تفاصيل الوظيفة
تابي تبحث عن Lead Anti-Fraud Officer للعمل في الرياض، المملكة العربية السعودية.
نبذة عن الوظيفة
يقود المسؤول الرئيسي لمكافحة الاحتيال أنشطة الحوكمة والمخاطر والامتثال المعقدة بشكل مستقل، ويعمل كخبير موضوعي في مجال واحد أو أكثر من مجالات GRC - حوكمة أمن المعلومات المؤسسية، أطر إدارة المخاطر، الامتثال التنظيمي، أو إدارة مخاطر الطرف الثالث. ينتج هذا الدور مخرجات GRC عالية الجودة، ويقدم الإرشاد الفني لأعضاء الفريق من المستوى المبتدئ والمتوسط، ويساهم بشكل مباشر في التحسين المستمر لإطار GRC وعمليات معالجة المخاطر وآليات تقارير الامتثال في المؤسسة. يعمل المسؤول الرئيسي لمكافحة الاحتيال كجسر بين التنفيذ الفني وقيادة البرامج - بالتعاون مع قادة الأقسام والشؤون القانونية والتدقيق وأصحاب المصلحة في الأعمال لتحقيق نتائج GRC ناضجة وفعالة تتوافق مع البيئة التنظيمية للتقنية المالية السعودية.
المهام والمسؤوليات
- قيادة تطوير ومراجعة وتحسين سياسات أمن المعلومات والمعايير والإجراءات وأطر الحوكمة.
- العمل كخبير موضوعي للمجالات التنظيمية المحددة، وتقديم تفسير موثوق للمتطلبات وترجمتها إلى أهداف رقابية قابلة للتنفيذ.
- مراقبة وتتبع التطورات التنظيمية والقانونية التي تؤثر على أمن المعلومات - تقييم الأثر والتوصية بتحديثات إطار الحوكمة.
- إعداد ومراجعة وثائق الحوكمة - مصفوفات RACI وتحديثات ميثاق الأمن وحزم لجنة الحوكمة - وعرض النتائج على كبار أصحاب المصلحة.
- قيادة إعداد التقييمات الذاتية التنظيمية وشهادات الامتثال، وتنسيق جمع الأدلة ومراجعة جودة الطلبات قبل الموافقة النهائية.
- إرشاد أعضاء الفريق من المستوى GR1-GR2 في جودة وثائق الحوكمة والتفسير التنظيمي ومنهجية تقييم المخاطر.
- قيادة تنفيذ تقييمات مخاطر أمن المعلومات المؤسسية المعقدة، وتطبيق منهجيات نوعية وكمية متقدمة لإنتاج ملفات مخاطر متوافقة مع شهية المخاطر.
- إدارة وصيانة سجل مخاطر أمن المعلومات المؤسسية - ضمان الدقة والتحديث والتصعيد المناسب للمخاطر الكبيرة.
- قيادة عمليات BIA للوظائف الحيوية في العمل - التنسيق مع مالكي الأصول وتحليل متطلبات الاسترداد وإنتاج مخرجات BIA لتخطيط استمرارية الأعمال والتعافي من الكوارث.
- تصميم وتنفيذ برامج اختبار فعالية الرقابة، وإنتاج تقارير النتائج مع تحليل الفجوات وتوصيات المعالجة المرتبة حسب المخاطر.
- قيادة إدارة مخاطر أمن المعلومات للطرف الثالث - تصميم أطر التقييم وإجراء مراجعات معمقة للبائعين وصيانة سجل مخاطر الطرف الثالث.
- إنتاج تقارير مخاطر على مستوى تنفيذي مع تحليل الاتجاهات وتحديد المخاطر الناشئة وتتبع تقدم المعالجة للإدارة العليا واللجان.
- قيادة أنشطة مراقبة الامتثال لـ CFFR و NCA ECC و PDPL و ISO 27001 و PCI-DSS - إنتاج تحليلات الفجوات وخطط المعالجة وتقارير حالة الامتثال الدورية.
- إدارة دورات التدقيق الداخلي والخارجي - تنسيق جمع الأدلة ومراجعة جودة الأدلة والتواصل مع المدققين ومتابعة المعالجة حتى الإغلاق.
- تصميم وتقديم برنامج التوعية الأمنية - إنتاج محتوى مستهدف لشرائح الموظفين المختلفة وعقد جلسات توعية وتحليل مقاييس الفعالية.
- تطوير وصيانة لوحات مؤشرات برنامج GRC، وضمان قياس مؤشرات الأداء الرئيسية ومؤشرات المخاطر الرئيسية بدقة وعرضها على الإدارة العليا وفق الجدول الزمني.
- قيادة دمج متطلبات أمن المعلومات في عقود الطرف الثالث وعمليات الشراء وإدماج المشاريع الكبيرة.
- المساهمة في تطوير استراتيجية برنامج أمن المعلومات، وتحديد فرص تحسين القدرات والتوصية بأولويات الاستثمار للقائد.
- العمل كنقطة اتصال رئيسية لـ GRC مع فرق الأعمال والتقنية المحددة - تقديم إرشادات الخبراء حول متطلبات الأمن ومعالجة المخاطر والتزامات الامتثال.
- قيادة مراجعات تصنيف المعلومات ومتطلبات الأمن للمشاريع التقنية والمنتجات والأعمال الهامة.
- المساهمة في قاعدة معارف GRC - تطوير قوالب وأدلة إرشادية ومواد تدريبية قابلة لإعادة الاستخدام للاستخدام الداخلي.
- تمثيل وظيفة GRC في مجموعات العمل متعددة الوظائف ولجان توجيه المشاريع والمسارات التنظيمية.
- أداء مسؤوليات إضافية يكلف بها من الإدارة.
الشروط والمتطلبات
- درجة البكالوريوس في تقنية المعلومات أو علوم الحاسب أو هندسة البرمجيات أو الأمن السيبراني أو إدارة المخاطر أو مجال ذي صلة.
- درجة الماجستير في أمن المعلومات أو إدارة المخاطر أو إدارة الأعمال تعتبر ميزة إضافية.
- خبرة مهنية متراكمة تتراوح بين 3-5 سنوات في حوكمة أمن المعلومات أو إدارة المخاطر أو الامتثال، مع خبرة مثبتة في القيادة المستقلة لدورات تقييم المخاطر أو برامج الامتثال التنظيمي أو تنسيق التدقيق.
المهارات المطلوبة
- معرفة متعمقة بإطار CFFR مطلوبة.
- خبرة في بيئة تقنية مالية منظمة أو مصرفية مفضلة بشدة.
المزايا
- ثقافة شركة شاملة تحتضن التنوع والنزاهة والشفافية.
- السعي لتحقيق التوازن بين العمل والحياة والاهتمام بأوقات الفراغ مع الأحباء.
- ثقة 100% وحرية لتطبيق رؤيتك الخاصة وتقديم أفكارك من اليوم الأول في تابي.
- برنامج خيارات الأسهم للموظفين متاح للجميع.
- فرصة للتعلم والنمو في إحدى شركات التقنية المالية الأسرع نمواً في المنطقة.
- دعم إعادة التوطين وتوجيهك خلال العملية بأكملها.
- تجهيزك بالأجهزة اللازمة لعمل.
عرض النص الأصلي للإعلان
Department: Risk B2C
Location: KSA
The Lead Anti-Fraud Officer independently leads complex governance, risk, and compliance activities and serves as a subject matter expert in one or more GRC domains - enterprise information security governance, risk management frameworks, regulatory compliance, or third-party risk management. The role produces high-quality GRC deliverables, provides technical mentoring to junior and mid-level team members, and contributes directly to the continuous improvement of the organization's GRC framework, risk treatment processes, and compliance reporting mechanisms.
The Lead Anti-Fraud Officer operates as a bridge between technical execution and programme leadership - collaborating with leads, legal, audit, and business stakeholders to drive mature and effective GRC outcomes aligned with the Saudi Fintech regulatory environment.
Key Responsibilities
- Lead the development, review, and continuous improvement of information security policies, standards, procedures, and governance frameworks.
- Serve as the subject matter expert for assigned regulatory domains, providing authoritative interpretation of requirements and translating them into implementable control objectives.
- Monitor and proactively track regulatory and legal developments affecting information security - assessing impact and recommending updates to the governance framework.
- Prepare and review governance documentation - RACI matrices, security charter updates, governance committee packs - and present findings to senior stakeholders.
- Lead the preparation of regulatory self-assessments and compliance attestations, coordinating evidence gathering and quality-reviewing submissions before senior sign-off.
- Mentor GR1-GR2 team members on governance documentation quality, regulatory interpretation, and risk assessment methodology.
- Lead the execution of complex enterprise information security risk assessments, applying advanced qualitative and quantitative methodologies to produce risk profiles aligned with the organization's risk appetite.
- Own and maintain the enterprise information security risk register - ensuring accuracy, currency, and appropriate escalation of significant risks.
- Lead BIA processes for critical business functions - coordinating with asset owners, analysing recovery requirements, and producing BIA outputs for Business Continuity and Disaster Recovery planning.
- Design and execute control effectiveness testing programmes, producing findings reports with gap analysis and risk-ranked remediation recommendations.
- Lead third-party information security risk management - designing assessment frameworks, conducting in-depth vendor reviews, and maintaining the third-party risk register.
- Produce executive-quality risk reporting with trend analysis, emerging risk identification, and treatment progress tracking for senior management and committee consumption.
- Lead compliance monitoring activities for CFFR, NCA ECC, PDPL, ISO 27001, and PCI-DSS - producing gap analyses, treatment plans, and periodic compliance status reports.
- Manage internal and external audit cycles - coordinating evidence collection, reviewing evidence quality, engaging with auditors, and tracking remediation to closure.
- Design and deliver the security awareness programme - producing targeted content for different staff segments, conducting awareness sessions, and analysing effectiveness metrics.
- Develop and maintain GRC programme metrics dashboards, ensuring KPIs and KRIs are accurately measured and presented to senior management on schedule.
- Lead the integration of information security requirements into third-party contracts, procurement processes, and major project onboarding.
- Contribute to the development of the information security programme strategy, identifying capability improvement opportunities and recommending investment priorities to the Lead.
- Serve as the primary GRC point of contact for assigned business and technology teams - providing expert guidance on security requirements, risk treatment, and compliance obligations.
- Lead information classification and security requirements reviews for significant IT, product, and business projects.
- Contribute to the GRC knowledge base - developing reusable templates, guidance documents, and training materials for internal use.
- Represent the GRC function in cross-functional working groups, project steering committees, and regulatory workstreams.
- Perform additional responsibilities as assigned by management.
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
- A Master's degree in Information Security, Risk Management, or Business Administration is an advantage.
- 3-5 years of progressive professional experience in information security governance, risk management, or compliance. Demonstrable experience independently leading risk assessment cycles, regulatory compliance programmes, or audit coordination activities.
- In-depth knowledge of the CFFR framework is required.
- Experience in a regulated Fintech or banking environment is strongly preferred.
- We have an inclusive company culture, embracing diversity, integrity and transparency. We strive for work-life balance and cherish the moments you spend with your loved ones, off-work. In the same spirit as for our product, we are caring and nurturing for our employees.
- Our people are granted 100% trust and freedom to apply their own vision and come up with their ideas from day 1 at Tabby. You are the one who takes responsibility for your area of work. We encourage everyone to think and make decisions like Tabby was their own business, well because it is. Our employee stock options programme is available for everyone.
- You will have an opportunity to learn and grow in one of the fastest growing fintech companies in the region
- We offer you relocation support as well as we guide you through all the process.
- We’ll set you up with the devices required for your work.
رقم الإعلان لدى المصدر: 4468205777