SlipstreamJobsFresh Startup & VC-Backed Jobs

Global Cybersecurity GRC Manager

Foodics - Riyadh, Saudi Arabia - In-office - posted 2026-08-26

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Foodics is a leading restaurant management ecosystem and payment technology provider founded in 2014, headquartered in Riyadh with offices across 5 countries (UAE, Egypt, Jordan, Kuwait) serving customers in over 35 countries. The company has processed over 6 billion orders and recently raised $170 million in the largest SaaS funding round in MENA. You will manage and coordinate the group's cybersecurity governance, risk, and compliance (GRC) program under the direction of the CISO. This is a high-visibility, cross-functional role responsible for translating cybersecurity frameworks, regulatory obligations, and business risks into practical controls, clear ownership, measurable remediation plans, and decision-ready reporting. Key responsibilities include: - Manage day-to-day GRC activities, priorities, operating cadence, and continuous improvement initiatives across the Foodics Group - Conduct and coordinate gap assessments against ISO 27001, SOC 2, NCA ECC, SAMA CSF, KSA PDPL, and other applicable requirements - Translate regulatory and framework requirements into practical controls with accountable owners, target dates, and measurable evidence requirements - Maintain the cybersecurity policy framework including policies, standards, procedures, control owners, and governance records - Own and maintain the cybersecurity risk register, facilitate risk assessments, and drive follow-up on treatment plans and risk acceptance - Monitor control implementation and remediation progress, challenge weak responses, and escalate material risks and overdue actions - Coordinate internal and external audits, customer cybersecurity due diligence, and certification activities - Support Foodics Pay cybersecurity compliance activities including control mapping, evidence coordination, and audit support - Prepare cybersecurity GRC dashboards, KPIs, KRIs, risk summaries, and compliance status reports for management and governance committees - Partner with control owners across Technology, Product, Operations, HR, Legal, Privacy, and Procurement to embed cybersecurity requirements into business processes - Maintain compliance calendar and ensure recurring assessments, reviews, and audit commitments are completed on schedule - Improve GRC program efficiency through standardized templates, control libraries, automation, and tooling You will work closely with Cybersecurity, Technology, Product, Legal, Privacy, Internal Audit, and business teams across the group. REQUIREMENTS: - 10+ years of professional experience in cybersecurity governance, risk, compliance, audit, or closely related field, with demonstrated experience managing enterprise GRC activities and working with senior cybersecurity leadership - Strong hands-on knowledge of ISO 27001 and SOC 2, with practical experience conducting gap assessments, mapping controls, collecting evidence, and driving remediation to closure - Good working knowledge of Saudi cybersecurity and privacy requirements, particularly NCA ECC and KSA PDPL, with ability to interpret requirements and translate them into actionable controls - Demonstrated experience owning or managing cybersecurity risk registers, risk assessments, treatment plans, risk acceptance, exceptions, and management escalation - Experience maintaining cybersecurity policies, standards, procedures, control libraries, control ownership, evidence repositories, and compliance documentation - Proven ability to coordinate internal and external audits, manage evidence requests, respond to customer security assessments, and support certification or assurance readiness - Strong analytical skills and ability to turn complex risk and compliance information into clear dashboards, executive summaries, and decision-ready committee reporting - Stakeholder management skills with confidence to challenge control owners constructively, drive accountability, and follow actions through to completion - Strong written and verbal communication in English, including ability to write clear policies, risk statements, assessment findings, remediation actions, and management reports - Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, or related discipline, or equivalent relevant professional experience NICE TO HAVE: - Experience working in FinTech, payments, SaaS, or other regulated and technology-driven environment - Experience with SAMA cybersecurity requirements or supporting cybersecurity compliance activities for regulated payment or financial-services entity - Professional certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISM, CRISC, CISA, CISSP, or equivalent - Experience with PCI DSS, third-party cybersecurity risk management, privacy compliance, or other regional and international security frameworks - Hands-on experience with GRC platforms, evidence automation, compliance tooling, or building structured control and risk reporting workflows - Experience operating across multiple business entities, countries, or regulatory environments - Arabic language skills for engaging with stakeholders, regulators, and documentation

Similar roles