SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tabby is seeking a Lead Anti-Fraud Officer to independently lead complex governance, risk, and compliance (GRC) activities within a Saudi fintech environment. This role serves as a subject matter matter expert across enterprise information security governance, risk management frameworks, regulatory compliance, and third-party risk management.
The Lead Anti-Fraud Officer will produce high-quality GRC deliverables, provide technical mentoring to junior and mid-level team members, and drive continuous improvement of the organization's GRC framework and compliance reporting mechanisms. The role operates as a bridge between technical execution and programme leadership, collaborating with legal, audit, and business stakeholders to achieve mature GRC outcomes aligned with Saudi fintech regulatory requirements.
Key responsibilities include:
**Governance & Policy Leadership:** Develop, review, and continuously improve information security policies, standards, procedures, and governance frameworks. Serve as subject matter expert for assigned regulatory domains, providing authoritative interpretation of requirements and translating them into implementable control objectives. Monitor regulatory and legal developments affecting information security and recommend framework updates. Prepare governance documentation including RACI matrices and security charter updates for senior stakeholder review. Lead regulatory self-assessments and compliance attestations, coordinating evidence gathering and quality review. Mentor junior team members on governance documentation, regulatory interpretation, and risk assessment methodology.
**Enterprise Risk Management:** Lead execution of complex enterprise information security risk assessments using advanced qualitative and quantitative methodologies. Own and maintain the enterprise information security risk register with accurate, current escalation of significant risks. Lead Business Impact Analysis (BIA) processes for critical business functions, coordinating with asset owners and producing outputs for Business Continuity and Disaster Recovery planning. Design and execute control effectiveness testing programmes with gap analysis and risk-ranked remediation recommendations. Lead third-party information security risk management, designing assessment frameworks and maintaining the third-party risk register. Produce executive-quality risk reporting with trend analysis and treatment progress tracking.
**Compliance Programme Delivery:** Lead compliance monitoring for CFFR, NCA ECC, PDPL, ISO 27001, and PCI-DSS frameworks, producing gap analyses and periodic status reports. Manage internal and external audit cycles, coordinating evidence collection and tracking remediation to closure. Design and deliver security awareness programmes with targeted content and effectiveness metrics. Develop and maintain GRC programme metrics dashboards with accurate KPI and KRI measurement. Lead integration of information security requirements into third-party contracts and procurement processes. Contribute to information security programme strategy development.
**Cross-Functional Collaboration:** Serve as primary GRC point of contact for assigned business and technology teams, providing expert guidance on security requirements and compliance obligations. Lead information classification and security requirements reviews for significant projects. Contribute to the GRC knowledge base with reusable templates and guidance documents. Represent the GRC function in cross-functional working groups and regulatory workstreams.
**Requirements:**
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or related field
- Master's degree in Information Security, Risk Management, or Business Administration is advantageous
- 3–5 years of progressive professional experience in information security governance, risk management, or compliance
- Demonstrable experience independently leading risk assessment cycles, regulatory compliance programmes, or audit coordination activities
- In-depth knowledge of the CFFR framework is required
- Experience in a regulated Fintech or banking environment is strongly preferred