Information Security Specialist
Job Description Roles & Responsibilities We're looking for an Information Security Specialist (GRC) to join Tabby! The successful candidate will independently execute governance, risk, and compliance activities across the Tabby's information security programme. Information Security Governance Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures. Draft and revise information security policies, standards, and baselines, ensuring alignment with applicable regulatory requirements and business objectives. Monitor and track changes in legal, regulatory, and contractual requirements affecting information security (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating the compliance register accordingly. Maintain and update role and responsibility matrices (RACI), information security governance committee documentation, and reporting packs. Coordinate security governance committee meetings preparing agendas, minutes, and action tracking. Produce internal and external communication materials related to information security governance, policies, and programme updates. Information Risk Management Execute information security risk assessments independently, applying the organization's risk assessment methodology and producing complete risk registers with identified threats, vulnerabilities, likelihood, impact, and treatment plans. Maintain and update the information asset register tracking asset owners, classifications, and associated risk profiles. Lead business impact assessment (BIA) data collection activities, coordinating with asset owners and business units to capture accurate recovery objectives and criticality ratings. Conduct control effectiveness evaluations for key information security controls, documenting findings and escalating gaps to the Lead for treatment. Coordinate third-party information security risk assessments preparing assessment questionnaires, reviewing vendor responses, and producing risk summaries. Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes. Prepare periodic risk reports for senior review, highlighting emerging risks, significant changes in the risk profile, and the status of risk treatment actions. Compliance & Programme Development Monitor the organization's compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS tracking control status, identifying gaps, and coordinating remediation. Coordinate internal and external audit activities gathering evidence packages, liaising with auditors, tracking findings, and monitoring remediation progress. Support the preparation of regulatory submissions, self-assessments, and compliance attestations required by SAMA, NCA, and PCI Council. Maintain and enhance the security awareness programme developing training materials, scheduling communications, and tracking completion metrics. Monitor KPIs and KRIs for the information security programme, preparing accurate and timely dashboards for senior management review. Support the integration of information security requirements into procurement, project management, and change control processes. Cross-Functional & General GRC Support Maintain the information security policy, standard, and procedure library managing version control, review cycles, and distribution. Support information security initiatives across business and technology teams, providing GRC subject matter expertise on projects and change programmes. Conduct information classification reviews and document security requirements for key business and IT projects. Deliver information security awareness sessions and materials to targeted staff groups. Provide analytical support for GRC team reporting, data gathering, and programme tracking activities. Desired Candidate Profile Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field. 1 3 years of professional experience in information security governance, risk management, compliance, or a closely related field. Hands-on experience with risk assessment execution, policy development, or compliance monitoring is required. Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements is a strong advantage. Experience in a regulated Fintech or banking environment is preferred. ISO 27001 Foundation or Lead Implementer (preferred). CompTIA Security+ or equivalent. Working toward CRISC (Certified in Risk and Information Systems Control) or CISM. Company Industry BankingFinancial ServicesBroking Department / Functional Area IT Software Keywords Information Security Specialist Get real-time job updates only on our App
Ready to apply?
You are viewing this role on JobSphere AI. Applications are completed on the original employer / source website.
Apply NowOpens the employer's site in a new tab
- Companytabby
- LocationSaudi Arabia
- CategoryCybersecurity
- SourceNaukrigulf
- Listed1 month ago
Related Cybersecurity jobs
Technical I, IT Operations
The Technical I, IT Operations role provides end user support across Concentrix s desktop, network, telephony, and application environments. In this hands-on…
Operator - UAE National
Job Title: Operator Reporting To: Manager Main roles and responsibilities: -Work on 24/7 security patrols at sensitive locations, ensuring immediate response…
Site Engineer
Required 02 male Site Supervisor / Engineer with the below job description & requirements Project Execution: Execute architectural and MEP works as per the…
Principal Inspector – Public Health (UAE Nationals)
Purpose of the Position Perform advanced-level inspection, investigation, and health surveillance activities at ports to ensure compliance with public health…