Information Security Specialist

tabby

Saudi Arabia

On-site

SAR 180,000 - 260,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tabby is seeking an Information Security governance and risk professional to lead the development and maintenance of security policy frameworks, risk registers, and compliance programs. You will drive GRC initiatives and coordinate with stakeholders to ensure alignment with industry standards and regulatory requirements.

The role focuses on governance, risk management, and regulatory compliance across SAMA CSF, NCA, PDPL, ISO 27001, and PCI-DSS, delivering dashboards and continuous improvement

Qualifications

  • Bachelor's degree in IT or related field.
  • 1-3 years of professional experience in information security governance, risk management, compliance, or a closely related field.
  • Hands-on experience with risk assessment, policy development, or compliance monitoring.
  • Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements is a strong advantage.
  • Experience in a regulated Fintech or banking environment is preferred.
  • ISO 27001 Foundation or Lead Implementer (preferred).
  • CompTIA Security+ or equivalent.
  • Working toward CRISC (Certified in Risk and Information Systems Control) or CISM.

Responsibilities

  • Maintain and update the information security governance framework documentation policy library and associated standards and procedures.
  • Draft and revise information security policies standards and baselines ensuring alignment with applicable regulatory requirements and business objectives.
  • Monitor and track changes in legal regulatory and contractual requirements affecting information security.
  • Maintain and update role and responsibility matrices RACI.

Skills

Risk assessment execution
Policy development
Compliance monitoring
GRC knowledge
Information security governance

Education

Bachelor's degree in IT or related field

Job description

Information Security Governance
  • Maintain and update the information security governance framework documentation policy library and associated standards and procedures
  • Draft and revise information security policies standards and baselines ensuring alignment with applicable regulatory requirements and business objectives
  • Monitor and track changes in legal regulatory and contractual requirements affecting information security
  • SAMA CSF PDPL NCA ECC PCI-DSS updating the compliance register accordingly
  • Maintain and update role and responsibility matrices RACI
  • information security governance committee documentation and reporting packs
  • Coordinate security governance committee meetings preparing agendas minutes and action tracking
  • Produce internal and external communication materials related to information security governance policies and programme updates
Information Risk Management
  • Execute information security risk assessments independently applying the organization s risk assessment methodology and producing complete risk registers with identified threats vulnerabilities likelihood impact and treatment plans
  • Maintain and update the information asset register tracking asset owners classifications and associated risk profiles
  • Lead business impact assessment BIA data collection activities coordinating with asset owners and business units to capture accurate recovery objectives and criticality ratings
  • Conduct control effectiveness evaluations for key information security controls documenting findings and escalating gaps to the Lead for treatment
  • Coordinate third-party information security risk assessments preparing assessment questionnaires reviewing vendor responses and producing risk summaries
  • Integrate risk and vulnerability data into procurement reviews project onboarding and change management processes
  • Prepare periodic risk reports for senior review highlighting emerging risks significant changes in the risk profile and the status of risk treatment actions
Compliance & Programme Development
  • Monitor the organization s compliance posture against SAMA CSF NCA ECC PDPL ISO 27001 and PCI-DSS tracking control status identifying gaps and coordinating remediation
  • Coordinate internal and external audit activities gathering evidence packages liaising with auditors tracking findings and monitoring remediation progress
  • Support the preparation of regulatory submissions self-assessments and compliance attestations required by SAMA NCA and PCI Council
  • Maintain and enhance the security awareness programme developing training materials scheduling communications and tracking completion metrics
  • Monitor KPIs and KRIs for the information security programme preparing accurate and timely dashboards for senior management review
  • Support the integration of information security requirements into procurement project management and change control processes
Cross-Functional & General GRC Support
  • Maintain the information security policy standard and procedure library managing version control review cycles and distribution
  • Support information security initiatives across business and technology teams providing GRC subject matter expertise on projects and change programmes
  • Conduct information classification reviews and document security requirements for key business and IT projects
  • Deliver information security awareness sessions and materials to targeted staff groups
  • Provide analytical support for GRC team reporting data gathering and programme tracking activities
Qualifications and Experience
  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
  • 1 3 years of professional experience in information security governance, risk management, compliance, or a closely related field.
  • Hands-on experience with risk assessment execution, policy development, or compliance monitoring is required.
  • Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements is a strong advantage.
  • Experience in a regulated Fintech or banking environment is preferred.
  • ISO 27001 Foundation or Lead Implementer (preferred).
  • CompTIA Security+ or equivalent.
  • Working toward CRISC (Certified in Risk and Information Systems Control) or CISM.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 201,000 - 312,000
Medical Insurance
Paid Time Off
Training & Development
+1
GRC Senior Specialist
GRC Senior Specialist

مرنة للتمويل • Riyadh

On-site
SAR 246,000 - 379,000
Information Security GRC Specialist: Governance & Risk
Information Security GRC Specialist: Governance & Risk

tabby • Saudi Arabia

On-site
SAR 180,000 - 260,000
GRC Consultant
GRC Consultant

Help AG • Riyadh

On-site
SAR 120,000 - 180,000
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

Sifi • Riyadh

On-site
SAR 180,000 - 300,000
Information Security Risk Assessment Manager
Information Security Risk Assessment Manager

SAB • Riyadh

On-site
SAR 240,000 - 420,000
Cybersecurity GRC Lead
Cybersecurity GRC Lead

Confidential • Al Khobar

On-site
SAR 220,000 - 320,000
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000
Information Security Specialist
Information Security Specialist

Tamimi Commercial • Al Khobar

On-site
SAR 150,000 - 200,000
GRC Specialist (KSA National)
GRC Specialist (KSA National)

Specialized Technical Services – STS • Riyadh

On-site
SAR 100,000 - 150,000