img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Tamara

Tamara is a leading fintech platform operating across Saudi Arabia and the wider GCC region. The company's mission is to empower individuals by building a customer-centric financial super-app. Tamara serves millions of users and collaborates with prominent global and regional brands, including SHEIN, Jarir, noon, IKEA, and Amazon, alongside various small and medium businesses. As Saudi Arabia's first fintech unicorn, Tamara is supported by investors such as Sanabil Investments, SNB Capital, and *********, with its headquarters located in Riyadh, Saudi Arabia, complemented by regional and global support offices.

The Role: Cybersecurity GRC Lead

Tamara is seeking a dedicated Cybersecurity GRC Lead to join its Cyber Security team in Riyadh. This full-time role involves owning the day-to-day governance, risk, and compliance (GRC) operations that underpin Tamaraโ€™s cybersecurity program. The successful candidate will ensure the organization meets regulatory expectations, maintains a robust control environment, and continuously enhances its security posture. This position requires an experienced individual contributor capable of operating independently, taking ownership of GRC deliverables, and leading initiatives to advance the maturity of Tamaraโ€™s cybersecurity governance and compliance program.

Key Responsibilities

  • Support end-to-end SAMA inspection readiness, including compliance assessments, evidence coordination, gap analysis, and direct support during on-site regulatory visits.
  • Lead compliance assessment and alignment activities across applicable regulatory frameworks such as SAMA CSF, NCA, PCI-DSS, and PDPL, ensuring timely closure of identified gaps and observations.
  • Drive the governance lifecycle for cybersecurity policies, standards, and procedures, encompassing development, periodic review, version control, stakeholder approval, and communication.
  • Maintain and manage compliance mappings, control inventories, and maturity tracking across all in-scope frameworks to ensure accuracy and audit-readiness.
  • Follow up with first-line teams (Technology, Engineering, IT Ops) and relevant business stakeholders to ensure timely implementation and remediation of compliance requirements and control gaps.
  • Coordinate and respond to regulatory initiatives, requests, and ad-hoc inquiries from regulators like SAMA, NCA, and relevant payment scheme bodies.
  • Prepare and present cybersecurity governance, compliance status, and maturity updates for the Cyber Security Committee and other internal governance forums.
  • Produce GRC-related dashboards, metrics, and KPI reports to provide leadership visibility on compliance posture, policy health, and remediation progress.
  • Collaborate with Enterprise Risk and Compliance teams on cross-functional risk and compliance matters, including contributing to vendor risk assessment reviews from a cybersecurity perspective.
  • Utilize and maintain Tamaraโ€™s GRC platform to manage compliance workflows, control assessments, policy repositories, and audit evidence.
  • Support audit activities by coordinating evidence collection, tracking findings, and following up on remediation and mitigation actions to closure.
  • Stay current on regulatory updates, emerging cybersecurity risks, and industry best practices relevant to fintech and financial services in the GCC region.

Required Qualifications and Experience

  • 4โ€“6 years of experience in Cyber Security GRC, Technology Risk, IT Governance, IT Audit, or a related field within financial services, fintech, or banking.
  • Demonstrated experience with regulatory compliance frameworks, particularly SAMA CSF (required) and NCA (preferred). Experience with PCI-DSS and/or PDPL is a strong advantage.
  • Solid understanding of cybersecurity governance principles, policy lifecycle management, and control assessment methodologies.
  • Experience conducting or supporting regulatory inspections, compliance assessments, and maturity evaluations.
  • Proven ability to manage compliance remediation programs, track findings to closure, and coordinate across multiple stakeholders.
  • Experience working with GRC platforms and tools for compliance management, policy governance, and audit tracking is a plus.

Skills and Competencies

  • Strong documentation and reporting skills, with the ability to produce clear, structured deliverables for both technical and executive audiences.
  • Ability to operate independently and take ownership of deliverables.
  • Effective coordination and communication skills for engaging with various internal and external stakeholders.

Work Environment

This role is based at Tamara's headquarters in Riyadh, Saudi Arabia. As a Cybersecurity GRC Lead, you will be a key individual contributor within the Cyber Security team, driving critical compliance and governance initiatives in a dynamic fintech environment.


Requirements

  • Requires 2-5 Years experience

Similar Jobs