وظيفة كبير مسؤولي أمن المعلومات شاغرة لدى فلووس في الرياض
تفاصيل الوظيفة
فلووس (AL-AN Alkhaligia for Consumer Microfinance Company) تعلن عن توفر وظيفة رئيس أمن المعلومات (Chief Information Security Officer) في الرياض، السعودية. يشغل شاغل الوظيفة قيادة وظيفة الأمن السيبراني المستقلة وحماية أصول المعلومات وبيانات العملاء والخدمات الرقمية مع ضمان الامتثال الكامل لمتطلبات البنك المركزي السعودي (ساما) والجهات التنظيمية الأخرى.
المهام والمسؤوليات
- استراتيجية الأمن السيبراني والحوكمة: تحديد وتنفيذ استراتيجية وخريطة طريق الأمن السيبراني بما يتوافق مع استراتيجية العمل ورغبة المخاطرة، إنشاء وصيانة إطار الحوكمة والسياسات والمعايير والإجراءات، إعداد وإدارة ميزانية الأمن السيبراني وأولويات الاستثمار، رئاسة أو دعم لجنة توجيه الأمن السيبراني وإعداد التقارير للإدارة العليا ومجلس الإدارة، الحفاظ على استقلالية وظيفة الأمن السيبراني عن عمليات تقنية المعلومات وفقاً لمتطلبات ساما.
- المخاطر السيبرانية والامتثال التنظيمي: ضمان الامتثال لإطار الأمن السيبراني لساما وضوابط الأمن السيبراني الأساسية للمركز الوطني الإرشادي (NCA) وغيرها من اللوائح والمعايير، تحديد وتقييم وإدارة مخاطر الأمن السيبراني عبر الأنظمة والعمليات والمشاريع والأطراف الثالثة، إجراء تقييمات ذاتية دورية لنضج الأمن السيبراني وقيادة خطط المعالجة، قيادة الجوانب المتعلقة بالأمن السيبراني في الفحوص التنظيمية والتدقيقات الداخلية والخارجية وضمان إغلاق النتائج في الوقت المحدد، متابعة التطورات التنظيمية وتحديث ضوابط الأمن السيبراني وفقاً لذلك.
- عمليات الأمن والاستجابة للحوادث: الإشراف على مراقبة الأمن وكشف التهديدات سواء من خلال مركز عمليات أمني (SOC) داخلي أو خارجي، قيادة الاستجابة للحوادث السيبرانية والتحقيق والإبلاغ إلى ساما والسلطات الأخرى ضمن الأطر الزمنية المطلوبة، إدارة برامج إدارة الثغرات واختبار الاختراق واستخبارات التهديدات، ضمان دمج المرونة السيبرانية في خطط استمرارية الأعمال والتعافي من الكوارث واختبارها بانتظام، الإشراف على إدارة الهوية والوصول بما في ذلك ضوابط الوصول المميز.
- أمن البنية التحتية وحماية البيانات: تعريف معايير أمن البنية التحتية وضمان مبادئ التصميم الآمن عبر البنية التحتية والسحابة والتطبيقات وواجهات برمجة التطبيقات (API) والقنوات الرقمية، مراجعة واعتماد أمن الأنظمة والتكاملات والتغييرات والمشاريع التقنية الجديدة قبل الإطلاق، قيادة ضوابط حماية البيانات بالتنسيق مع مسؤول حماية البيانات وفقاً لنظام حماية البيانات الشخصية (PDPL)، الإشراف على أمن التطبيقات بما في ذلك ممارسات التطوير الآمن واختبارات أمن القنوات المحمولة والويب، ضمان وجود ضوابط لمنع الاحتيال وحماية بيانات العملاء والمعاملات.
- الأطراف الثالثة والتوعية وإدارة الأفراد: تقييم ومراقبة الوضع الأمني للموردين وترتيبات التعاقد الخارجي وفقاً لمتطلبات التعاقد الخارجي لساما، تحديد متطلبات الأمن السيبراني في العقود واتفاقيات مستوى الخدمة مع الأطراف الثالثة، قيادة برامج التوعية والتدريب في الأمن السيبراني للموظفين والإدارة ومجلس الإدارة، قيادة وتدريب وتطوير فريق الأمن السيبراني، بناء خطط التعاقب وتطوير الكفاءات الوطنية في الأمن السيبراني.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو تقنية المعلومات أو الهندسة أو مجال ذي صلة. يفضل درجة الماجستير في الأمن السيبراني أو أمن المعلومات أو ماجستير إدارة الأعمال.
- خبرة لا تقل عن 10 سنوات في الأمن السيبراني أو أمن المعلومات، منها 5 سنوات على الأقل في منصب قيادي في الأمن السيبراني.
- خبرة في الخدمات المالية أو التقنية المالية أو التمويل الاستهلاكي مطلوبة. خبرة سابقة في قيادة وظيفة أمن سيبراني ضمن جهة خاضعة لإشراف ساما مفضلة.
- شهادة احترافية في الأمن السيبراني مثل CISSP أو CISM أو ما يعادلها مطلوبة. شهادات مثل CISA وCRISC وISO 27001 Lead Implementer/Auditor وشهادات أمن سحابي (مثل CCSP) تعتبر ميزة إضافية.
- إجادة اللغتين العربية والإنجليزية بطلاقة.
- سعودي الجنسية.
المهارات المطلوبة
- معرفة قوية وخبرة عملية في حوكمة الأمن السيبراني وإدارة المخاطر والامتثال (GRC).
- خبرة في عمليات الأمن ومراكز عمليات الأمن (SOC) والاستجابة للحوادث.
- خبرة في أمن السحابة والشبكات والتطبيقات.
- خبرة في إدارة الهوية والوصول (IAM/PAM).
- خبرة في أمن واجهات برمجة التطبيقات (API) والقنوات الرقمية.
- خبرة في إدارة الثغرات واختبار الاختراق.
- خبرة في حماية البيانات ومنع فقدانها.
- خبرة في إدارة مخاطر الأمن السيبراني للأطراف الثالثة.
- خبرة في المرونة السيبرانية واستمرارية الأعمال والتعافي من الكوارث.
- معرفة متعمقة بإطار الأمن السيبراني لساما ومتطلبات التعاقد الخارجي.
- معرفة بضوابط الأمن السيبراني للمركز الوطني الإرشادي (NCA) ونظام حماية البيانات الشخصية (PDPL).
- الإلمام بالمعايير الدولية مثل ISO 27001 وNIST وPCI DSS.
- خبرة في قيادة الفحوص التنظيمية والتدقيقات.
عرض النص الأصلي للإعلان
About Flooss
AL-AN Alkhaligia for Consumer Microfinance Company (Flooss) provides consumer microfinance solutions in Saudi Arabia and operates in the regulated financial sector under the supervision of the Saudi Central Bank (SAMA).
We are building a customer-focused, technology-enabled, and well-governed organization, and we are looking for leaders who will help shape its next stage of growth.
Role Purpose
Lead the Company's independent Cybersecurity function and protect the Company's information assets, customer data, and digital services against cyber threats, while ensuring full compliance with SAMA and other applicable regulatory requirements.
The CISO will own the cybersecurity strategy, governance framework, risk management, and security operations, and will partner closely with the IT Manager, Risk, Compliance, and executive management to embed security across the business.
Key Responsibilities
1. Cybersecurity Strategy & Governance
- Define and execute the cybersecurity strategy and roadmap in alignment with the Company's business strategy and risk appetite.
- Establish and maintain the cybersecurity governance framework, policies, standards, and procedures.
- Prepare and manage the cybersecurity budget and investment priorities.
- Chair or support the Cybersecurity Steering Committee and report cybersecurity posture, risks, and key metrics to executive management, the Board, and relevant committees.
- Maintain the independence of the Cybersecurity function from IT operations, in line with SAMA requirements.
2. Cyber Risk & Regulatory Compliance
- Ensure compliance with the SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, and other applicable regulations and standards.
- Identify, assess, and manage cybersecurity risks across systems, processes, projects, and third parties.
- Conduct periodic cybersecurity maturity self-assessments and drive remediation plans.
- Lead the cybersecurity aspects of regulatory examinations and internal and external audits, and ensure timely closure of findings.
- Monitor regulatory developments and update the Company's cybersecurity controls accordingly.
3. Security Operations & Incident Response
- Oversee security monitoring and threat detection, whether through an in-house or outsourced Security Operations Center (SOC).
- Lead cyber incident response, investigation, and reporting to SAMA and other authorities within required timelines.
- Manage vulnerability management, penetration testing, and threat intelligence programs.
- Ensure cyber resilience is integrated into Business Continuity and Disaster Recovery plans and tested regularly.
- Oversee identity and access management, including privileged access controls.
4. Security Architecture & Data Protection
- Define security architecture standards and ensure secure-by-design principles across infrastructure, cloud, applications, APIs, and digital channels.
- Review and approve the security of new systems, integrations, changes, and technology projects before go-live.
- Lead data protection controls in coordination with the Data Protection Officer, in line with the Personal Data Protection Law (PDPL).
- Oversee application security, including secure development practices and security testing of mobile and web channels.
- Ensure controls are in place to prevent fraud and protect customer data and transactions.
5. Third Parties, Awareness & People Management
- Assess and monitor the cybersecurity posture of vendors and outsourcing arrangements, in line with SAMA outsourcing requirements.
- Define cybersecurity requirements in contracts and service level agreements with third parties.
- Lead cybersecurity awareness and training programs for employees, management, and the Board.
- Lead, coach, and develop the cybersecurity team.
- Build succession plans and develop national cybersecurity talent.
Qualifications & Experience
Education
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
- Master's degree in Cybersecurity, Information Security, or an MBA is preferred.
Experience
- Minimum 10 years of experience in cybersecurity or information security.
- At least 5 years in a cybersecurity leadership role.
- Experience in financial services, fintech, or consumer finance is required.
- Proven experience leading a cybersecurity function within a SAMA-regulated entity is preferred.
Professional Certifications
- CISSP, CISM, or equivalent senior cybersecurity certification is required.
- CISA, CRISC, ISO 27001 Lead Implementer/Auditor, and relevant cloud security certifications (e.g., CCSP) are an advantage.
Technical Skills
Strong knowledge and practical experience in:
- Cybersecurity governance, risk, and compliance (GRC)
- Security operations, SOC, and incident response
- Cloud, network, and application security
- Identity and access management (IAM/PAM)
- API and digital channel security
- Vulnerability management and penetration testing
- Data protection and data loss prevention
- Third-party cybersecurity risk management
- Cyber resilience, Business Continuity, and Disaster Recovery
Regulatory & Compliance Knowledge
- In-depth knowledge of the SAMA Cyber Security Framework and SAMA outsourcing requirements.
- Knowledge of NCA cybersecurity controls and the Personal Data Protection Law (PDPL).
- Familiarity with international standards such as ISO 27001, NIST, and PCI DSS.
- Experience leading regulatory examinations and audits.
Languages
- Fluent in Arabic and English.
Nationality
- Saudi national
رقم الإعلان لدى المصدر: 4473638451