Chief Information Security Officer

فلووس | Flooss

Riyadh

On-site

SAR 900,000 - 1,300,000

Full time

11 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

AL-AN Alkhaligia for Consumer Microfinance Company (Flooss) in Saudi Arabia seeks a strategic CISO to lead the independent cybersecurity function, protecting information assets, customer data, and digital services while ensuring compliance with SAMA and PDPL. You will own strategy, governance, risk management, and security operations, partnering with IT, risk, and executive management.

The role requires at least 10 years in cybersecurity, 5 in leadership, financial sector experience, and senior

Qualifications

  • Bachelor's degree in a relevant field; Master's preferred for strategic roles.
  • Minimum 10 years in cybersecurity with 5+ in leadership.
  • Experience in financial services, fintech, or consumer finance.
  • SAMA-regulated entity leadership experience preferred; strong certifications required.

Responsibilities

  • Define and execute cybersecurity strategy, governance, and budget.
  • Lead risk management, regulatory compliance, and audits with timely closure.
  • Oversee security operations including SOC, incident response, and threat intel.
  • Define security architecture, data protection, IAM, and third-party risk.
  • Build and develop the cybersecurity team and talent pipeline.

Skills

Cybersecurity leadership
GRC
Security operations
IAM/PAM
Cloud security
Data protection
Vulnerability management
Vendor risk
BC/DR
ISO/NIST/PCI

Education

Bachelor's degree in Cybersecurity, CS, IT, Engineering
Master's degree preferred (Cybersecurity/InfoSec/MBA)

Tools

CISSP
CISM
CISA
CRISC
ISO 27001 Lead Implementer/Auditor
CCSP

Job description

AL-AN Alkhaligia for Consumer Microfinance Company (Flooss) provides consumer microfinance solutions in Saudi Arabia and operates in the regulated financial sector under the supervision of the Saudi Central Bank (SAMA).

We are building a customer-focused, technology-enabled, and well-governed organization, and we are looking for leaders who will help shape its next stage of growth.

Role Purpose

Lead the Company's independent Cybersecurity function and protect the Company's information assets, customer data, and digital services against cyber threats, while ensuring full compliance with SAMA and other applicable regulatory requirements.

The CISO will own the cybersecurity strategy, governance framework, risk management, and security operations, and will partner closely with the IT Manager, Risk, Compliance, and executive management to embed security across the business.

Key Responsibilities
1. Cybersecurity Strategy & Governance
  • Define and execute the cybersecurity strategy and roadmap in alignment with the Company's business strategy and risk appetite.
  • Establish and maintain the cybersecurity governance framework, policies, standards, and procedures.
  • Prepare and manage the cybersecurity budget and investment priorities.
  • Chair or support the Cybersecurity Steering Committee and report cybersecurity posture, risks, and key metrics to executive management, the Board, and relevant committees.
  • Maintain the independence of the Cybersecurity function from IT operations, in line with SAMA requirements.
2. Cyber Risk & Regulatory Compliance
  • Ensure compliance with the SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, and other applicable regulations and standards.
  • Identify, assess, and manage cybersecurity risks across systems, processes, projects, and third parties.
  • Conduct periodic cybersecurity maturity self-assessments and drive remediation plans.
  • Lead the cybersecurity aspects of regulatory examinations and internal and external audits, and ensure timely closure of findings.
  • Monitor regulatory developments and update the Company's cybersecurity controls accordingly.
3. Security Operations & Incident Response
  • Oversee security monitoring and threat detection, whether through an in-house or outsourced Security Operations Center (SOC).
  • Lead cyber incident response, investigation, and reporting to SAMA and other authorities within required timelines.
  • Manage vulnerability management, penetration testing, and threat intelligence programs.
  • Ensure cyber resilience is integrated into Business Continuity and Disaster Recovery plans and tested regularly.
  • Oversee identity and access management, including privileged access controls.
4. Security Architecture & Data Protection
  • Define security architecture standards and ensure secure-by-design principles across infrastructure, cloud, applications, APIs, and digital channels.
  • Review and approve the security of new systems, integrations, changes, and technology projects before go-live.
  • Lead data protection controls in coordination with the Data Protection Officer, in line with the Personal Data Protection Law (PDPL).
  • Oversee application security, including secure development practices and security testing of mobile and web channels.
  • Ensure controls are in place to prevent fraud and protect customer data and transactions.
5. Third Parties, Awareness & People Management
  • Assess and monitor the cybersecurity posture of vendors and outsourcing arrangements, in line with SAMA outsourcing requirements.
  • Define cybersecurity requirements in contracts and service level agreements with third parties.
  • Lead cybersecurity awareness and training programs for employees, management, and the Board.
  • Lead, coach, and develop the cybersecurity team.
  • Build succession plans and develop national cybersecurity talent.
Qualifications & Experience
Education
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
  • Master's degree in Cybersecurity, Information Security, or an MBA is preferred.
Experience
  • Minimum 10 years of experience in cybersecurity or information security.
  • At least 5 years in a cybersecurity leadership role.
  • Experience in financial services, fintech, or consumer finance is required.
  • Proven experience leading a cybersecurity function within a SAMA-regulated entity is preferred.
Professional Certifications
  • CISSP, CISM, or equivalent senior cybersecurity certification is required.
  • CISA, CRISC, ISO 27001 Lead Implementer/Auditor, and relevant cloud security certifications (e.g., CCSP) are an advantage.
Technical Skills

Strong knowledge and practical experience in:

  • Cybersecurity governance, risk, and compliance (GRC)
  • Security operations, SOC, and incident response
  • Cloud, network, and application security
  • Identity and access management (IAM/PAM)
  • API and digital channel security
  • Vulnerability management and penetration testing
  • Data protection and data loss prevention
  • Third-party cybersecurity risk management
  • Cyber resilience, Business Continuity, and Disaster Recovery
Regulatory & Compliance Knowledge
  • In-depth knowledge of the SAMA Cyber Security Framework and SAMA outsourcing requirements.
  • Knowledge of NCA cybersecurity controls and the Personal Data Protection Law (PDPL).
  • Familiarity with international standards such as ISO 27001, NIST, and PCI DSS.
  • Experience leading regulatory examinations and audits.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

فلووس | Flooss • Riyadh

On-site
SAR 180,000 - 240,000
Strategic CISO: Regulated Finance & Cyber Defense
Strategic CISO: Regulated Finance & Cyber Defense

فلووس | Flooss • Riyadh

On-site
SAR 900,000 - 1,300,000
IT Manager
IT Manager

فلووس | Flooss • Riyadh

On-site
SAR 260,000 - 460,000
Cybersecurity Officer (Mid-Level) - at Sadu Portfolio Company
Cybersecurity Officer (Mid-Level) - at Sadu Portfolio Company

Sadu Capital • Saudi Arabia

On-site
SAR 200,000 - 340,000
Competitive pay
Equity options
Regulator exposure
+1
Information Technology Specialist
Information Technology Specialist

فلووس | Flooss • Riyadh

On-site
SAR 90,000 - 130,000
Cyber Security Specialist
Cyber Security Specialist

Sahm Capital • Riyadh

On-site
SAR 180,000 - 240,000
VP – Information Security, BCM & Data Privacy – KSA
VP – Information Security, BCM & Data Privacy – KSA

First Abu Dhabi Bank (FAB) • Riyadh

On-site
SAR 800,000 - 1,100,000
Chief Information Security Officer
Chief Information Security Officer

Foreground LLC • Riyadh

On-site
SAR 900,000 - 1,500,000
Cyber Security Specialist
Cyber Security Specialist

Alkhorayef Group • Riyadh

On-site
SAR 150,000 - 210,000
Cybersecurity Director
Cybersecurity Director

Confidential Government • Riyadh

On-site
SAR 900,000 - 1,300,000