جيبي تعلن عن وظيفة مدير GRC - الأمن السيبراني في الرياض
تفاصيل الوظيفة
شركة جيبي، إحدى شركات التمويل الخاضعة لإشراف البنك المركزي السعودي (ساما)، تبحث عن مدير للحوكمة والمخاطر والامتثال في مجال الأمن السيبراني (GRC Manager - Cybersecurity) للعمل في مكتبها بالرياض. يتولى هذا المنصب القيادة التنفيذية لبرنامج الحوكمة والمخاطر والامتثال السيبراني، وإدارة فريق من المحللين، وضمان الالتزام التام بإطار ساما للأمن السيبراني (CSF) والتقارير التنظيمية.
المهام والمسؤوليات
- ضمان امتثال برنامج الحوكمة والمخاطر والامتثال السيبراني بالكامل لمتطلبات إطار ساما للأمن السيبراني (CSF)، بما في ذلك التقييمات الذاتية الدورية والتقارير التنظيمية.
- تنفيذ وتحسين سياسات وإجراءات ومعايير الحوكمة السيبرانية للمؤسسة بشكل مستمر، بما يتماشى مع متطلبات ساما وأفضل الممارسات وأهداف العمل.
- قيادة تقييمات المخاطر وتحليلات الفجوات على مستوى المؤسسة؛ وصيانة سجل المخاطر وعرض النتائج وخطط المعالجة على الإدارة العليا.
- الإشراف على مراقبة وتحسين إطار الضوابط السيبرانية عبر المؤسسة.
- التعاون مع أصحاب المصلحة في تقنية المعلومات والشؤون القانونية والمراجعة والوحدات التجارية لدمج إدارة المخاطر السيبرانية في القرارات التشغيلية.
- قيادة وتوجيه وتطوير فريق من محللي وموظفي الحوكمة والمخاطر والامتثال؛ وإدارة عبء العمل والأداء والنمو المهني.
- العمل كخبير موضوعي في مجال الحوكمة والمخاطر والامتثال السيبراني والامتثال لساما، وتقديم تقارير المخاطر والامتثال للإدارة العليا.
- إدارة برنامج التوعية والتدريب في الأمن السيبراني؛ ودفع التبني على مستوى المؤسسة.
- تنسيق حوكمة الاستجابة للحوادث السيبرانية - تنسيق الاستجابة عبر الوظائف، ومراجعة ما بعد الحادث، وإعداد التقارير للإدارة، بما في ذلك الإخطار التنظيمي عند الحاجة وفقاً لمتطلبات ساما.
- إدارة العلاقات اليومية مع ساما ومدققي الحسابات الخارجيين والمقيّمين الخارجيين؛ والإشراف على جاهزية التدقيق ومتابعة المعالجة.
- مراقبة المشهد التنظيمي والتهديدات، وترجمة المتطلبات الناشئة إلى توصيات على مستوى البرنامج.
- دعم تقييم أدوات الحوكمة والمخاطر والامتثال والتنسيق مع البائعين (منصات GRC، SIEM، إدارة الثغرات، إلخ).
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو تقنية المعلومات أو الأمن السيبراني أو مجال ذي صلة (يفضّل الماجستير).
- خبرة من 5 إلى 8 سنوات في مجال الحوكمة والمخاطر والامتثال السيبراني، ويفضّل أن تكون في جهة خاضعة لإشراف ساما (بنك، شركة تمويل، أو تأمين)، مع سنتين على الأقل في منصب قيادي للفريق.
- شهادة CISSP أو CISM أو CISA مطلوبة (أو ما يعادلها)، ويفضّل CRISC.
- خبرة عميقة في أطر الأمن السيبراني واللوائح، وخاصة إطار ساما للأمن السيبراني (CSF)، بالإضافة إلى NCA ECC وNIST وISO 27001.
- سجل مثبت في قيادة تقييمات المخاطر ومراجعات الامتثال وبرامج المعالجة - ويفضّل أن تشمل التقييمات الذاتية لساما.
- خبرة في إدارة فرق متعددة الوظائف والتنسيق مع البائعين والجهات التنظيمية.
- مهارات تواصل قوية - القدرة على ترجمة المخاطر التقنية إلى أثر تجاري للإدارة العليا.
- مهارات قوية في التفكير الاستراتيجي وإدارة الأفراد والتأثير على أصحاب المصلحة.
المهارات المطلوبة
- معرفة عملية قوية بإطار ساما للأمن السيبراني (CSF) وتطبيقه العملي في سياق قطاع التمويل.
- فهم متين لمبادئ الحوكمة والمخاطر والامتثال وإدارة المخاطر المؤسسية.
- الإلمام بـ NCA ECC والمتطلبات التنظيمية السعودية الأخرى ذات الصلة.
- قيادة الأفراد: التدريب وإدارة الأداء وتخطيط القدرات.
- مهارات إدارة البرامج/المشاريع لتشغيل مبادرات الحوكمة والمخاطر والامتثال متعددة أصحاب المصلحة.
- الإلمام بمنصات GRC ومشهد الأدوات الأمنية.
- تعاون قوي عبر الوظائف، خاصة مع تقنية المعلومات والشؤون القانونية والامتثال والمراجعة.
عرض النص الأصلي للإعلان
Job Description & Accountabilities
Cybersecurity GRC Manager
The Cybersecurity GRC Manager leads the day-to-day execution of the organization’s cybersecurity governance, risk, and compliance (GRC) program within a SAMA-regulated financing company. This role manages a team of GRC analysts/officers, maintains the risk register, and supports senior leadership with clear reporting on the organization’s risk and compliance posture. The manager drives risk assessments, oversees the cybersecurity controls framework, and ensures full alignment with SAMA Cyber Security Framework (CSF) requirements and other applicable regulations - reporting to the Chief of Cybersecurity.
Reports to: Chief of Cybersecurity Sector: Financing / Regulated by SAMA
Responsibilities
- Ensure the cybersecurity GRC program remains fully compliant with SAMA Cyber Security Framework (CSF) requirements, including periodic self-assessments and regulatory reporting.
- Execute and continuously improve the organization’s cybersecurity governance policies, procedures, and standards, aligned with SAMA requirements, industry best practices, and business objectives.
- Lead enterprise-wide risk assessments and gap analyses; maintain the risk register and present findings/remediation plans to senior leadership.
- Oversee the monitoring and continuous improvement of the cybersecurity controls framework across the organization.
- Partner with stakeholders across IT, legal, audit, and business units to embed cybersecurity risk management into operational decisions.
- Lead, mentor, and develop a team of GRC analysts/officers; manage workload, performance, and professional growth.
- Serve as a subject-matter expert on cybersecurity GRC and SAMA compliance, providing risk and compliance reporting to senior leadership.
- Manage the cybersecurity awareness and training program; drive organization-wide adoption.
- Coordinate cybersecurity incident response governance - cross-functional response coordination, post-incident review, and reporting to leadership, including regulatory notification where required by SAMA.
- Manage day-to-day relationships with SAMA, external auditors, and third-party assessors; oversee audit readiness and remediation tracking.
- Monitor the regulatory and threat landscape, translating emerging requirements into program-level recommendations.
- Support GRC tooling evaluation and vendor coordination (GRC platforms, SIEM, vulnerability management, etc.).
Qualifications & Experience
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (Master’s a plus).
- 5-8 years of cybersecurity GRC experience, preferably within a SAMA-regulated entity (bank, finance company, or insurance), including 2+ years in a team leadership capacity.
- CISSP, CISM, or CISA required (or equivalent); CRISC a plus.
- Deep expertise in cybersecurity frameworks and regulations, particularly SAMA Cyber Security Framework (CSF), in addition to NCA ECC, NIST, and ISO 27001.
- Proven track record leading risk assessments, compliance audits, and remediation programs - ideally including SAMA self-assessments.
- Experience managing cross-functional teams and coordinating with vendors and regulators.
- Strong communication skills - able to translate technical risk into business impact for senior leadership.
- Strong strategic thinking, people management, and stakeholder influence skills.
Knowledge & Skills
- Strong, hands-on knowledge of SAMA Cyber Security Framework (CSF) and its practical application in a financing sector context.
- Solid understanding of GRC principles and enterprise risk management.
- Familiarity with NCA ECC and other applicable Saudi regulatory requirements.
- People leadership: coaching, performance management, capacity planning.
- Program/project management skills to run multi-stakeholder GRC initiatives.
- Familiarity with GRC platforms and the security tooling landscape.
- Strong cross-functional collaboration, especially with IT, legal, compliance, and audit
J-B Values:
- Simplicity
- We make the complex simple, so our customers don’t have to spend more time than necessary understanding their options and credit.
- Reliability
Transparent and always there. We mean what we say and do what we say.
- Proactiveness
We are a true supporter and advisor to our customers, always predicting and anticipating their needs.
- Proud
Created by Saudis for Saudi, we are a proud Saudi brand and we do what’s best for our community.
وظائف أخرى لدى جيبي