Cybersecurity Manager

moneymoon

Riyadh

On-site

SAR 350,000 - 600,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

تسعى شركة Moneymoon لتعيين مدير أمن سيبراني (CISO) ليقود وظيفة الأمن على مستوى المؤسسة ويعزز موقفها الأمني في بيئة تقنية مالية منظمة في السعودية. ستتكامل المسؤوليات مع فرق التقنية والامتثال والمنتجات والعمليات والإدارة العليا لضمان حماية البيانات والعملاء.

هذا الدور عمل ميداني يجمع الحوكمة والاستعداد التنظيمي ومراقبة المخاطر وعمليات الأمن والهندسة والتهديدات عبر السحابة والتطبيقات والواجهات البرمجية، مع توجيه الاستجابة للحوادث والتحول الرقمي الآمن.

Qualifications

  • أولاً: تشكيل إطار حوكمة الأمن السيبراني وتحديث السياسات والمعايير والضوابط والخرائط التنظيمية.
  • ثانياً: التزام بقواعد SAMA CSF والمتطلبات التنظيمية، مع توثيق الأدلة والنتائج.
  • ثالثاً: قيادة تقييمات الأمن والتدقيق والاعتماد على تقارير مخاطر تقنية.
  • رابعاً: إدارة دورة حياة مخاطر الأمن السيبراني والتقارير للإدارة العليا.
  • خامساً: قيادة عمليات الأمن والهندسة والأمان في البرمجيات والسحابة والتطبيقات.

Responsibilities

  • قيادة حوكمة الأمن والجاهزية التنظيمية لـ SAMA وتحديث الإطارات والضوابط.
  • إدارة مخاطر الأمن السيبراني وتتبّع مؤشرات المخاطر والتقارير للإدارة العليا.
  • تشغيل وتحسين قدرات الأمن عبر البنية السحابية و IAM وEDR والبريد والشبكات والتطبيقات.
  • بدء مبادرات أتمتة القياسات الأمنية وجمع الأدلة بشكل آلي.
  • التعاون مع فرق التقنية والامتثال والموارد البشرية والمالية لضمان دمج الأمن عبر المنتجات والأنظمة.
  • قيادة استجابات الحوادث والتعافي وتوثيق الدروس المستفادة.

Skills

Cybersecurity governance
Risk management
Cloud security
Incident response
Regulatory compliance

Tools

SIEM
IAM
EDR

Job description

أول شركة تقنية مالية للتمويل من فرد إلى فرد، بتجربة مستخدم سلسة ومؤتمتة بالكامل، مصرحة من البنك المركزي السعودي

About Us

Moneymoon is a pioneering Fintech platform transforming short-term microlending through secure, compliant, and seamless peer-to-peer technology. We enable individuals to support one another through a one-month lending model built on transparency, safety, and trust.

As we progress through the Saudi Central Bank (SAMA) Regulatory Sandbox and prepare for full licensing, strong cybersecurity governance, operational resilience, and regulatory readiness are critical to how we operate and scale.

About The Role

Moneymoon is looking for a Cybersecurity Manager acting (CISO) to own and manage the cybersecurity function end to end and strengthen our security posture as we continue to grow within a regulated Saudi fintech environment.

This is a hands-on role that combines cybersecurity governance, SAMA regulatory readiness, cyber risk management, security operations, cloud and application security, incident response, resilience, and technical security oversight.

You will work closely with Technology, Product, Data & AI, Operations, Compliance, Risk, HR, Finance, and senior leadership to ensure cybersecurity is embedded across our products, infrastructure, systems, processes, and third-party relationships.

The role requires someone who can operate across both strategy and execution — translating cybersecurity and regulatory requirements into practical controls, measurable improvements, and effective security operations.

Why This Role Matters

Every security decision has a direct impact on the business.

  • The lending business. Fraud, account takeover, identity abuse, API attacks, and security failures can create direct financial exposure. Your controls protect real money and real customers.
  • Speed to market. Security reviews that happen too late slow down product delivery. Your role is to make secure design and secure delivery part of the normal engineering process.
  • Regulatory readiness. SAMA cybersecurity requirements are not simply a documentation exercise. They are fundamental to our ability to operate, scale, and maintain regulatory readiness.
  • Customer trust. Customers trust Moneymoon with their identity, financial information, and personal data. Protecting that trust is a core responsibility of this role.

We are looking for someone who sees cybersecurity not simply as a control checklist, but as a business-critical capability that must be built, operated, measured, and continuously improved.

What You’ll Own
1. Cybersecurity Governance & SAMA Regulatory Readiness
  • Own and continuously enhance Moneymoon’s cybersecurity governance framework, policies, procedures, standards, controls, and security improvement plans.
  • Drive readiness and ongoing alignment with the SAMA Cyber Security Framework (SAMA CSF) and applicable regulatory cybersecurity requirements.
  • Manage applicable requirements across the wider regulatory landscape, including Minimum Verification Controls (MVC), Cyber Resilience Fundamental Requirements (CRFR), Counter-Fraud Fundamental Requirements (CFFR), NCA ECC, PDPL, and ISO/IEC 27001.
  • Own the cybersecurity control environment, maturity and remediation plans, supporting evidence, and regulatory documentation.
  • Lead cybersecurity assessments, regulatory reviews, internal and external audits, control testing, evidence preparation, findings management, and remediation.
  • Work directly with auditors, assessors, and internal stakeholders to ensure findings are addressed effectively and within required timelines.
2. Cybersecurity Risk, Metrics & Reporting
  • Own the cybersecurity risk management lifecycle, including risk identification, assessment, treatment, acceptance, escalation, monitoring, and closure.
  • Maintain the Cybersecurity Risk Register and ensure material risks have clear owners, treatment plans, and target dates.
  • Define and monitor meaningful cybersecurity Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and security metrics.
  • Automate security metrics and evidence collection from relevant systems and security tooling wherever practical.
  • Provide clear reporting to senior management and relevant governance committees on cybersecurity risks, control effectiveness, incidents, vulnerabilities, and remediation progress.
  • Translate technical cybersecurity issues into clear business risks and actionable recommendations.
3. Security Operations & Engineering
  • Manage and continuously improve security capabilities across cloud infrastructure, IAM/PAM, endpoints, EDR, email security, networks, applications, APIs, vulnerability management, logging, SIEM, and threat detection.
  • Maintain hands-on involvement in security tooling, configurations, monitoring, detections, and automation.
  • Own the access lifecycle end to end, including joiners, movers and leavers, segregation of duties, privileged accounts, elevated permissions, periodic access reviews, and access remediation.
  • Strengthen privileged access controls and reduce unnecessary or excessive permissions across critical systems.
  • Improve and automate repetitive security processes through scripting, integrations, and security tooling wherever practical.
  • Ensure relevant security events are appropriately logged, monitored, investigated, and escalated.
4. AI Security & Security Automation
  • Work closely with Technology and Data & AI teams to develop practical uses of AI and automation within cybersecurity.
  • Explore and implement capabilities such as anomaly detection across access and transaction patterns, automated alert triage, evidence collection, security workflow automation, and incident-response support.
  • Evaluate opportunities to improve detection and response capabilities using AI/ML where there is a clear security and business benefit.
  • Manage security risks associated with Moneymoon’s own use of AI and Large Language Models (LLMs).
  • Establish appropriate controls against risks such as prompt injection, sensitive data leakage, unauthorized access, insecure integrations, and model misuse.
5. Product, Application, API & Cloud Security
  • Embed cybersecurity requirements throughout the product and technology lifecycle.
  • Conduct threat modeling and security reviews for new products, features, applications, architecture, APIs, integrations, and significant technology changes.
  • Partner directly with Technology and Engineering teams on Secure SDLC, application security, API security, cloud security, secrets management, security testing, and secure architecture.
  • Ensure security requirements are identified early and addressed before production deployment.
  • Assess cloud environments and infrastructure configurations and drive remediation of identified security weaknesses.
  • Help make secure development the standard delivery path rather than a late-stage approval gate.
6. Fraud & Verification Security Controls
  • Work with relevant teams on technical security controls addressing account takeover, identity abuse, suspicious access behavior, transaction anomalies, authentication weaknesses, and application/API abuse.
  • Strengthen security controls around customer authentication, identity verification, and sensitive transactions.
  • Support the effective implementation and monitoring of applicable SAMA Minimum Verification Controls and Counter-Fraud requirements.
  • Ensure relevant controls are operating effectively in practice and supported by appropriate evidence.
  • Collaborate with relevant business, technology, risk, and compliance stakeholders where cybersecurity and fraud risks overlap.
7. Vulnerability Management, Incident Response & Cyber Resilience
  • Own the vulnerability management lifecycle, including vulnerability scanning, assessment, prioritization, remediation tracking, and closure.
  • Coordinate penetration testing and ensure identified findings are assigned, prioritized, remediated, and verified.
  • Prioritize vulnerabilities based on actual exposure, exploitability, asset criticality, and business impact rather than severity scores alone.
  • Lead cybersecurity incident response across detection, containment, investigation, eradication, recovery, root-cause analysis, lessons learned, and corrective actions.
  • Maintain and continuously improve cybersecurity incident response plans and procedures.
  • Support Business Continuity, Disaster Recovery, Cyber Resilience, recovery objectives, resilience testing, tabletop exercises, and incident simulations.
  • Ensure lessons learned from incidents, testing, and exercises result in measurable improvements.
8. Third-Party Cybersecurity
  • Manage cybersecurity assessments for vendors, technology providers, cloud services, integrations, and other critical third parties.
  • Assess third-party security controls, architecture, data access, dependencies, certifications, and material cybersecurity risks.
  • Go beyond questionnaire-based assessments where higher-risk vendors require deeper technical or control review.
  • Work with relevant stakeholders to ensure appropriate cybersecurity requirements and obligations are incorporated into vendor agreements.
  • Monitor material third-party cybersecurity risks and ensure remediation actions are tracked through closure.
9. Cybersecurity Awareness & Culture
  • Drive cybersecurity awareness and training initiatives across Moneymoon.
  • Ensure employees understand their cybersecurity responsibilities and the risks relevant to their roles.
  • Support cybersecurity awareness during employee onboarding and throughout the employee lifecycle.
  • Develop targeted awareness activities based on emerging threats, incidents, identified risks, and regulatory requirements.
  • Promote practical security ownership and accountability across business and technology teams.
10. Lead Our AI Defense Capability
  • AI-driven detection and response capabilities within Moneymoon’s infrastructure, including anomaly detection across transaction and
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Manager
Cybersecurity Manager

Manar Rass • Riyadh

On-site
SAR 1,000,000 - 1,500,000
Competitive salary package
VIP Medical insurance
Annual salary review
CISO & Cyber Risk Transformation Lead (Fintech)
CISO & Cyber Risk Transformation Lead (Fintech)

Manar Rass • Riyadh

On-site
SAR 1,000,000 - 1,500,000
Competitive salary package
VIP Medical insurance
Annual salary review
Vibe Coding - Coop Program
Vibe Coding - Coop Program

moneymoon • Riyadh

On-site
SAR 11,000 - 28,000
CISO & Cyber Resilience Leader for FinTech
CISO & Cyber Resilience Leader for FinTech

moneymoon • Riyadh

On-site
SAR 350,000 - 600,000
Senior Manager - Network & Security Engineering
Senior Manager - Network & Security Engineering

D360 Bank • Riyadh

On-site
SAR 180,000 - 300,000
Product Design & UX - Coop Program
Product Design & UX - Coop Program

Manar Rass • Riyadh

On-site
SAR 17,000 - 28,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Mission.dev • Saudi Arabia

On-site
SAR 450,000 - 787,000
Admin support
On-call support
Monthly payment
+2
Information Security Risk Assessment Manager
Information Security Risk Assessment Manager

SAB • Riyadh

On-site
SAR 240,000 - 420,000
Managing Consultant, Cybersecurity Business Development, Services
Managing Consultant, Cybersecurity Business Development, Services

Mastercard • Riyadh Region

On-site
SAR 350,000 - 600,000
Information Security Officer
Information Security Officer

Soum • Riyadh

On-site