Lead Anti-Fraud Officer

Tabby | تابي

Riyadh

On-site

SAR 240,000 - 360,000

Full time

8 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Relocation support
Employee stock options
Devices provided

Job summary

Tabby, a leading fintech in the KSA, seeks a Lead Anti-Fraud Officer to independently lead governance, risk and compliance activities and to serve as a subject matter expert in GRC domains across enterprise information security governance, risk management frameworks, regulatory compliance, or third‑party risk management. The role mentors junior staff and contributes to ongoing improvements of the GRC framework.

Department: Risk B2C. Location: KSA.

Qualifications

  • Bachelor's degree in information technology, computer science, software engineering, cybersecurity or risk management is required.
  • Experience leading risk assessment cycles, regulatory compliance programmes or audit coordination.
  • In‑depth knowledge of the CFFR framework is required.
  • Experience in a regulated fintech or banking environment is strongly preferred.

Responsibilities

  • Lead the development, review, and continuous improvement of information security policies, standards, procedures, and governance frameworks.
  • Serve as SME for regulatory domains, translating requirements into implementable control objectives.
  • Monitor regulatory and legal developments and update the governance framework accordingly.
  • Prepare and review governance documentation and present findings to senior stakeholders.
  • Lead regulatory self-assessments and compliance attestations with evidence gathering and sign‑off.

Skills

GRC governance
Regulatory compliance
Risk management
Third‑party risk management

Education

Bachelor's degree in IT/CS/Software Engineering/Cybersecurity/Risk Management
Master's degree in Information Security/Risk Management/BA

Job description

The Lead Anti-Fraud Officer independently leads complex governance, risk, and compliance activities and serves as a subject matter expert in one or more GRC domains — enterprise information security governance, risk management frameworks, regulatory compliance, or third-party risk management. The role produces high-quality GRC deliverables, provides technical mentoring to junior and mid-level team members, and contributes directly to the continuous improvement of the organization’s GRC framework, risk treatment processes, and compliance reporting mechanisms.

Department: Risk B2C

Employment Type: Full Time

Location: KSA

Key Responsibilities
  • Lead the development, review, and continuous improvement of information security policies, standards, procedures, and governance frameworks.
  • Serve as the subject matter expert for assigned regulatory domains, providing authoritative interpretation of requirements and translating them into implementable control objectives.
  • Monitor and proactively track regulatory and legal developments affecting information security — assessing impact and recommending updates to the governance framework.
  • Prepare and review governance documentation — RACI matrices, security charter updates, governance committee packs — and present findings to senior stakeholders.
  • Lead the preparation of regulatory self‑assessments and compliance attestations, coordinating evidence gathering and quality‑reviewing submissions before senior sign‑off.
  • Mentor GR1–GR2 team members on governance documentation quality, regulatory interpretation, and risk assessment methodology.
Enterprise Risk Management
  • Lead the execution of complex enterprise information security risk assessments, applying advanced qualitative and quantitative methodologies to produce risk profiles aligned with the organization’s risk appetite.
  • Own and maintain the enterprise information security risk register — ensuring accuracy, currency, and appropriate escalation of significant risks.
  • Lead BIA processes for critical business functions — coordinating with asset owners, analysing recovery requirements, and producing BIA outputs for Business Continuity and Disaster Recovery planning.
  • Design and execute control effectiveness testing programmes, producing findings reports with gap analysis and risk‑ranked remediation recommendations.
  • Lead third‑party information security risk management — designing assessment frameworks, conducting in‑depth vendor reviews, and maintaining the third‑party risk register.
  • Produce executive‑quality risk reporting with trend analysis, emerging risk identification, and treatment progress tracking for senior management and committee consumption.
Compliance Programme Delivery
  • Lead compliance monitoring activities for CFFR, NCA ECC, PDPL, ISO 27001, and PCI‑DS — producing gap analyses, treatment plans, and periodic compliance status reports.
  • Manage internal and external audit cycles — coordinating evidence collection, reviewing evidence quality, engaging with auditors, and tracking remediation to closure.
  • Design and deliver the security awareness programme — producing targeted content for different staff segments, conducting awareness sessions, and analysing effectiveness metrics.
  • Develop and maintain GRC programme metrics dashboards, ensuring KPIs and KRIs are accurately measured and presented to senior management on schedule.
  • Lead the integration of information security requirements into third‑party contracts, procurement processes, and major project onboarding.
  • Contribute to the development of the information security programme strategy, identifying capability improvement opportunities and recommending investment priorities to the Lead.
Cross‑Functional Collaboration & Knowledge Leadership
  • Serve as the primary GRC point of contact for assigned business and technology teams — providing expert guidance on security requirements, risk treatment, and compliance obligations.
  • Lead information classification and security requirements reviews for significant IT, product, and business projects.
  • Contribute to the GRC knowledge base — developing reusable templates, guidance documents, and training materials for internal use.
  • Represent the GRC function in cross‑functional working groups, project steering committees, and regulatory workstreams.
  • Perform additional responsibilities as assigned by management.
Skills, Knowledge and Expertise
  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
  • A Master's degree in Information Security, Risk Management, or Business Administration is an advantage.
  • 3–5 years of progressive professional experience in information security governance, risk management, or compliance. Demonstrable experience independently leading risk assessment cycles, regulatory compliance programmes, or audit coordination activities.
  • In‑depth knowledge of the CFFR framework is required.
  • Experience in a regulated Fintech or banking environment is strongly preferred.
Benefits
  • We have an inclusive company culture, embracing diversity, integrity and transparency. We strive for work‑life balance and cherish the moments you spend with your loved ones, off‑work. In the same spirit as for our product, we are caring and nurturing for our employees.
  • Our people are granted 100% trust and freedom to apply their own vision and come up with their ideas from day 1 at Tabby. You are the one who takes responsibility for your area of work. We encourage everyone to think and make decisions like Tabby was their own business, well because it is. Our employee stock options programme is available for everyone.
  • You will have an opportunity to learn and grow in one of the fastest growing fintech companies in the region
  • We offer you relocation support as well as we guide you through all the process.
  • We’ll set you up with the devices required for your work.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Anti-Fraud Officer
Lead Anti-Fraud Officer

تابي • Riyadh

On-site
SAR 240,000 - 360,000
Relocation support
Stock options
Device setup
+1
Information Security Specialist
Information Security Specialist

تابي • Riyadh

On-site
SAR 120,000 - 180,000
Relocation support
Devices provided
Information Security Lead (Defensive)
Information Security Lead (Defensive)

تابي • Riyadh

On-site
SAR 320,000 - 520,000
Lead Information Security Engineer (Defensive) at Tabby
Lead Information Security Engineer (Defensive) at Tabby

Tabby • Riyadh

On-site
SAR 350,000 - 650,000
Lead, Information Security (Defensive)
Lead, Information Security (Defensive)

Tabby | تابي • Riyadh

On-site
SAR 420,000 - 660,000
Lead Information Security Engineer (Defensive)
Lead Information Security Engineer (Defensive)

Tabby | تابي • Riyadh

On-site
SAR 260,000 - 380,000
Lead Information Security Engineer (Defensive)
Lead Information Security Engineer (Defensive)

تابي • Riyadh

On-site
SAR 300,000 - 520,000
Lead Information Security Engineer (Defensive)
Lead Information Security Engineer (Defensive)

تابي • Saudi Arabia

On-site
SAR 500,000 - 800,000
Senior GRC & InfoSec Lead - Compliance & Risk (Relocation)
Senior GRC & InfoSec Lead - Compliance & Risk (Relocation)

تابي • Riyadh

On-site
SAR 240,000 - 360,000
Relocation support
Stock options
Device setup
+1
Lead Anti-Fraud Officer
Lead Anti-Fraud Officer

tabby • Medina

On-site
SAR 300,000 - 540,000