فودكس تعلن عن وظيفة مدير عالمي للأمن السيبراني (GRC) في الرياض
تفاصيل الوظيفة
تعلن شركة فودكس (Foodics)، الرائدة في مجال أنظمة إدارة المطاعم وتقنية المدفوعات ومقرها الرئيسي في الرياض، عن توفر شاغر وظيفي لـ (مدير الحوكمة والمخاطر والامتثال السيبراني العالمي - Global Cybersecurity GRC Manager) في مدينة الرياض، المملكة العربية السعودية.
المهام والمسؤوليات
- إدارة وتنسيق برنامج حوكمة ومخاطر وامتثال الأمن السيبراني للمجموعة تحت إشراف CISO، بما يشمل الأنشطة اليومية والأولويات وجدول العمل ومبادرات التحسين المستمر.
- إجراء وتنسيق وتتبع تقييمات الفجوات وفقاً لمتطلبات ISO 27001 وSOC 2 وNCA ECC وSAMA CSF وKSA PDPL وغيرها من المتطلبات السيبرانية والخصوصية والتنظيمية والتعاقدية السارية.
- ترجمة متطلبات الأطر التنظيمية والأطر المعيارية إلى ضوابط عملية وإجراءات تنفيذ وأصحاب مسؤولية وجداول زمنية وأدلة قياس قابلة للتحقق.
- صيانة إطار سياسات الأمن السيبراني بما في ذلك السياسات والمعايير والإجراءات وأصحاب الضوابط والأدلة الداعمة ودورات المراجعة والاستثناءات المعتمدة والسجلات الحوكمية ذات الصلة.
- إدارة سجل مخاطر الأمن السيبراني، وتسهيل تقييمات المخاطر، ومتابعة خطط المعالجة وقبول المخاطر والإجراءات المتأخرة مع أصحاب المصلحة في الأعمال والتقنية.
- مراقبة تنفيذ الضوابط وتقدم المعالجة، وتحدي الاستجابات الضعيفة أو غير المكتملة، ورفع المخاطر الجوهرية والثغرات المتكررة والإجراءات المتأخرة عند الاقتضاء.
- تنسيق عمليات التدقيق الداخلي والخارجي، والعناية الواجبة للأمن السيبراني للعملاء، وأنشطة الاعتماد، وتقييمات الجاهزية، مع ضمان معالجة الطلبات والأدلة بشكل متسق وفعال.
- دعم أنشطة الامتثال السيبراني لمجموعة Foodics عند الحاجة، بما في ذلك رسم الخرائط الضوابطية وتنسيق الأدلة وتتبع المعالجة ودعم التدقيق وإعداد تقارير الإدارة.
- إعداد لوحات معلومات و KPIs و KRIs وملخصات المخاطر وتقارير حالة الامتثال ومواد حوكمة الأمن السيبراني للإدارة ولجان الحوكمة.
- الشراكة مع مالكي الضوابط عبر الأقسام (التقنية والمنتجات والعمليات والموارد البشرية والقانونية والخصوصية والمشتريات) لدمج متطلبات الأمن السيبراني في العمليات التجارية والمبادرات.
- الحفاظ على تقويم امتثال واضح وضمان إتمام التقييمات الدورية والمراجعات وجمع الأدلة وتحديث السياسات ومراجعات المخاطر والتزامات التدقيق ضمن الجداول الزمنية المتفق عليها.
- تحسين كفاءة وجودة برنامج GRC من خلال قوالب موحدة ومكتبات ضوابط وأتمتة وأدوات وممارسات أقوى لإدارة الأدلة.
الشروط والمتطلبات
- خبرة مهنية لا تقل عن 10 سنوات في مجال حوكمة الأمن السيبراني أو المخاطر أو الامتثال أو التدقيق أو مجال وثيق الصلة، مع خبرة مثبتة في إدارة أنشطة GRC المؤسسية والعمل مع القيادة العليا للأمن السيبراني.
- معرفة عملية قوية بـ ISO 27001 وSOC 2، وخبرة فعلية في إجراء تقييمات الفجوات ورسم خرائط الضوابط وجمع الأدلة وقيادة المعالجة حتى الإغلاق.
- معرفة عملية جيدة بمتطلبات الأمن السيبراني والخصوصية في المملكة العربية السعودية، خاصة NCA ECC وKSA PDPL، مع القدرة على تفسير المتطلبات وترجمتها إلى ضوابط قابلة للتنفيذ.
- خبرة مثبتة في إدارة سجلات مخاطر الأمن السيبراني وتقييمات المخاطر وخطط المعالجة وقبول المخاطر والاستثناءات والتصعيد الإداري.
- خبرة في صيانة سياسات الأمن السيبراني والمعايير والإجراءات ومكتبات الضوابط وبيانات الأدلة والتوثيق الامتثالي.
- قدرة مثبتة على تنسيق عمليات التدقيق الداخلي والخارجي وإدارة طلبات الأدلة والرد على تقييمات أمن العملاء ودعم جهود الاعتماد أو ضمان الجاهزية.
- مهارات تحليلية قوية والقدرة على تحويل معلومات المخاطر والامتثال المعقدة إلى لوحات بيانات واضحة وملخصات تنفيذية وتقارير جاهزة للجان القرار.
- مهارات إدارة أصحاب المصلحة مع الثقة في تحدي مالكي الضوابط بشكل بناء ودفع المساءلة ومتابعة الإجراءات حتى الإنجاز.
- مهارات كتابية وشفهية قوية باللغة الإنجليزية، بما في ذلك القدرة على كتابة سياسات واضحة وبيانات مخاطر ونتائج تقييم وإجراءات علاجية وتقارير إدارية.
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو تقنية المعلومات أو علوم الحاسب أو إدارة المخاطر أو تخصص ذي صلة، أو خبرة مهنية معادلة.
المهارات المطلوبة (يفضل توفرها)
- خبرة في العمل في بيئة التكنولوجيا المالية (FinTech) أو المدفوعات أو SaaS أو أي بيئة منظمة وقائمة على التقنية.
- خبرة مع متطلبات SAMA للأمن السيبراني أو دعم أنشطة الامتثال السيبراني لكيان مدفوعات أو خدمات مالية خاضع للتنظيم.
- شهادات مهنية مثل ISO 27001 Lead Implementer / Lead Auditor أو CISM أو CRISC أو CISA أو CISSP أو ما يعادلها.
- خبرة في PCI DSS أو إدارة مخاطر الأمن السيبراني للطرف الثالث أو الامتثال للخصوصية أو أطر أمنية إقليمية ودولية أخرى.
- خبرة عملية مع منصات GRC وأتمتة الأدلة وأدوات الامتثال أو بناء سير عمل منظم للتقارير الضوابطية والمخاطر.
- خبرة في العمل عبر كيانات تجارية أو دول أو بيئات تنظيمية متعددة.
- إجادة اللغة العربية للتعامل مع أصحاب المصلحة والجهات التنظيمية والوثائق.
المزايا
- حزمة تعويضات تنافسية تشمل المكافآت وإمكانية الحصول على أسهم.
- التركيز على التطوير الشخصي من خلال تدريب منتظم ومنح دراسية سنوية للتعلم لمواجهة تحديات جديدة والنمو الوظيفي في بيئة شديدة النمو.
- الانضمام إلى فريق موهوب يضم أكثر من 30 جنسية يعملون في 14 دولة، واكتساب خبرة قيّمة في صناعة مثيرة.
- الاستقلالية في العمل والإرشاد وأهداف طموحة تخلق فرصًا استثنائية لكل من الموظف والشركة.
عرض النص الأصلي للإعلان
Who Are We❓
We Are Foodics! a leading restaurant management ecosystem and payment tech provider. Founded in 2014 with headquarters in Riyadh and offices across 5 countries, including UAE, Egypt, Jordan and Kuwait. We are currently serving customers and partners in over 35 different countries worldwide. Our innovative products have successfully processed over 6 billion (yes, billion with a B) orders so far! making Foodics one of the most rapidly evolving SaaS companies to ever emerge from the MENA region. Also, Foodics has achieved three rounds of funding, with the latest raising $170 million in the largest SaaS funding round in MENA, boosting its innovation capabilities to better serve business owners.
The Job in a Nutshell💡
We are looking for a Global Cybersecurity GRC Manager to manage and coordinate cybersecurity governance, risk, and compliance activities across the Foodics Group under the direction of the CISO. You will be responsible for the day-to-day operation of the GRC program translating cybersecurity frameworks, regulatory obligations, and business risks into practical controls, clear ownership, measurable remediation plans, and decision-ready reporting. This is a high-visibility, cross-functional role working closely with Cybersecurity, Technology, Product, Legal, Privacy, Internal Audit, and business teams across the group, while supporting Foodics Pay cybersecurity compliance activities where required.
What you will do💡
- Manage and coordinate the group cybersecurity governance, risk, and compliance program under the direction of the CISO, including day-to-day GRC activities, priorities, operating cadence, and continuous improvement initiatives.
- Conduct, coordinate, and track gap assessments against ISO 27001, SOC 2, NCA ECC, SAMA CSF, KSA PDPL, and other applicable cybersecurity, privacy, regulatory, and contractual requirements.
- Translate regulatory and framework requirements into practical controls, implementation actions, accountable owners, target dates, and measurable evidence requirements.
- Maintain the cybersecurity policy framework, including policies, standards, procedures, control owners, supporting evidence, review cycles, approved exceptions, and related governance records.
- Own and maintain the cybersecurity risk register, facilitate risk assessments, and drive follow-up on treatment plans, risk acceptance, and overdue actions with business and technology owners.
- Monitor control implementation and remediation progress, challenge weak or incomplete responses, and escalate material risks, recurring gaps, and overdue actions when necessary.
- Coordinate internal audits, external audits, customer cybersecurity due diligence, certification activities, and readiness assessments, ensuring requests and evidence are handled consistently and efficiently.
- Support Foodics cybersecurity compliance activities where required, including control mapping, evidence coordination, remediation tracking, audit support, and management reporting.
- Prepare cybersecurity GRC dashboards, KPIs, KRIs, risk summaries, compliance status reports, and materials for management and cybersecurity governance committees.
- Partner with control owners across Technology, Product, Operations, HR, Legal, Privacy, Procurement, and other functions to embed cybersecurity requirements into business processes and initiatives.
- Maintain a clear compliance calendar and ensure recurring assessments, reviews, evidence collection, policy updates, risk reviews, and audit commitments are completed within agreed timelines.
- Improve the efficiency and quality of the GRC program through standardized templates, control libraries, automation, tooling, and stronger evidence-management practices.
What Are We Looking For❓
Required
- 10+ years of professional experience in cybersecurity governance, risk, compliance, audit, or a closely related field, with demonstrated experience managing enterprise GRC activities and working with senior cybersecurity leadership.
- Strong hands-on knowledge of ISO 27001 and SOC 2, with practical experience conducting gap assessments, mapping controls, collecting evidence, and driving remediation to closure.
- Good working knowledge of Saudi cybersecurity and privacy requirements, particularly NCA ECC and KSA PDPL, with the ability to interpret requirements and translate them into actionable controls.
- Demonstrated experience owning or managing cybersecurity risk registers, risk assessments, treatment plans, risk acceptance, exceptions, and management escalation.
- Experience maintaining cybersecurity policies, standards, procedures, control libraries, control ownership, evidence repositories, and compliance documentation.
- Proven ability to coordinate internal and external audits, manage evidence requests, respond to customer security assessments, and support certification or assurance readiness.
- Strong analytical skills and the ability to turn complex risk and compliance information into clear dashboards, executive summaries, and decision-ready committee reporting.
- Stakeholder management skills, with the confidence to challenge control owners constructively, drive accountability, and follow actions through to completion.
- Strong written and verbal communication in English, including the ability to write clear policies, risk statements, assessment findings, remediation actions, and management reports.
- Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, or a related discipline, or equivalent relevant professional experience.
Nice to have
- Experience working in FinTech, payments, SaaS, or another regulated and technology-driven environment.
- Experience with SAMA cybersecurity requirements or supporting cybersecurity compliance activities for a regulated payment or financial-services entity.
- Professional certifications such as ISO 27001 Lead Implementer / Lead Auditor, CISM, CRISC, CISA, CISSP, or equivalent.
- Experience with PCI DSS, third-party cybersecurity risk management, privacy compliance, or other regional and international security frameworks.
- Hands-on experience with GRC platforms, evidence automation, compliance tooling, or building structured control and risk reporting workflows.
- Experience operating across multiple business entities, countries, or regulatory environments.
- Arabic language skills for engaging with stakeholders, regulators, and documentation.
What We Offer You❗
We believe you will love working at Foodics!
- We offer highly competitive compensation packages, including bonuses and the potential for shares.
- We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment.
- Join a talented team of over 30 nationalities working in 14 countries, and gain valuable experience in an exciting industry.
- We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.
رقم الإعلان لدى المصدر: wkb-foodics-6B8790DE1A