SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tabby is seeking an Information Security Specialist to independently execute governance, risk, and compliance (GRC) activities across the organization's information security programme.
Key responsibilities span three core areas:
Information Security Governance: Maintain and update the security governance framework, policy library, standards, and procedures. Draft and revise policies aligned with regulatory requirements (SAMA CSF, PDPL, NCA ECC, PCI-DSS). Monitor changes in legal and regulatory requirements, updating compliance registers. Maintain RACI matrices and governance committee documentation. Coordinate security governance meetings and produce internal/external communications on security initiatives.
Information Risk Management: Execute information security risk assessments independently, producing complete risk registers with threat, vulnerability, likelihood, impact, and treatment analysis. Maintain the information asset register tracking owners, classifications, and risk profiles. Lead business impact assessment data collection with asset owners. Conduct control effectiveness evaluations and escalate gaps. Coordinate third-party risk assessments and vendor questionnaires. Integrate risk and vulnerability data into procurement, project onboarding, and change management. Prepare periodic risk reports for senior leadership.
Compliance & Programme Development: Monitor compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS. Coordinate internal and external audits, gather evidence, track findings, and monitor remediation. Support regulatory submissions and self-assessments. Maintain and enhance the security awareness programme. Monitor KPIs and KRIs, preparing dashboards for management. Support integration of security requirements into procurement and project management.
The role also includes cross-functional GRC support: managing the policy library, providing GRC expertise on projects, conducting information classification reviews, delivering awareness sessions, and supporting team reporting and programme tracking.
Required: Bachelor's degree in IT, Computer Science, Cybersecurity, Risk Management, or related field. 1–3 years of professional experience in information security governance, risk management, or compliance with hands-on risk assessment, policy development, or compliance monitoring. Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC is a strong advantage. Experience in regulated Fintech or banking environments is preferred. ISO 27001 Foundation or Lead Implementer certification preferred; CompTIA Security+ or equivalent required. Working toward CRISC or CISM is valued.