img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About Foodics and the Role

Foodics, a leading restaurant management ecosystem and payment tech provider, was founded in 2014 with headquarters in Riyadh. Operating across 5 countries and serving customers in over 35 worldwide, Foodics has processed over 6 billion orders. As one of the most rapidly evolving SaaS companies in the MENA region, having raised $170 million in funding, Foodics is seeking a Head of Risk and Cyber Security to join its team in Riyadh. This full-time role is pivotal for establishing, leading, and maturing the organization's enterprise risk management (ERM) and information/cyber security functions.

Role Purpose

The Head of Risk and Cyber Security is responsible for ensuring the business effectively identifies, assesses, and mitigates operational, financial, regulatory, and technology-related risks. This role also involves safeguarding company and customer data against cyber threats. The incumbent will serve as the primary advisor to senior leadership and the board regarding risk posture and security strategy.

Enterprise Risk Management Responsibilities

  • Design and maintain the organization's ERM framework, risk appetite statement, and risk registers.
  • Lead periodic risk assessments across business units and consolidate findings into board/ERM committee reporting, including Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs).
  • Identify emerging risks (operational, strategic, financial, regulatory, reputational) and drive mitigation planning with process owners.
  • Own business continuity and disaster recovery planning.
  • Support internal audit and compliance functions with risk-based input.

Cyber and Information Security Responsibilities

  • Develop and execute the information security strategy, policies, and controls.
  • Oversee security operations, including threat detection, vulnerability management, incident response, and penetration testing programs.
  • Lead cyber incident response planning and act as incident commander during security events.
  • Ensure compliance with data protection regulations and industry certifications.
  • Manage security awareness training programs across the organization.

Leadership and Governance

  • Build, lead, and develop the risk and security team.
  • Present regular risk and security posture updates to executive leadership and the board/risk committee.
  • Manage relationships with regulators, auditors, and external security partners.
  • Own the risk and security budget, tooling, and roadmap.

Qualifications and Experience

  • Bachelor's degree in Information Security, Risk Management, Computer Science, or a related field; Master's degree preferred.
  • 10+ years of experience in risk management and/or cybersecurity, with 5+ years in a leadership role.
  • Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent.
  • Strong knowledge of regulatory frameworks relevant to the industry and region.
  • Proven experience building risk frameworks and security programs from the ground up or scaling existing ones.
  • Excellent stakeholder management and board-level communication skills.
  • Fluent in English, with strong written and verbal communication skills.
  • Demonstrated strategic thinking with hands-on execution ability.
  • Strong analytical and problem-solving skills.
  • Ability to manage crises and make decisions under pressure.
  • Proven cross-functional influence without direct authority.

متطلبات الوظيفة

  • تتطلب اكثر من ١٠ سنوات خبرة

وظائف مشابهة