شركة SiFi تعلن عن وظيفة أخصائي Cybersecurity GRC في الرياض
Cybersecurity GRC Specialist
🏢 SiFi
تفاصيل الوظيفة
تعلن شركة SiFi، وهي شركة سريعة النمو في مجال التكنولوجيا المالية (B2B) ومتخصصة في حلول إدارة الإنفاق وإصدار البطاقات، عن توفر وظيفة أخصائي حوكمة ومخاطر وامتثال للأمن السيبراني (Cybersecurity GRC Specialist) في الرياض.
المهام والمسؤوليات
- إدارة متتبع الامتثال لأطر SAMA CSF وPDPL/NDMO وPCI-DSS لضمان الجاهزية للتدقيق.
- الإشراف على دورة حياة الأدلة بالكامل: جمعها والتحقق منها وتوثيقها.
- ضمان الجاهزية المستمرة للتدقيق من خلال أدلة قابلة للتتبع ومتوافقة مع الضوابط.
- تتبع نتائج التدقيق وخطط المعالجة وضمان إغلاقها في الوقت المحدد.
- تقديم تقارير دورية عن حالة الامتثال إلى CISO واللجان المختصة.
- تطوير وصيانة سياسات ومعايير وإجراءات الأمن السيبراني.
- ضمان توافق الوثائق مع هيكل الحوكمة في SiFi والمتطلبات التنظيمية.
- إدارة دورة حياة المستندات (الإصدار، الموافقات، المراجعات).
- ربط جميع السياسات والإجراءات بضوابط SAMA CSF.
- صيانة وتحديث سجل مخاطر الأمن السيبراني.
- إجراء تقييمات مخاطر الطرف الثالث (TPRA) والعناية الواجبة للموردين.
- دعم دوريات مراجعة المخاطر وإعداد التقارير.
- التعاون مع فرق المخاطر والامتثال لمواءمة أطر المخاطر المؤسسية.
- جمع والتحقق من مؤشرات الأداء الرئيسية (KPIs/KRIs) من أصحاب المصلحة.
- صيانة متتبع مركزي لمؤشرات الأداء الرئيسية.
- إعداد تقارير دورية مع تحليل الاتجاهات لدعم النضج التنظيمي (المستوى 3+).
- تحديد فجوات الأداء ورفعها.
الشروط والمتطلبات
- خبرة من 1 إلى 3 سنوات في دور مخصص لحوكمة ومخاطر وامتثال الأمن السيبراني (GRC).
- خبرة عملية في الامتثال لإطار SAMA CSF ضمن جهات خاضعة للرقابة.
- خبرة في إعداد أدلة التدقيق والتقييمات التنظيمية.
- خبرة قوية في صياغة سياسات وإجراءات الأمن السيبراني.
- خبرة في استخدام منصات GRC مثل Archer أو ServiceNow GRC أو OneTrust أو ما يعادلها.
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو مجال ذي صلة.
- شهادات مهنية مثل ISO 27001 Lead Implementer/Lead Auditor، Security+، (ISC)² CC، CGRC، CISA أو CRISC.
- إجادة اللغتين الإنجليزية والعربية.
- ملاحظة هامة: الوظيفة متاحة للسعوديين فقط.
المهارات المطلوبة
- خبرة مع لوائح PDPL وNDMO (مفضلة).
- خبرة في الامتثال لـ PCI-DSS (مفضلة).
- معرفة بأمن الحوسبة السحابية (AWS، Azure، GCP، OCI) (مفضلة).
- خبرة في مجال التكنولوجيا المالية أو الخدمات المالية (مفضلة).
- الإلمام بأطر مثل ISO 27001 وNIST وCOBIT (مفضلة).
عرض النص الأصلي للإعلان
About SiFi
SiFi is a fast-growing B2B FinTech company specializing in spend management and card issuance solutions. We help companies take control of their spending, streamline expense workflows, and operate with greater efficiency.
Role Overview
1. Regulatory Compliance & Audit Readiness
SiFi is a fast-growing B2B FinTech company specializing in spend management and card issuance solutions. We help companies take control of their spending, streamline expense workflows, and operate with greater efficiency.
Role Overview
The Cybersecurity GRC Specialist plays a critical role in maintaining SiFi’s cybersecurity compliance posture and ensuring audit readiness across all regulatory frameworks.
This role is responsible for managing the full Governance, Risk, and Compliance (GRC) lifecycle - including evidence management, policy governance, risk tracking, and KPI/KRI reporting - ensuring that all cybersecurity controls are measurable, defensible, and aligned with regulatory expectations.
1. Regulatory Compliance & Audit Readiness
- Maintain and manage the compliance tracker across SAMA CSF, PDPL/NDMO, and PCI-DSS
- Own the full evidence lifecycle: collection, validation, and documentation
- Ensure continuous audit readiness with traceable, control-aligned evidence
- Track regulatory findings and remediation plans, ensuring timely closure
- Provide regular compliance status reports to the CISO and relevant committees
- Develop and maintain cybersecurity policies, standards, and procedures
- Ensure documentation aligns with SiFi governance structure and regulatory expectations
- Manage document lifecycle (versioning, approvals, reviews)
- Map all policies and procedures to SAMA CSF controls
- Maintain and update the cybersecurity risk register
- Conduct third-party risk assessments (TPRA) and vendor due diligence
- Support risk reviews and reporting cycles
- Collaborate with Risk and Compliance teams to align enterprise risk frameworks
- Collect and validate cybersecurity KPIs/KRIs from relevant stakeholders
- Maintain a centralized KPI/KRI tracker
- Prepare periodic reports with trend analysis to support regulatory maturity (Level 3+)
- Identify and escalate performance gaps
- We are looking for candidates with 1-3 years of experience in a dedicated Cybersecurity GRC role.
- years in a dedicated Cybersecurity GRC role
- Hands-on experience with SAMA CSF compliance within regulated entities
- Experience in audit evidence preparation and regulatory assessments
- Strong background in drafting cybersecurity policies and procedures
- Experience using GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust, etc.)
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field
- Certifications in ISO 27001 Lead Implementer / Lead Auditor, Security+, (ISC)² CC, CGRC or CISA or CRISC
- Speaks English and Arabic
- Experience with PDPL and NDMO regulations
- PCI-DSS compliance exposure
- Knowledge of cloud security (AWS, Azure, GCP, OCI)
- Experience in fintech or financial services\
- Familiarity with frameworks like ISO 27001, NIST, COBIT
المصدر: LinkedIn - أُضيفت للموقع في 12 أغسطس 2026