GRC Information Security Specialist - Policy & Risk

تابي

Riyadh

On-site

SAR 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Relocation support
Devices provided

Job summary

Tabby is seeking an Information Security Specialist (GRC) to independently drive governance, risk, and compliance activities across Tabby's information security programme in KSA. The role focuses on building and maintaining policy libraries, conducting risk assessments, and coordinating audits and regulatory submissions, with emphasis on SAMA CSF, PDPL, NCA ECC, and ISO 27001.

You will collaborate with cross-functional teams, ensure regulatory alignment, and contribute to a mature security

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
  • 1–3 years of professional experience in information security governance, risk management, compliance, or a closely related field.
  • Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements is a strong advantage.

Responsibilities

  • Maintain and update information security governance framework documentation and policy library.
  • Draft and revise information security policies and baselines to regulatory alignment.
  • Monitor changes in legal, regulatory, and contractual requirements (SAMA CSF, PDPL, NCA ECC, PCI-DSS).
  • Coordinate security governance committee meetings and reporting packs.
  • Prepare risk assessments and maintain risk registers with treatment plans.
  • Lead audits coordination and remediation tracking with stakeholders.

Skills

Governance & risk management
Regulatory compliance
Policy development
Information security governance
Risk assessment execution
Audit & remediation coordination

Education

Bachelor's degree in IT, CS, Cybersecurity or related
CRISC or CISM certification (preferred)
ISO 27001 Foundation/Lead Implementer
CompTIA Security+ or equivalent

Job description

Tabby is seeking an Information Security Specialist (GRC) to independently drive governance, risk, and compliance activities across Tabby's information security programme in KSA. The role focuses on building and maintaining policy libraries, conducting risk assessments, and coordinating audits and regulatory submissions, with emphasis on SAMA CSF, PDPL, NCA ECC, and ISO 27001.

You will collaborate with cross-functional teams, ensure regulatory alignment, and contribute to a mature security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Information Security Specialist - Risk & Compliance
GRC Information Security Specialist - Risk & Compliance

Tabby | تابي • Riyadh

On-site
SAR 180,000 - 300,000
International team
Stock options
Relocation support
+2
GRC Information Security Specialist (KSA)
GRC Information Security Specialist (KSA)

تابي • Saudi Arabia

On-site
SAR 120,000 - 210,000
Global team
Inclusive culture
Stock options
+3
Information Security GRC Specialist: Governance & Risk
Information Security GRC Specialist: Governance & Risk

tabby • Saudi Arabia

On-site
SAR 180,000 - 260,000
Information Security Specialist
Information Security Specialist

Tabby | تابي • Riyadh

On-site
SAR 180,000 - 300,000
International team
Stock options
Relocation support
+2
Information Security Specialist
Information Security Specialist

تابي • Riyadh

On-site
SAR 120,000 - 180,000
Relocation support
Devices provided
Information Security Specialist KSA
Information Security Specialist KSA

تابي • Saudi Arabia

On-site
SAR 120,000 - 210,000
Global team
Inclusive culture
Stock options
+3
Cybersecurity GRC Lead: Policy, Risk & Audit Excellence
Cybersecurity GRC Lead: Policy, Risk & Audit Excellence

Confidential • Al Khobar

On-site
SAR 220,000 - 320,000
Cyber GRC Specialist: Risk & Compliance Champion
Cyber GRC Specialist: Risk & Compliance Champion

Managed.sa • Jeddah

On-site
SAR 70,000 - 100,000
Lead Cyber Security Engineer: Cloud, DevSecOps & IR
Lead Cyber Security Engineer: Cloud, DevSecOps & IR

Tabby | تابي • Riyadh

On-site
SAR 420,000 - 660,000
Cybersecurity GRC Specialist: Audit-Ready Policy & Risk Lead
Cybersecurity GRC Specialist: Audit-Ready Policy & Risk Lead

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000