📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

جيبي تعلن عن وظيفة مدير الأمن السيبراني والحوكمة والمخاطر والامتثال في الرياض

Cybersecurity, GRC Manager
🕒 نُشرت: (منذ 3 أيام) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

شركة جيبي، إحدى شركات التمويل الخاضعة لإشراف مؤسسة النقد العربي السعودي (ساما)، تبحث عن مدير حوكمة ومخاطر والامتثال في الأمن السيبراني (Cybersecurity GRC Manager) للعمل في مدينة الرياض.

المهام والمسؤوليات

  • ضمان امتثال برنامج حوكمة ومخاطر والامتثال للأمن السيبراني لمتطلبات إطار الأمن السيبراني الصادر عن ساما، بما في ذلك التقييمات الذاتية الدورية والتقارير التنظيمية.
  • تنفيذ وتحسين سياسات وإجراءات ومعايير حوكمة الأمن السيبراني بما يتوافق مع متطلبات ساما وأفضل الممارسات وأهداف العمل.
  • قيادة تقييمات المخاطر وتحليلات الفجوات على مستوى المؤسسة، وصيانة سجل المخاطر، وعرض النتائج وخطط المعالجة على الإدارة العليا.
  • الإشراف على مراقبة وتحسين إطار ضوابط الأمن السيبراني عبر المؤسسة.
  • التعاون مع أصحاب المصلحة في تقنية المعلومات والشؤون القانونية والتدقيق والوحدات التنظيمية لدمج إدارة مخاطر الأمن السيبراني في القرارات التشغيلية.
  • قيادة وتوجيه وتطوير فريق من محللي وضباط الحوكمة والمخاطر والامتثال، وإدارة عبء العمل والأداء والنمو المهني.
  • العمل كخبير موضوعي في حوكمة ومخاطر والامتثال للأمن السيبراني والامتثال لساما، وتقديم تقارير المخاطر والامتثال للإدارة العليا.
  • إدارة برنامج التوعية والتدريب في الأمن السيبراني ودفع تبنيه على مستوى المؤسسة.
  • تنسيق حوكمة الاستجابة للحوادث السيبرانية - الاستجابة المشتركة بين الأقسام، المراجعة اللاحقة للحادث، وإعداد التقارير للإدارة بما في ذلك الإشعار التنظيمي عند الحاجة وفقاً لساما.
  • إدارة العلاقات اليومية مع ساما والمدققين الخارجيين ومقيمي الطرف الثالث، والإشراف على جاهزية التدقيق ومتابعة المعالجات.
  • مراقبة المشهد التنظيمي والتهديدات، وترجمة المتطلبات الناشئة إلى توصيات برنامجية.
  • دعم تقييم أدوات الحوكمة والمخاطر والامتثال والتنسيق مع الموردين (منصات GRC، SIEM، إدارة الثغرات وغيرها).

الشروط والمتطلبات

  • درجة البكالوريوس في علوم الحاسب، تقنية المعلومات، الأمن السيبراني أو مجال ذي صلة (يفضل الماجستير).
  • خبرة من 5 إلى 8 سنوات في حوكمة ومخاطر والامتثال للأمن السيبراني، ويفضل أن تكون داخل كيان خاضع لرقابة ساما (بنك، شركة تمويل أو تأمين)، مع سنتين على الأقل في منصب قيادي لفريق.
  • شهادة CISSP أو CISM أو CISA إلزامية (أو ما يعادلها)، ويفضل CRISC.
  • خبرة عميقة في أطر الأمن السيبراني واللوائح، وخاصة إطار الأمن السيبراني لساما (CSF)، بالإضافة إلى NCA ECC و NIST و ISO 27001.
  • سجل مثبت في قيادة تقييمات المخاطر ومراجعات الامتثال وبرامج المعالجة - ويفضل أن تشمل تقييمات ساما الذاتية.
  • خبرة في إدارة فرق متعددة الوظائف والتنسيق مع الموردين والجهات التنظيمية.
  • مهارات تواصل قوية - القدرة على ترجمة المخاطر التقنية إلى تأثير تجاري للإدارة العليا.
  • مهارات قوية في التفكير الاستراتيجي وإدارة الأفراد والتأثير على أصحاب المصلحة.

المهارات المطلوبة

  • معرفة عملية قوية بإطار الأمن السيبراني لساما (CSF) وتطبيقه العملي في قطاع التمويل.
  • فهم متين لمبادئ الحوكمة والمخاطر والامتثال (GRC) وإدارة مخاطر المؤسسة.
  • الإلمام بـ NCA ECC والمتطلبات التنظيمية السعودية الأخرى ذات الصلة.
  • قيادة الأفراد: التدريب، إدارة الأداء، تخطيط السعة.
  • مهارات إدارة البرامج/المشاريع لقيادة مبادرات GRC متعددة الأطراف.
  • الإلمام بمنصات GRC ومشهد أدوات الأمن.
  • تعاون قوي متعدد الوظائف، خاصة مع تقنية المعلومات والشؤون القانونية والامتثال والتدقيق.
عرض النص الأصلي للإعلان

Job Description & Accountabilities


Cybersecurity GRC Manager

The Cybersecurity GRC Manager leads the day-to-day execution of the organization’s cybersecurity governance, risk, and compliance (GRC) program within a SAMA-regulated financing company. This role manages a team of GRC analysts/officers, maintains the risk register, and supports senior leadership with clear reporting on the organization’s risk and compliance posture. The manager drives risk assessments, oversees the cybersecurity controls framework, and ensures full alignment with SAMA Cyber Security Framework (CSF) requirements and other applicable regulations - reporting to the Chief of Cybersecurity.

Reports to: Chief of Cybersecurity Sector: Financing / Regulated by SAMA

Responsibilities

  • Ensure the cybersecurity GRC program remains fully compliant with SAMA Cyber Security Framework (CSF) requirements, including periodic self-assessments and regulatory reporting.
  • Execute and continuously improve the organization’s cybersecurity governance policies, procedures, and standards, aligned with SAMA requirements, industry best practices, and business objectives.
  • Lead enterprise-wide risk assessments and gap analyses; maintain the risk register and present findings/remediation plans to senior leadership.
  • Oversee the monitoring and continuous improvement of the cybersecurity controls framework across the organization.
  • Partner with stakeholders across IT, legal, audit, and business units to embed cybersecurity risk management into operational decisions.
  • Lead, mentor, and develop a team of GRC analysts/officers; manage workload, performance, and professional growth.
  • Serve as a subject-matter expert on cybersecurity GRC and SAMA compliance, providing risk and compliance reporting to senior leadership.
  • Manage the cybersecurity awareness and training program; drive organization-wide adoption.
  • Coordinate cybersecurity incident response governance - cross-functional response coordination, post-incident review, and reporting to leadership, including regulatory notification where required by SAMA.
  • Manage day-to-day relationships with SAMA, external auditors, and third-party assessors; oversee audit readiness and remediation tracking.
  • Monitor the regulatory and threat landscape, translating emerging requirements into program-level recommendations.
  • Support GRC tooling evaluation and vendor coordination (GRC platforms, SIEM, vulnerability management, etc.).

Qualifications & Experience

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (Master’s a plus).
  • 5-8 years of cybersecurity GRC experience, preferably within a SAMA-regulated entity (bank, finance company, or insurance), including 2+ years in a team leadership capacity.
  • CISSP, CISM, or CISA required (or equivalent); CRISC a plus.
  • Deep expertise in cybersecurity frameworks and regulations, particularly SAMA Cyber Security Framework (CSF), in addition to NCA ECC, NIST, and ISO 27001.
  • Proven track record leading risk assessments, compliance audits, and remediation programs - ideally including SAMA self-assessments.
  • Experience managing cross-functional teams and coordinating with vendors and regulators.
  • Strong communication skills - able to translate technical risk into business impact for senior leadership.
  • Strong strategic thinking, people management, and stakeholder influence skills.

Knowledge & Skills

  • Strong, hands-on knowledge of SAMA Cyber Security Framework (CSF) and its practical application in a financing sector context.
  • Solid understanding of GRC principles and enterprise risk management.
  • Familiarity with NCA ECC and other applicable Saudi regulatory requirements.
  • People leadership: coaching, performance management, capacity planning.
  • Program/project management skills to run multi-stakeholder GRC initiatives.
  • Familiarity with GRC platforms and the security tooling landscape.
  • Strong cross-functional collaboration, especially with IT, legal, compliance, and audit


J-B Values:

  • Simplicity
  • We make the complex simple, so our customers don’t have to spend more time than necessary understanding their options and credit.
  • Reliability

Transparent and always there. We mean what we say and do what we say.

  • Proactiveness

We are a true supporter and advisor to our customers, always predicting and anticipating their needs.

  • Proud

Created by Saudis for Saudi, we are a proud Saudi brand and we do what’s best for our community.

المصدر: LinkedIn - أُضيفت للموقع في 26 أغسطس 2026
رقم الإعلان لدى المصدر: 4457912608