تمارا تعلن عن وظيفة Technology Risk GRC Lead في الرياض
تفاصيل الوظيفة
تمارا، الشركة الرائدة في مجال التكنولوجيا المالية في المملكة العربية السعودية ومنطقة الخليج، تبحث عن قائد مخاطر التكنولوجيا والحوكمة والامتثال (Technology Risk GRC Lead) للانضمام إلى فريق الأمن السيبراني في الرياض.
نبذة عن الوظيفة
بصفتك قائد GRC في الأمن السيبراني، ستتولى مسؤولية عمليات الحوكمة والمخاطر والامتثال اليومية التي تدعم برنامج الأمن السيبراني في تمارا، مما يضمن تلبية التوقعات التنظيمية والحفاظ على بيئة رقابية ناضجة وتحسين الوضع الأمني باستمرار. ستكون مسؤولاً عن أنشطة الامتثال التنظيمي الشاملة بما في ذلك تفتيش SAMA، وتقييمات NCA، والامتثال لـ PCI-DSS، ومواءمة PDPL، بالإضافة إلى دورة حياة حوكمة سياسات الأمن السيبراني ومعاييره وإجراءاته. ستكون نقطة التنسيق الرئيسية بين فريق الأمن السيبراني وأصحاب المصلحة من الخط الأول في التكنولوجيا والهندسة والأعمال فيما يتعلق بمسائل الامتثال.
المهام والمسؤوليات
- دعم جاهزية تفتيش SAMA (شامل) بما في ذلك تقييمات الامتثال، تنسيق الأدلة، تحليل الفجوات، والدعم المباشر أثناء الزيارات التنظيمية الميدانية.
- قيادة أنشطة تقييم الامتثال والمواءمة عبر الأطر التنظيمية المطبقة بما في ذلك SAMA CSF وNCA وPCI-DSS وPDPL، وضمان إغلاق الفجوات والملاحظات في الوقت المناسب.
- إدارة دورة حياة حوكمة سياسات الأمن السيبراني ومعاييره وإجراءاته بما في ذلك التطوير والمراجعة الدورية والتحكم في الإصدار واعتماد أصحاب المصلحة والتواصل مع الموظفين.
- الحفاظ على خرائط الامتثال، وسجلات الرقابة، وتتبع النضج عبر جميع الأطر المعنية، وضمان الدقة والجاهزية للتدقيق في جميع الأوقات.
- متابعة فرق الخط الأول (التكنولوجيا، الهندسة، عمليات تقنية المعلومات) وأصحاب المصلحة المعنيين لضمان التنفيذ والمعالجة في الوقت المناسب لمتطلبات الامتثال وفجوات الرقابة.
- التنسيق والاستجابة للمبادرات التنظيمية والطلبات والاستفسارات الموقتة من الجهات التنظيمية مثل SAMA وNCA وهيئات أنظمة الدفع ذات الصلة.
- إعداد وعرض تحديثات حوكمة الأمن السيبراني وحالة الامتثال والنضج للجنة الأمن السيبراني ومنتديات الحوكمة الداخلية الأخرى.
- إنتاج لوحات معلومات ومقاييس وتقارير مؤشرات أداء رئيسية متعلقة بـ GRC لتوفير رؤية للقيادة حول وضع الامتثال وصحة السياسات وتقدم المعالجة.
- التعاون مع فرق المخاطر المؤسسية والامتثال في المسائل المشتركة للمخاطر والامتثال، بما في ذلك المساهمة في مراجعات تقييم مخاطر البائعين من منظور الأمن السيبراني.
- استخدام وصيانة منصة GRC في تمارا لإدارة سير عمل الامتثال وتقييمات الرقابة ومستودعات السياسات وأدلة التدقيق.
- دعم أنشطة التدقيق من خلال تنسيق جمع الأدلة وتتبع النتائج ومتابعة المعالجة والإجراءات التصحيحية حتى الإغلاق.
الشروط والمتطلبات
- 4-6 سنوات من الخبرة في مجال GRC للأمن السيبراني، أو مخاطر التكنولوجيا، أو حوكمة تقنية المعلومات، أو تدقيق تقنية المعلومات، أو مجال ذي صلة في قطاع الخدمات المالية أو التكنولوجيا المالية أو البنوك.
- خبرة مثبتة في أطر الامتثال التنظيمي، وخاصة SAMA CSF (مطلوب) وNCA (مفضل). خبرة في PCI-DSS و/أو PDPL تعتبر ميزة قوية.
- خبرة في إجراء أو دعم التفتيش التنظيمي وتقييمات الامتثال وتقييمات النضج.
- قدرة مثبتة على إدارة برامج معالجة الامتثال وتتبع النتائج حتى الإغلاق والتنسيق عبر جهات متعددة.
المهارات المطلوبة
- فهم متين لمبادئ حوكمة الأمن السيبراني ودورة حياة إدارة السياسات ومنهجيات تقييم الرقابة.
- مهارات قوية في التوثيق وإعداد التقارير مع القدرة على إنتاج مخرجات واضحة ومنظمة للجمهور الفني والتنفيذي.
- خبرة في العمل مع منصات وأدوات GRC لإدارة الامتثال وحوكمة السياسات وتتبع التدقيق (ميزة إضافية).
عرض النص الأصلي للإعلان
About us
Tamara is the leading fintech platform in Saudi Arabia and the wider GCC region with a mission to help people make their dreams come true by building the most customer-centric financial super-app on earth. The company serves millions of users in the region and partners with leading global and regional brands such as SHEIN, Jarir, noon, IKEA and Amazon, as well as small and medium businesses.
Tamara is Saudi’s first fintech unicorn and is backed by Sanabil Investments, SNB Capital, Checkout.com, amongst others, operating out of its headquarters in Riyadh, Saudi Arabia with other regional and global support offices.
Your role
Tamara is seeking a Cyber Security specialist / lead to join our Cyber Security team. In this role, you will own the day-to-day governance, risk, and compliance operations that underpin Tamara’s cyber security program, ensuring the organization meets regulatory expectations, maintains a mature control environment, and continuously improves its security posture.
You will be responsible for end-to-end regulatory compliance activities - including SAMA inspections, NCA assessments, PCI-DSS compliance, and PDPL alignment - as well as the governance lifecycle of cyber security policies, standards, and procedures. You will drive internal follow-ups to remediate identified maturity gaps and observations, and serve as the primary point of coordination between the Cyber Security team and first-line technology, engineering, and business stakeholders on compliance matters.
As an experienced individual contributor, you are expected to operate independently, take ownership of GRC deliverables, and lead initiatives that advance the maturity of Tamara’s cyber security governance and compliance program.
Your responsibilities
- Support in SAMA inspection readiness (end-to-end), including compliance assessments, evidence coordination, gap analysis, and direct support during on-site regulatory visits.
- Lead compliance assessment and alignment activities across applicable regulatory frameworks, including SAMA CSF, NCA, PCI-DSS, and PDPL, ensuring timely closure of identified gaps and observations.
- Drive the governance lifecycle for cyber security policies, standards, and procedures including development, periodic review, version control, stakeholder approval, and communication to Tamarians.
- Maintain and manage compliance mappings, control inventories, and maturity tracking across all in-scope frameworks, ensuring accuracy and audit-readiness at all times.
- Follow up with first-line teams (Technology, Engineering, IT Ops) and relevant business stakeholders to ensure timely implementation and remediation of compliance requirements and control gaps.
- Coordinate and respond to regulatory initiatives, requests, and ad-hoc inquiries from regulators such as SAMA, NCA, and relevant payment scheme bodies.
- Prepare and present cyber security governance, compliance status, and maturity updates for the Cyber Security Committee and other internal governance forums.
- Produce GRC-related dashboards, metrics, and KPI reporting for leadership visibility on compliance posture, policy health, and remediation progress.
- Collaborate with Enterprise Risk and Compliance teams on cross-functional risk and compliance matters, including contributing to vendor risk assessment reviews from a cyber security perspective.
- Utilize and maintain the Tamara’s GRC platform to manage compliance workflows, control assessments, policy repositories, and audit evidence.
- Support audit activities by coordinating evidence collection, tracking findings, and following up on remediation and mitigation actions to closure.
- Stay current on regulatory updates, emerging cyber security risks, and industry best practices relevant to fintech and financial services in the GCC region.
Your expertise
- 4-6 years of experience in Cyber Security GRC, Technology Risk, IT Governance, IT Audit, or a related field within financial services, fintech, or banking.
- Demonstrated experience with regulatory compliance frameworks, particularly SAMA CSF (required) and NCA (preferred). Experience with PCI-DSS and/or PDPL is a strong advantage.
- Solid understanding of cyber security governance principles, policy lifecycle management, and control assessment methodologies.
- Experience conducting or supporting regulatory inspections, compliance assessments, and maturity evaluations.
- Proven ability to manage compliance remediation programs, track findings to closure, and coordinate across multiple stakeholders.
- Strong documentation and reporting skills, with the ability to produce clear, structured deliverables for both technical and executive audiences.
- Experience working with GRC platforms and tools for compliance management, policy governance, and audit tracking are a plus.