📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة مدير حوكمة ومخاطر وامتثال الأمن السيبراني شاغرة لدى هلا بالرياض

Cybersecurity GRC Manager
🏢 هلا (Hala)
🕒 نُشرت: (منذ 19 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

هلا، شركة رائدة في مجال التكنولوجيا المالية في منطقة MENAP، تبحث عن مدير حوكمة ومخاطر وامتثال للأمن السيبراني (Cybersecurity GRC Manager) للعمل في الرياض، المملكة العربية السعودية.

المهام والمسؤوليات

  • تطوير وتنفيذ وتحسين إطار حوكمة أمن المعلومات، والسياسات، والمعايير، والإجراءات.
  • قيادة إنشاء وتنفيذ استراتيجية الأمن السيبراني بما يتوافق مع أهداف الشركة.
  • تقديم تقارير دورية لمجلس الإدارة والإدارة التنفيذية حول حالة الأمن السيبراني.
  • إنشاء وإدارة برنامج مؤشرات الأداء الرئيسية (KPIs) لقياس فعالية برنامج الأمن.
  • الإشراف على ميزانية أمن المعلومات وضمان تخصيص الموارد بفعالية لإدارة المخاطر.
  • تصميم وإدارة برنامج شامل لإدارة مخاطر الأمن السيبراني على مستوى المؤسسة.
  • إجراء تقييمات منتظمة للمخاطر، بما في ذلك تحليل تأثير الأعمال (BIA)، لتحديد المخاطر وتحليلها وتقييمها.
  • تسهيل خطط معالجة المخاطر مع مالكي الأعمال والتقنية، وضمان تنفيذ استراتيجيات التخفيف أو القبول أو النقل المناسبة.
  • إدارة برنامج إدارة مخاطر البائعين، وتقييم الوضع الأمني للبائعين والشركاء الخارجيين، خاصة مزودي الخدمات السحابية وبوابات الدفع.
  • دمج إدارة المخاطر في دورة حياة تطوير البرمجيات (SDLC) وعمليات إدارة التغيير.
  • العمل كنقطة اتصال رئيسية وخبير موضوعي لجميع الفحوصات والتدقيقات التنظيمية المتعلقة بالأمن السيبراني (مثل SAMA، CMA).
  • ضمان الامتثال المستمر لإطار الأمن السيبراني (CSF) الصادر عن البنك المركزي السعودي (SAMA)، ومتطلبات PCI DSS، واللوائح الأخرى ذات الصلة.
  • إدارة عملية الحصول على التراخيص والشهادات التنظيمية اللازمة والحفاظ عليها من منظور الأمن السيبراني.
  • إعداد وتقديم تقارير تنظيمية دقيقة وفي الوقت المحدد، والاستبيانات، وطلبات الإثبات.
  • مراقبة المشهد التنظيمي للتغيرات في القوانين واللوائح، وتقديم المشورة الاستباقية للشركة بشأن التعديلات المطلوبة.
  • إدارة جميع التدقيقات الأمنية الداخلية والخارجية، بما في ذلك التنسيق مع المدققين، وتقديم الأدلة، ومتابعة معالجة النتائج.
  • تطوير وصيانة برنامج اختبار رقابي قوي للتحقق من فعالية الضوابط الأمنية الرئيسية.
  • إدارة معالجة جميع نتائج التدقيقات والتقييمات، وضمان إغلاقها بشكل فعال ودائم.
  • تطوير وتقديم برنامج توعية وتدريب أمني مخصص للأدوار المختلفة داخل المؤسسة، مع التركيز على السياق المحلي والتهديدات.
  • تعزيز ثقافة أمنية قوية، وضمان فهم كل موظف لدوره في حماية أصول معلومات الشركة.

المزايا

  • ثقافة شاملة ومتنوعة تشجع الابتكار ومرونة العمل (عن بعد، في المكتب، أو هجين).
  • حزم تعويضات تنافسية عالية، مع إمكانية الحصول على أسهم.
  • التطوير الشخصي من خلال تدريبات منتظمة ومخصص سنوي للتعلم لمواجهة التحديات الجديدة والنمو الوظيفي في بيئة فائقة النمو.
  • الانضمام إلى فريق موهوب يضم أكثر من 30 جنسية يعملون في 7 دول، واكتساب خبرة قيمة في صناعة مثيرة.
  • الاستقلالية، والإرشاد، والأهداف الطموحة التي تخلق فرصاً كبيرة لك وللشركة.
  • مسؤولية وثقة كبيرتان: نؤمن بأن أفضل النتائج تأتي عندما يتم منح المسؤولين عن وظيفة ما الحرية لفعل ما يرونه مناسباً.
عرض النص الأصلي للإعلان

Who Are We


HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools.


HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations.


Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank.

 

Responsibilities 
 

Governance & Strategy:

     Develop, implement, and continuously improve the organization's Information Security Governance framework, policies, standards, and procedures.

     Lead the creation and execution of the Cyber Security Strategy in alignment with the company's overall business goals.

     Providing regular reports to the Board of Directors and executive management on the state of cybersecurity.

     Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure the effectiveness of the security program and report on progress.

     Oversee the information security budget, ensuring resources are allocated effectively to manage risk.

  Risk Management:

     Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program.

     Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks.

     Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation, acceptance, or transfer strategies are implemented.

     Manage the vendor risk management program, assessing the security posture of third-party vendors and partners, especially cloud service providers and payment gateways.

     Integrate risk management into the Software Development Life Cycle (SDLC) and change management processes.

    

Regulatory Compliance:

     Serve as the primary point of contact and subject matter expert for all regulatory examinations and audits related to cybersecurity (e.g., SAMA, CMA).

     Ensure continuous compliance with SAMA's Cyber Security Framework (CSF), Payment Card Industry Data Security Standard (PCI DSS) requirements, and other relevant regulations.

     Manage the process for obtaining and maintaining necessary regulatory licenses and certifications from a cybersecurity perspective.

     Prepare and submit accurate and timely regulatory reports, questionnaires, and evidence requests.

     Monitor the regulatory landscape for changes in laws, regulations, and standards, and proactively advise the business on required adjustments.

    

Audit & Assurance:

     Manage all internal and external security audits, including coordinating with auditors, providing evidence, and tracking remediation of findings.

     Develop and maintain a robust control testing program to validate the effectiveness of key security controls.

     Manage the remediation of all audit and assessment findings, ensuring they are closed out effectively and permanently.

   

Awareness & Culture:

     Develop and deliver a security awareness and training program tailored to different roles within the organization, with a focus on local context and threats.

     Champion a strong security culture, ensuring that every employee understands their role in protecting the company's information assets.

 

 

What We Offer You
We believe you will love working at HALA!
  • We have an inclusive and diverse culture that encourages innovation and flexibility in remote, in-office, and hybrid work setups.
  • We offer highly competitive compensation packages, including the potential for shares.
  • We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment.
  • Join a talented team of over 30 nationalities working in 7 countries and gain valuable experience in an exciting industry.
  • We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.
  • You will be given a lot of responsibility and trust. We believe that the best results come when the people responsible for a function are given the freedom to do what they think is best.
 
If you think you have what it takes to join a remarkable team #apply_now 

 

المصدر: الموقع الرسمي للجهة - أُضيفت للموقع في 20 سبتمبر 2026
رقم الإعلان لدى المصدر: 5406613008