وظيفة مدير حوكمة ومخاطر والامتثال للأمن السيبراني شاغرة لدى HALA في الرياض
تفاصيل الوظيفة
شركة HALA، إحدى الشركات الرائدة في مجال التكنولوجيا المالية في منطقة MENAP، تبحث عن مدير حوكمة أمن المعلومات وإدارة المخاطر والامتثال (GRC) للعمل في مكتبها بالرياض، السعودية. تهدف الشركة إلى تمكين المنشآت الصغيرة والمتوسطة من خلال حلول مالية وتقنية مبتكرة، وتعمل تحت ترخيص من البنك المركزي السعودي.
المهام والمسؤوليات
- تطوير وتنفيذ وتحسين إطار حوكمة أمن المعلومات بما في ذلك السياسات والمعايير والإجراءات.
- قيادة إنشاء وتنفيذ استراتيجية الأمن السيبراني بما يتوافق مع أهداف الشركة.
- تقديم تقارير دورية لمجلس الإدارة والإدارة التنفيذية حول حالة الأمن السيبراني.
- إنشاء وإدارة برنامج مقاييس ومؤشرات أداء رئيسية لقياس فعالية برنامج الأمن.
- الإشراف على ميزانية أمن المعلومات وضمان تخصيص الموارد بفعالية لإدارة المخاطر.
- تصميم وإدارة برنامج شامل لإدارة مخاطر الأمن السيبراني على مستوى المؤسسة.
- إجراء تقييمات مخاطر منتظمة بما في ذلك تحليل تأثير الأعمال لتحديد وتحليل المخاطر.
- تسهيل تخطيط معالجة المخاطر مع مالكي الأعمال والتقنية وتنفيذ استراتيجيات التخفيف والقبول أو النقل.
- إدارة برنامج تقييم مخاطر البائعين بما في ذلك تقييم الوضع الأمني للشركاء الخارجيين وخاصة موفري الخدمات السحابية وبوابات الدفع.
- دمج إدارة المخاطر في دورة حياة تطوير البرمجيات وعمليات إدارة التغيير.
- العمل كنقطة اتصال رئيسية وخبير موضوعي لجميع الفحوصات التنظيمية ومراجعات الأمن السيبراني (مثل SAMA و CMA).
- ضمان الامتثال المستمر لإطار الأمن السيبراني SAMA ومتطلبات PCI DSS واللوائح الأخرى ذات الصلة.
- إدارة عملية الحصول على التراخيص والشهادات التنظيمية والحفاظ عليها من منظور الأمن السيبراني.
- إعداد وتقديم تقارير تنظيمية دقيقة وفي الوقت المناسب بالإضافة إلى الاستبيانات وطلبات الأدلة.
- مراقبة المشهد التنظيمي للتغيرات في القوانين واللوائح وتقديم المشورة للشركة بشأن التعديلات المطلوبة.
- إدارة جميع مراجعات الأمن الداخلية والخارجية بما في ذلك التنسيق مع المدققين وتقديم الأدلة وتتبع معالجة النتائج.
- تطوير وصيانة برنامج اختبار رقابة قوي للتحقق من فعالية ضوابط الأمن الرئيسية.
- إدارة معالجة جميع نتائج المراجعات والتقييمات وضمان إغلاقها بفعالية وبشكل دائم.
- تطوير وتقديم برنامج توعية وتدريب أمني مخصص للأدوار المختلفة مع التركيز على السياق المحلي والتهديدات.
- الترويج لثقافة أمنية قوية وضمان فهم كل موظف لدوره في حماية أصول المعلومات.
المزايا
- ثقافة عمل شاملة ومتنوعة تشجع الابتكار والمرونة مع خيارات العمل عن بُعد أو في المكتب أو الهجين.
- حزمة تعويضات تنافسية للغاية تتضمن إمكانية الحصول على أسهم.
- أولوية للتطوير الشخصي مع تدريب منتظم ومنحة تعلم سنوية لمواجهة التحديات الجديدة وتنمية مسيرتك المهنية.
- الانضمام إلى فريق موهوب يضم أكثر من 30 جنسية يعملون في 7 دول واكتساب خبرة قيمة في صناعة مثيرة.
- استقلالية وتوجيه وأهداف طموحة تخلق فرصًا استثنائية لك وللشركة.
- مسؤولية وثقة كبيرتان مع حرية اتخاذ القرارات المناسبة لدورك.
عرض النص الأصلي للإعلان
Who Are We
HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools.
HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations.
Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank.
Responsibilities
Governance & Strategy:
Develop, implement, and continuously improve the organization's Information Security Governance framework, policies, standards, and procedures.
Lead the creation and execution of the Cyber Security Strategy in alignment with the company's overall business goals.
Providing regular reports to the Board of Directors and executive management on the state of cybersecurity.
Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure the effectiveness of the security program and report on progress.
Oversee the information security budget, ensuring resources are allocated effectively to manage risk.
Risk Management:
Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program.
Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks.
Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation, acceptance, or transfer strategies are implemented.
Manage the vendor risk management program, assessing the security posture of third-party vendors and partners, especially cloud service providers and payment gateways.
Integrate risk management into the Software Development Life Cycle (SDLC) and change management processes.
Regulatory Compliance:
Serve as the primary point of contact and subject matter expert for all regulatory examinations and audits related to cybersecurity (e.g., SAMA, CMA).
Ensure continuous compliance with SAMA's Cyber Security Framework (CSF), Payment Card Industry Data Security Standard (PCI DSS) requirements, and other relevant regulations.
Manage the process for obtaining and maintaining necessary regulatory licenses and certifications from a cybersecurity perspective.
Prepare and submit accurate and timely regulatory reports, questionnaires, and evidence requests.
Monitor the regulatory landscape for changes in laws, regulations, and standards, and proactively advise the business on required adjustments.
Audit & Assurance:
Manage all internal and external security audits, including coordinating with auditors, providing evidence, and tracking remediation of findings.
Develop and maintain a robust control testing program to validate the effectiveness of key security controls.
Manage the remediation of all audit and assessment findings, ensuring they are closed out effectively and permanently.
Awareness & Culture:
Develop and deliver a security awareness and training program tailored to different roles within the organization, with a focus on local context and threats.
Champion a strong security culture, ensuring that every employee understands their role in protecting the company's information assets.
What We Offer You
We believe you will love working at HALA!
- We have an inclusive and diverse culture that encourages innovation and flexibility in remote, in-office, and hybrid work setups.
- We offer highly competitive compensation packages, including the potential for shares.
- We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment.
- Join a talented team of over 30 nationalities working in 7 countries and gain valuable experience in an exciting industry.
- We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.
- You will be given a lot of responsibility and trust. We believe that the best results come when the people responsible for a function are given the freedom to do what they think is best.
رقم الإعلان لدى المصدر: 4469581697