📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

Tanami تعلن عن وظيفة مسؤول أمن المعلومات في الرياض

Information Security Officer
🏢 Tanami
🕒 نُشرت: (منذ 25 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تنضم شركة Tanami إلى فريقها كمسؤول أمن المعلومات (Information Security Officer) في الرياض، السعودية. تهدف Tanami إلى إعادة تشكيل الوصول إلى الأسواق الخاصة في الشرق الأوسط وخارجه من خلال بناء الأنظمة الأساسية والتجارب الشاملة التي تجعل الأسواق الخاصة متاحة.

المهام والمسؤوليات

  • المسؤولية الكاملة عن برنامج أمن المعلومات - مجموعة الضوابط، والسياسات، والأدلة التي تثبت فعالية كل ضابط.
  • إدارة سجل مخاطر أمن المعلومات: تحديد، وتقييم، وتتبع، وإعداد التقارير.
  • قيادة التواصل التنظيمي في الشؤون الإلكترونية، بما يشمل عمليات التفتيش، والتقديمات، والمراسلات.
  • إدارة دورة اختبار الاختراق السنوية - تحديد النطاق، واختيار الطرف الثالث، وفرز النتائج، والتحقق من الإغلاق.
  • تحديد خطوط الأساس للتصلب والتكوين عبر بيئة السحابة والإنتاجية.
  • إدارة أدوات الأمن - إدارة الثغرات، والاستجابة للحوادث، وخدمات أمن السحابة.
  • المسؤولية عن دفاتر تشغيل الاستجابة للحوادث، واختبارها دورياً، والعمل كقائد للحوادث عند حدوثها.
  • إجراء تقييمات مخاطر أمن الموردين والجهات الخارجية، بما في ذلك شركاء المنصة والتكنولوجيا المالية.
  • تقديم تقارير عن حالة الضوابط ونضج الأمن إلى الإدارة العليا.

الشروط والمتطلبات

  • خبرة سابقة في ملكية أمن المعلومات ضمن الخدمات المالية الخاضعة للتنظيم - سواء بتولي برنامج الأمن في شركة مرخصة أو تقديم المشورة عن قرب مع تحمل العواقب.
  • عقلية ضمان - القدرة على التحقق من الضوابط وتوثيقها بنفس القدر من الراحة في تصميمها.
  • إلمام عميق بأطر العمل المعترف بها مثل NIST CSF، ISO 27001، SOC 2، CIS، والعمل بها بشكل طبيعي دون الاعتماد على قوائم جاهزة.
  • خبرة سحابية حقيقية مع معرفة كافية بـ AWS وGCP وMicrosoft 365 لتمكين مناقشة المهندسين والتأكد من صحة إجاباتهم.
  • انضباط في إعداد الأدلة - خبرة في إنتاج أدلة تدقيق وتنظيم صمدت أمام المراجعة، ومعرفة الفرق بين ضابط موجود وضابط يمكن إثباته.
  • القدرة على التمسك بالموقف - بما في ذلك مع أصحاب المصلحة الهندسيين الكبار، وشرح الأساس المنطقي لغير التقنيين.
  • عقلية الشركات الناشئة - استقلالية عالية، وراحة مع البدء من الصفر، وتوجه نحو العمل، وعدم وجود فريق تحت الإدارة في اليوم الأول.
  • الإقامة في الرياض والجنسية السعودية (وفقاً لمتطلبات الوظيفة).
  • يفضل: خبرة متعددة الولايات القضائية (إدارة برنامج أمن تحت أكثر من جهة تنظيمية).
  • يفضل: شهادات CISM أو CRISC أو CISSP أو ما يعادلها.
  • يفضل: خبرة كأول مسؤول أمن في شركة - بناء الوظيفة بدلاً من وراثتها.
  • يفضل: الإلمام بالهياكل السحابية الأصلية وأمن التطبيقات المحمولة.
  • يفضل: خبرة في الأسواق الخاصة، أو منصات الاستثمار، أو مجال الأوراق المالية.
عرض النص الأصلي للإعلان

About Tanami

Tanami is reshaping access to private markets in the Middle East and beyond. We're building the core systems and end-to-end experiences that make private markets accessible - from secure onboarding and transaction processing to portfolio management, money movement, and reporting.

We're a small, high-ownership team building our own platform from the infrastructure up.

 

The Role

We're looking for an Information Security Officer to own security across Tanami - the standards we hold ourselves to, the evidence behind them, and the relationship with our regulators. You'll report directly to the Chief Product & Technology Officer, and you'll be our voice on cyber risk with the leadership team.

You'll set the bar and verify it's met; our engineering team builds against it. You'll hold our security tooling and visibility across the estate.


What You'll Do

  • Own our information security programme - the control set, the policies, and the evidence that proves each control works
  • Own the information security risk register: identify, assess, track, and report
  • Lead regulatory engagement on cyber matters, including inspections, submissions, and correspondence
  • Run the annual penetration testing cycle - scoping, third-party selection, findings triage, and verification of closure
  • Define hardening and configuration baselines across our cloud and productivity estate
  • Administer our security tooling - vulnerability management, incident response, and cloud security services
  • Own incident response playbooks, keep them tested, and act as incident commander when something happens
  • Run vendor and third-party security risk assessments, including our platform and fintech partners
  • Report on control status and security maturity to leadership


What We're Looking For

  • Information security ownership in regulated financial services - you've held the security programme at a licensed firm, or advised one closely enough to have carried the consequences
  • An assurance mindset - you're as comfortable verifying and evidencing a control as designing one
  • Framework fluency - you work naturally from a recognised control framework (NIST CSF, ISO 27001, SOC 2, CIS) rather than from a checklist someone handed you
  • Cloud literacy with real depth - enough AWS, GCP, and Microsoft 365 to challenge an engineer's answer and know when it doesn't hold up
  • Evidence discipline - you've produced audit and regulatory evidence that survived scrutiny, and you know the difference between a control that exists and a control you can prove
  • Able to hold a position - including with senior engineering stakeholders, and able to explain the reasoning to people who aren't technical
  • Startup DNA - high autonomy, comfortable with a blank page, biased to action, no team beneath you on day one

 

Nice to Have

  • Multi-jurisdiction experience - you've run a security programme under more than one regulator and know how to satisfy both without building two of everything
  • CISM, CRISC, CISSP or equivalent
  • Experience as the first security hire somewhere - you built the function rather than inherited it
  • Exposure to cloud-native architectures and mobile application security
  • Private-markets, investment-platform, or securities domain experience

 

Location & Work Style

This role is based in Riyadh and is open to Saudi nationals.

You'll work closely with our technology leadership and with engineers across the region, with meaningful daily overlap.

المصدر: LinkedIn - أُضيفت للموقع في 16 سبتمبر 2026
رقم الإعلان لدى المصدر: 4465996646