Information Security Specialist KSA

تابي

Saudi Arabia

On-site

SAR 120,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Global team
Inclusive culture
Stock options
Growth opportunity
Relocation support
Equipment provided

Job summary

Tabby is seeking an Information Security Specialist (GRC) to join the InfoSec GRC team in KSA. The role will independently execute governance, risk, and compliance activities across Tabby’s information security programme.

You will work on governance frameworks, risk assessments, regulatory tracking (SAMA CSF, PDPL, NCA ECC, PCI-DSS), and reporting. 1–3 years of relevant experience and applicable certifications are preferred.

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
  • 1–3 years of professional information security governance, risk management, compliance experience; hands-on risk assessment, policy development, or compliance monitoring.
  • ISO 27001 Foundation or Lead Implementer (preferred); CompTIA Security+ or equivalent.
  • Working toward CRISC or CISM.

Responsibilities

  • Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures.
  • Draft and revise information security policies, standards, and baselines, ensuring alignment with regulatory requirements and business objectives.
  • Monitor and track changes in regulatory requirements (SAMA CSF, PDPL, NCA ECC, PCI-DSS) and update the compliance register.
  • Maintain role and responsibility matrices (RACI) and governance reporting.
  • Coordinate security governance committee meetings with agendas, minutes and action tracking.
  • Produce internal and external communication materials related to information security governance.

Skills

Risk assessment
Policy development
Compliance monitoring
GRC experience
1–3 years experience
CRISC/CISM (pursuing)

Education

Bachelor's degree in IT/CS/CYBER/Risk mgmt
ISO 27001 Foundation/Lead Implementer
CompTIA Security+ or equivalent

Job description

Information Security Specialist

Department: InfoSec GRC

Employment Type: Full Time

Location: KSA


Description

We're looking for an Information Security Specialist (GRC) to join Tabby! The successful candidate will independently execute governance, risk, and compliance activities across the Tabby's information security programme.


Key Responsibilities
Information Security Governance
  • Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures.
  • Draft and revise information security policies, standards, and baselines, ensuring alignment with applicable regulatory requirements and business objectives.
  • Monitor and track changes in legal, regulatory, and contractual requirements affecting information security (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating the compliance register accordingly.
  • Maintain and update role and responsibility matrices (RACI), information security governance committee documentation, and reporting packs.
  • Coordinate security governance committee meetings — preparing agendas, minutes, and action tracking.
  • Produce internal and external communication materials related to information security governance, policies, and programme updates.
Information Risk Management
  • Execute information security risk assessments independently, applying the organization's risk assessment methodology and producing complete risk registers with identified threats, vulnerabilities, likelihood, impact, and treatment plans.
  • Maintain and update the information asset register — tracking asset owners, classifications, and associated risk profiles.
  • Lead business impact assessment (BIA) data collection activities, coordinating with asset owners and business units to capture accurate recovery objectives and criticality ratings.
  • Conduct control effectiveness evaluations for key information security controls, documenting findings and escalating gaps to the Lead for treatment.
  • Coordinate third-party information security risk assessments — preparing assessment questionnaires, reviewing vendor responses, and producing risk summaries.
  • Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes.
  • Prepare periodic risk reports for senior review, highlighting emerging risks, significant changes in the risk profile, and the status of risk treatment actions.
Compliance & Programme Development
  • Monitor the organization's compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS — tracking control status, identifying gaps, and coordinating remediation.
  • Coordinate internal and external audit activities — gathering evidence packages, liaising with auditors, tracking findings, and monitoring remediation progress.
  • Support the preparation of regulatory submissions, self-assessments, and compliance attestations required by SAMA, NCA, and PCI Council.
  • Maintain and enhance the security awareness programme — developing training materials, scheduling communications, and tracking completion metrics.
  • Monitor KPIs and KRIs for the information security programme, preparing accurate and timely dashboards for senior management review.
  • Support the integration of information security requirements into procurement, project management, and change control processes.
Cross-Functional & General GRC Support
  • Maintain the information security policy, standard, and procedure library — managing version control, review cycles, and distribution.
  • Support information security initiatives across business and technology teams, providing GRC subject matter expertise on projects and change programmes.
  • Conduct information classification reviews and document security requirements for key business and IT projects.
  • Deliver information security awareness sessions and materials to targeted staff groups.
  • Provide analytical support for GRC team reporting, data gathering, and programme tracking activities.

Skills, Knowledge and Expertise
  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
  • 1–3 years of professional experience in information security governance, risk management, compliance, or a closely related field. Hands-on experience with risk assessment execution, policy development, or compliance monitoring is required. Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements is a strong advantage. Experience in a regulated Fintech or banking environment is preferred.
  • ISO 27001 Foundation or Lead Implementer (preferred). CompTIA Security+ or equivalent.
  • Working toward CRISC (Certified in Risk and Information Systems Control) or CISM.

Benefits
  • We are an international Team of inspired professionals located all over the globe.
  • We have an inclusive company culture, embracing diversity, integrity and transparency. We strive for work-life balance and cherish the moments you spend with your loved ones, off-work. In the same spirit as for our product, we are caring and nurturing for our employees.
  • Our people are granted 100% trust and freedom to apply their own vision and come up with their ideas from day 1 at Tabby. You are the one who takes responsibility for your area of work. We encourage everyone to think and make decisions like Tabby was their own business, well because it is. Our employee stock options programme is available for everyone.
  • You will have an opportunity to learn and grow in one of the fastest growing fin tech companies in the region
  • We offer you relocation support as well as we guide you through all the process.
  • We’ll set you up with the devices required for your work.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Specialist
Information Security Specialist

تابي • Riyadh

On-site
SAR 120,000 - 180,000
Relocation support
Devices provided
Information Security Specialist
Information Security Specialist

Tabby | تابي • Riyadh

On-site
SAR 180,000 - 300,000
International team
Stock options
Relocation support
+2
Lead Information Security Engineer (Defensive)
Lead Information Security Engineer (Defensive)

تابي • Riyadh

On-site
SAR 300,000 - 520,000
Lead Information Security Engineer (Defensive)
Lead Information Security Engineer (Defensive)

تابي • Saudi Arabia

On-site
SAR 500,000 - 800,000
Lead, Information Security (Defensive)
Lead, Information Security (Defensive)

Tabby | تابي • Riyadh

On-site
SAR 420,000 - 660,000
GRC Information Security Specialist - Policy & Risk
GRC Information Security Specialist - Policy & Risk

تابي • Riyadh

On-site
SAR 120,000 - 180,000
Relocation support
Devices provided
GRC Information Security Specialist (KSA)
GRC Information Security Specialist (KSA)

تابي • Saudi Arabia

On-site
SAR 120,000 - 210,000
Global team
Inclusive culture
Stock options
+3
GRC Information Security Specialist - Risk & Compliance
GRC Information Security Specialist - Risk & Compliance

Tabby | تابي • Riyadh

On-site
SAR 180,000 - 300,000
International team
Stock options
Relocation support
+2
Information Security GRC Specialist: Governance & Risk
Information Security GRC Specialist: Governance & Risk

tabby • Saudi Arabia

On-site
SAR 180,000 - 260,000
AML Officer
AML Officer

تابي • Riyadh

On-site
SAR 134,000 - 201,000
Relocation support
Employee stock options
Devices provided
+1