img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About Foodics and the Role

Foodics is a leading restaurant management ecosystem and payment technology provider, established in 2014 with headquarters in Riyadh. The company maintains offices across 5 countries and serves customers and partners in over 35 different countries worldwide, having processed more than 6 billion orders. Foodics is recognized as one of the most rapidly evolving SaaS companies from the MENA region, having successfully completed three rounds of funding, with the latest raising $170 million in the largest SaaS funding round in MENA. This full-time position for a Head of Risk and Cyber Security is based in Riyadh, Riyadh Province.

Role Overview

The Head of Risk and Cyber Security is responsible for establishing, leading, and maturing the organization's enterprise risk management (ERM) and information/cyber security functions. This role ensures the business identifies, assesses, and mitigates operational, financial, regulatory, and technology-related risks, while safeguarding company and customer data against cyber threats. The Head of Risk and Cyber Security acts as the primary advisor to senior leadership and the board on risk posture and security strategy.

Enterprise Risk Management Responsibilities

  • Design and maintain the organization's ERM framework, risk appetite statement, and risk registers.
  • Lead periodic risk assessments across business units and consolidate findings into board and ERM committee reporting, including Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs).
  • Identify emerging risks across operational, strategic, financial, regulatory, and reputational domains, and drive mitigation planning with process owners.
  • Own business continuity and disaster recovery planning.
  • Support internal audit and compliance functions with risk-based input.

Cyber and Information Security Responsibilities

  • Develop and execute the information security strategy, policies, and controls.
  • Oversee security operations, including threat detection, vulnerability management, incident response, and penetration testing programs.
  • Lead cyber incident response planning and act as incident commander during security events.
  • Ensure compliance with data protection regulations and industry certifications.
  • Manage security awareness training programs across the organization.

Leadership and Governance

  • Build, lead, and develop the risk and security team.
  • Present regular risk and security posture updates to executive leadership and the board or risk committee.
  • Manage relationships with regulators, auditors, and external security partners.
  • Own the risk and security budget, tooling, and roadmap.

Qualifications and Experience

  • A minimum of 10 years of relevant experience.
  • Certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent.
  • Strong knowledge of regulatory frameworks relevant to the industry and region.
  • Proven experience in building risk frameworks and security programs from the ground up or scaling existing ones.
  • Excellent stakeholder management and board-level communication skills.

متطلبات الوظيفة

  • تتطلب اكثر من ١٠ سنوات خبرة

وظائف مشابهة