة والمخاطر والامتثال بشكل مستقل ضمن برنامج أمن المعلومات لدى تابي.
المهام والمسؤوليات
- الحفاظ على وثائق إطار حوكمة أمن المعلومات، مكتبة السياسات، والمعايير والإجراءات المرتبطة وتحديثها.
- صياغة ومراجعة سياسات أمن المعلومات ومعاييره وأسسه، مع ضمان التوافق مع المتطلبات التنظيمية السارية والأهداف التجارية.
- مراقبة وتتبع التغييرات في المتطلبات القانونية والتنظيمية والتعاقدية التي تؤثر على أمن المعلومات (SAMA CSF, PDPL, NCA ECC, PCI-DSS) وتحديث سجل الامتثال وفقاً لذلك.
- الحفاظ على مصفوفات المسؤوليات (RACI) ووثائق لجان حوكمة أمن المعلومات وحزم التقارير وتحديثها.
- تنسيق اجتماعات لجنة حوكمة الأمن - إعداد جداول الأعمال والمحاضر ومتابعة الإجراءات.
- إنتاج مواد الاتصال الداخلي والخارجي المتعلقة بحوكمة أمن المعلومات والسياسات وتحديثات البرنامج.
- تنفيذ تقييمات مخاطر أمن المعلومات بشكل مستقل، وتطبيق منهجية تقييم المخاطر وإنتاج سجلات مخاطر كاملة مع التهديدات ونقاط الضعف والاحتمالية والتأثير وخطط المعالجة.
- الحفاظ على سجل أصول المعلومات وتحديثه - تتبع مالكي الأصول وتصنيفاتها وملامح المخاطر المرتبطة.
- قيادة أنشطة جمع بيانات تقييم تأثير الأعمال (BIA) بالتنسيق مع مالكي الأصول ووحدات الأعمال لجمع أهداف الاسترداد وتصنيفات الأهمية بدقة.
- إجراء تقييمات فعالية الضوابط لضوابط أمن المعلومات الرئيسية، وتوثيق النتائج ورفع الفجوات إلى المسؤول للمعالجة.
- تنسيق تقييمات مخاطر أمن المعلومات للجهات الخارجية - إعداد استبيانات التقييم ومراجعة ردود الموردين وإنتاج ملخصات المخاطر.
- دمج بيانات المخاطر والثغرات في مراجعات المشتريات وإعداد المشاريع وعمليات إدارة التغيير.
- إعداد تقارير المخاطر الدورية للمراجعة العليا، مع تسليط الضوء على المخاطر الناشئة والتغييرات الهامة في ملف المخاطر وحالة إجراءات معالجة المخاطر.
- مراقبة وضع الامتثال للمنظمة تجاه SAMA CSF وNCA ECC وPDPL وISO 27001 وPCI-DSS - تتبع حالة الضوابط وتحديد الفجوات وتنسيق المعالجة.
- تنسيق أنشطة التدقيق الداخلي والخارجي - جمع حزم الأدلة والتواصل مع المدققين وتتبع النتائج ومراقبة تقدم المعالجة.
- دعم إعداد التقارير التنظيمية والتقييمات الذاتية وشهادات الامتثال المطلوبة من SAMA وNCA ومجلس PCI.
- الحفاظ على برنامج التوعية الأمنية وتعزيزه - تطوير مواد التدريب وجدولة الاتصالات وتتبع مقاييس الإنجاز.
- مراقبة مؤشرات الأداء الرئيسية (KPIs) ومؤشرات المخاطر الرئيسية (KRIs) لبرنامج أمن المعلومات، وإعداد لوحات بيانات دقيقة وفي الوقت المناسب لمراجعة الإدارة العليا.
- دعم دمج متطلبات أمن المعلومات في عمليات المشتريات وإدارة المشاريع والتحكم في التغيير.
- الحفاظ على مكتبة سياسات أمن المعلومات ومعاييره وإجراءاته - إدارة التحكم في الإصدار ودورات المراجعة والتوزيع.
- دعم مبادرات أمن المعلومات عبر فرق الأعمال والتقنية، وتقديم خبرة موضوعية في الحوكمة والمخاطر والامتثال (GRC) في المشاريع وبرامج التغيير.
- إجراء مراجعات تصنيف المعلومات وتوثيق متطلبات الأمن للمشاريع التجارية وتقنية المعلومات الرئيسية.
- تقديم جلسات ومواد توعية بأمن المعلومات لمجموعات مستهدفة من الموظفين.
- تقديم دعم تحليلي لأنشطة إعداد التقارير وجمع البيانات وتتبع البرنامج لفريق الحوكمة والمخاطر والامتثال.
الشروط والمتطلبات
- درجة البكالوريوس في تقنية المعلومات، علوم الحاسب، هندسة البرمجيات، الأمن السيبراني، إدارة المخاطر، أو مجال ذي صلة.
- خبرة مهنية تتراوح من 1 إلى 3 سنوات في حوكمة أمن المعلومات، إدارة المخاطر، الامتثال، أو مجال وثيق الصلة. مطلوب خبرة عملية في تنفيذ تقييم المخاطر أو تطوير السياسات أو مراقبة الامتثال. يُعد التعرض المسبق لمتطلبات SAMA CSF أو ISO 27001 أو PDPL أو NCA ECC ميزة قوية. يفضل خبرة في بيئة التكنولوجيا المالية المنظمة أو الخدمات المصرفية.
- شهادة ISO 27001 Foundation أو Lead Implementer (مفضلة). شهادة CompTIA Security+ أو ما يعادلها.
- العمل نحو الحصول على شهادة CRISC (Certified in Risk and Information Systems Control) أو CISM.
المزايا
- نحن فريق دولي من المهنيين الملهمين المنتشرين في جميع أنحاء العالم.
- لدينا ثقافة شركة شاملة تحتضن التنوع والنزاهة والشفافية. نسعى لتحقيق التوازن بين العمل والحياة ونعتز باللحظات التي تقضيها مع أحبائك خارج العمل. وبنفس روح منتجنا، نحن نهتم ونرعى موظفينا.
- يمنح موظفونا ثقة كاملة بنسبة 100% وحرية لتطبيق رؤيتهم الخاصة وطرح أفكارهم من اليوم الأول في تابي. أنت المسؤول عن مجال عملك. نشجع الجميع على التفكير واتخاذ القرارات كما لو كانت تابي أعمالهم الخاصة، لأنها كذلك. برنامج خيارات الأسهم للموظفين متاح للجميع.
- ستتاح لك فرصة التعلم والنمو في واحدة من أسرع شركات التكنولوجيا المالية نمواً في المنطقة.
- نقدم لك دعم الانتقال بالإضافة إلى إرشادك خلال العملية بأكملها.
- سنزودك بالأجهزة المطلوبة لعملك.
عرض النص الأصلي للإعلان
Department: InfoSec GRC
Employment Type: Full Time
Location: KSA
Description
We're looking for an Information Security Specialist (GRC) to join Tabby! The successful candidate will independently execute governance, risk, and compliance activities across the Tabby's information security programme.
Key Responsibilities
Information Security Governance
Employment Type: Full Time
Location: KSA
Description
We're looking for an Information Security Specialist (GRC) to join Tabby! The successful candidate will independently execute governance, risk, and compliance activities across the Tabby's information security programme.
Key Responsibilities
Information Security Governance
- Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures.
- Draft and revise information security policies, standards, and baselines, ensuring alignment with applicable regulatory requirements and business objectives.
- Monitor and track changes in legal, regulatory, and contractual requirements affecting information security (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating the compliance register accordingly.
- Maintain and update role and responsibility matrices (RACI), information security governance committee documentation, and reporting packs.
- Coordinate security governance committee meetings - preparing agendas, minutes, and action tracking.
- Produce internal and external communication materials related to information security governance, policies, and programme updates.
- Execute information security risk assessments independently, applying the organization's risk assessment methodology and producing complete risk registers with identified threats, vulnerabilities, likelihood, impact, and treatment plans.
- Maintain and update the information asset register - tracking asset owners, classifications, and associated risk profiles.
- Lead business impact assessment (BIA) data collection activities, coordinating with asset owners and business units to capture accurate recovery objectives and criticality ratings.
- Conduct control effectiveness evaluations for key information security controls, documenting findings and escalating gaps to the Lead for treatment.
- Coordinate third-party information security risk assessments - preparing assessment questionnaires, reviewing vendor responses, and producing risk summaries.
- Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes.
- Prepare periodic risk reports for senior review, highlighting emerging risks, significant changes in the risk profile, and the status of risk treatment actions.
- Monitor the organization's compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS - tracking control status, identifying gaps, and coordinating remediation.
- Coordinate internal and external audit activities - gathering evidence packages, liaising with auditors, tracking findings, and monitoring remediation progress.
- Support the preparation of regulatory submissions, self-assessments, and compliance attestations required by SAMA, NCA, and PCI Council.
- Maintain and enhance the security awareness programme - developing training materials, scheduling communications, and tracking completion metrics.
- Monitor KPIs and KRIs for the information security programme, preparing accurate and timely dashboards for senior management review.
- Support the integration of information security requirements into procurement, project management, and change control processes.
- Maintain the information security policy, standard, and procedure library - managing version control, review cycles, and distribution.
- Support information security initiatives across business and technology teams, providing GRC subject matter expertise on projects and change programmes.
- Conduct information classification reviews and document security requirements for key business and IT projects.
- Deliver information security awareness sessions and materials to targeted staff groups.
- Provide analytical support for GRC team reporting, data gathering, and programme tracking activities.
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
- 1-3 years of professional experience in information security governance, risk management, compliance, or a closely related field. Hands-on experience with risk assessment execution, policy development, or compliance monitoring is required. Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements is a strong advantage. Experience in a regulated Fintech or banking environment is preferred.
- ISO 27001 Foundation or Lead Implementer (preferred). CompTIA Security+ or equivalent.
- Working toward CRISC (Certified in Risk and Information Systems Control) or CISM.
- We are an international Team of inspired professionals located all over the globe.
- We have an inclusive company culture, embracing diversity, integrity and transparency. We strive for work-life balance and cherish the moments you spend with your loved ones, off-work. In the same spirit as for our product, we are caring and nurturing for our employees.
- Our people are granted 100% trust and freedom to apply their own vision and come up with their ideas from day 1 at Tabby. You are the one who takes responsibility for your area of work. We encourage everyone to think and make decisions like Tabby was their own business, well because it is. Our employee stock options programme is available for everyone.
- You will have an opportunity to learn and grow in one of the fastest growing fin tech companies in the region
- We offer you relocation support as well as we guide you through all the process.
- We’ll set you up with the devices required for your work.
المصدر: LinkedIn - أُضيفت للموقع في 9 سبتمبر 2026
رقم الإعلان لدى المصدر: 4465030365
رقم الإعلان لدى المصدر: 4465030365