img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Sifi and the Role

Sifi is a fast-growing B2B FinTech company specializing in spend management and card issuance solutions, helping companies control spending and streamline expense workflows. We are seeking a Cybersecurity GRC Specialist to join our team in Riyadh, Ar Riyad. This full-time position requires 2-5 years of relevant experience and is central to maintaining Sifi’s cybersecurity compliance posture and ensuring audit readiness.

Role Overview

The Cybersecurity GRC Specialist plays a critical role in maintaining Sifi’s cybersecurity compliance posture and ensuring audit readiness across all regulatory frameworks. This role is responsible for managing the full Governance, Risk, and Compliance (GRC) lifecycle, ensuring that all cybersecurity controls are measurable, defensible, and aligned with regulatory expectations.

Key Responsibilities

  • Regulatory Compliance & Audit Readiness: Maintain and manage the compliance tracker across SAMA CSF, PDPL/NDMO, and PCI-DSS. This includes owning the full evidence lifecycle (collection, validation, documentation), ensuring continuous audit readiness, tracking regulatory findings and remediation plans, and providing regular compliance status reports to the CISO and relevant committees.
  • Governance & Policy Management: Develop and maintain cybersecurity policies, standards, and procedures. Ensure documentation aligns with SiFi governance structure and regulatory expectations, manage the document lifecycle (versioning, approvals, reviews), and map all policies and procedures to SAMA CSF controls.
  • Cyber Risk Management: Maintain and update the cybersecurity risk register. Conduct third-party risk assessments (TPRA) and vendor due diligence. Support risk reviews and reporting cycles, and collaborate with Risk and Compliance teams to align enterprise risk frameworks.
  • KPI / KRI Monitoring & Reporting: Collect and validate cybersecurity KPIs/KRIs from relevant stakeholders. Maintain a centralized KPI/KRI tracker, prepare periodic reports with trend analysis to support regulatory maturity (Level 3+), and identify and escalate performance gaps.

Core Competencies and Experience

The ideal candidate will have 2-5 years of experience in cybersecurity GRC. Demonstrated proficiency in maintaining compliance trackers, managing evidence lifecycles, and ensuring audit readiness across frameworks like SAMA CSF, PDPL/NDMO, and PCI-DSS is required. Experience in developing cybersecurity policies, managing risk registers, conducting third-party risk assessments, and reporting on KPIs/KRIs is also essential.

Preferred Qualifications

  • Experience with PDPL and NDMO regulations.
  • PCI-DSS compliance exposure.
  • Knowledge of cloud security (AWS, Azure, GCP, OCI).
  • Experience in fintech or financial services.
  • Familiarity with frameworks like ISO 27001, NIST, COBIT.

Work Location and Type

This is a full-time position based in Riyadh, Ar Riyad. The role operates within a dynamic FinTech environment, contributing to the company's robust cybersecurity posture.


Requirements

  • For Saudis Only
  • Requires 2-5 Years experience

Similar Jobs