Cybersecurity GRC Manager
📣 Job Ad| Contract Type | Full-time | |
| Workplace type | On-site | |
| Location | Riyadh |
Job Description
About Hala
Hala is a leading fintech company in the MENAP region, focused on redefining financial services for Small and Medium-sized Enterprises (SMEs). The company aims to empower SMEs by providing advanced financial and technological tools to support their business operations and growth. Established in 2017, Hala holds licenses from the Saudi Arabian Central Bank and operates multiple entities across UAE, Saudi Arabia, and Egypt, including Hala Payments and Hala Logistics. Its solutions enable merchants to digitize payments and manage sales and operations.
The Role
Hala is seeking a Cybersecurity GRC Manager to join its team in Riyadh, Saudi Arabia. This full-time position requires 5-10 years of experience and is central to developing and maintaining the organization's cybersecurity posture through robust governance, risk management, and compliance frameworks. The role involves overseeing critical security functions and ensuring alignment with regulatory requirements and business objectives.
Key Responsibilities
- Develop, implement, and continuously improve the Information Security Governance framework, policies, standards, and procedures.
- Lead the creation and execution of the Cyber Security Strategy, aligning it with overall business goals.
- Provide regular reports to the Board of Directors and executive management on the state of cybersecurity.
- Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure program effectiveness.
- Oversee the information security budget, ensuring effective resource allocation for risk management.
- Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program.
- Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks.
- Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation strategies.
- Manage the vendor risk management program, assessing the security posture of third-party vendors, especially cloud service providers and payment gateways.
- Integrate risk management into the Software Development Life Cycle (SDLC) and change management processes.
- Serve as the primary point of contact for regulatory examinations and audits related to cybersecurity (*, SAMA, CMA).
- Ensure continuous compliance with SAMA's Cyber Security Framework (CSF), PCI DSS requirements, and other relevant regulations.
- Manage the process for obtaining and maintaining necessary regulatory licenses and certifications from a cybersecurity perspective.
- Prepare and submit accurate and timely regulatory reports, questionnaires, and evidence requests.
- Monitor the regulatory landscape for changes in laws, regulations, and standards, advising the business on required adjustments.
- Manage all internal and external security audits, including coordination with auditors, evidence provision, and tracking remediation of findings.
- Develop and maintain a robust control testing program to validate the effectiveness of key security controls.
- Manage the remediation of all audit and assessment findings, ensuring effective and permanent closure.
- Develop and deliver a security awareness and training program tailored to different organizational roles, with a focus on local context and threats.
- Champion a strong security culture, ensuring employees understand their role in protecting company information assets.
Experience and Qualifications
- A minimum of 5 to 10 years of relevant experience in cybersecurity, governance, risk, and compliance.
- Demonstrated expertise in developing and implementing information security frameworks, policies, and procedures.
- Strong understanding of regulatory compliance requirements, particularly SAMA's Cyber Security Framework (CSF) and PCI DSS.
- Experience in managing security audits and remediation processes.
- Ability to develop and deliver effective security awareness and training programs.
Work Environment
This is a full-time position based in Riyadh, Saudi Arabia, within a dynamic fintech environment. The role involves working closely with various departments and executive management to ensure comprehensive cybersecurity coverage.
Application Process
Candidates who meet the specified qualifications are encouraged to apply. Salary details will be discussed during the interview process.
Requirements
- Requires 5-10 Years experience
Similar Jobs
You may also like
- Related Cybersecurity GRC Manager Opportunities
- Cashier Jobs in Medina
- Human Resources Specialist Jobs in Medina
- Sales Representative Jobs in Medina
- Marketing Specialist Jobs in Medina
- Electrical Engineer Jobs in Medina
- Other Job Fields in Riyadh
- Barista Jobs in Riyadh
- Marketing Manager Jobs in Riyadh
- Cashier Jobs in Riyadh
- Human Resources Specialist Jobs in Riyadh
- Senior Accountant Jobs in Riyadh
- Sales Representative Jobs in Riyadh
- Customer Service Representative Jobs in Riyadh
- Marketing Specialist Jobs in Riyadh
- Electrical Engineer Jobs in Riyadh
- Receptionist Jobs in Riyadh
- Explore Jobs Across Saudi Arabia
- Sales Coordinator Jobs in Riyadh
- General Services Controller Jobs in Khamis Mushayt
- Seller Jobs in Al Qatif
- Seller Jobs in Dammam
- Software Developer Jobs in Dammam
- Engineering Supervisor Jobs in Riyadh
- Agricultural Engineer Jobs in Jazan
- Administrative Assistant Jobs in Al Jubail
- Nurse Specialist Jobs in Wadi Ad Dawasir
- Head Chef Jobs in Al Khobar