Décryptage du poste par Postule AI
Décryptage du poste par Postule AI
Généré automatiquement par Postule AI à partir de l’offre.
About the Role
Join Tabby as an Information Security Specialist (GRC) to independently execute governance, risk, and compliance activities across our information security programme. This role is ideal for a detail-oriented professional with hands-on experience in security governance, risk management, and compliance frameworks.
Key Responsibilities
Information Security Governance
- Maintain and update information security governance framework documentation, policy library, standards, and procedures.
- Draft and revise information security policies, standards, and baselines aligned with regulatory requirements and business objectives.
- Monitor and track changes in legal, regulatory, and contractual requirements (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating compliance registers.
- Coordinate security governance committee meetings, preparing agendas, minutes, and action tracking.
Information Risk Management
- Execute information security risk assessments independently, producing complete risk registers with identified threats, vulnerabilities, and treatment plans.
- Maintain and update information asset registers, tracking asset owners, classifications, and risk profiles.
- Lead business impact assessment (BIA) data collection activities with asset owners and business units.
- Conduct control effectiveness evaluations and coordinate third-party information security risk assessments.
Compliance & Programme Development
- Monitor compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS, tracking control status and coordinating remediation.
- Coordinate internal and external audit activities, gathering evidence and tracking findings.
- Maintain and enhance the security awareness programme with training materials and completion tracking.
- Monitor KPIs and KRIs, preparing dashboards for senior management review.
Required Skills & Qualifications
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Risk Management, or related field.
- 1–3 years of professional experience in information security governance, risk management, or compliance with hands-on experience in risk assessment, policy development, or compliance monitoring.
- ISO 27001 Foundation or Lead Implementer certification (preferred); CompTIA Security+ or equivalent.
- Working toward CRISC or CISM certification.
- Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC; experience in regulated Fintech or banking environments is preferred.
Why Join Tabby?
- Work with an international team of inspired professionals across the globe.
- Inclusive company culture embracing diversity, integrity, and transparency with strong work-life balance.
- 100% trust and freedom to apply your vision from day 1; employee stock options available for everyone.
- Opportunity to grow in one of the fastest-growing fintech companies in the region.
- Relocation support and all necessary work devices provided.
Cette description d'emploi a pu être reformatée par Postule pour améliorer sa lisibilité et sa présentation. Le contenu et les informations restent fidèles à l'offre d'emploi originale. .
