img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Moneymoon

Moneymoon is a pioneering Fintech platform focused on transforming short-term microlending through secure, compliant, and seamless peer-to-peer technology. The platform enables individuals to support one another via a one-month lending model built on transparency, safety, and trust. As Moneymoon progresses through the Saudi Central Bank (SAMA) Regulatory Sandbox and prepares for full licensing, strong cybersecurity governance, operational resilience, and regulatory readiness are critical to its operations and scaling.

The Role of Cybersecurity Manager

Moneymoon is seeking a Cybersecurity Manager, acting as a CISO, to manage the cybersecurity function end-to-end and strengthen the company's security posture within the regulated Saudi fintech environment. This full-time, Riyadh-based role requires 2-5 years of experience and combines cybersecurity governance, SAMA regulatory readiness, cyber risk management, security operations, cloud and application security, incident response, resilience, and technical security oversight. The role involves working closely with Technology, Product, Data & AI, Operations, Compliance, Risk, HR, Finance, and senior leadership to embed cybersecurity across all products, infrastructure, systems, processes, and third-party relationships. This position requires operating across both strategy and execution, translating cybersecurity and regulatory requirements into practical controls, measurable improvements, and effective security operations.

Key Responsibilities

  • Own and enhance Moneymoon’s cybersecurity governance framework, policies, procedures, standards, controls, and security improvement plans.
  • Drive readiness and ongoing alignment with the SAMA Cyber Security Framework (SAMA CSF) and other applicable regulatory cybersecurity requirements.
  • Manage the cybersecurity risk management lifecycle, including identification, assessment, treatment, acceptance, escalation, monitoring, and closure.
  • Manage and improve security capabilities across cloud infrastructure, IAM/PAM, endpoints, EDR, email security, networks, applications, APIs, vulnerability management, logging, SIEM, and threat detection.
  • Collaborate with Technology and Data & AI teams to develop practical uses of AI and automation within cybersecurity, and manage security risks associated with Moneymoon’s use of AI and LLMs.
  • Embed cybersecurity requirements throughout the product and technology lifecycle, conducting threat modeling and security reviews for new products and features.
  • Work with relevant teams on technical security controls addressing account takeover, identity abuse, suspicious access behavior, and transaction anomalies.
  • Own the vulnerability management lifecycle and lead cybersecurity incident response across detection, containment, investigation, eradication, recovery, and root-cause analysis.
  • Manage cybersecurity assessments for vendors, technology providers, cloud services, and other critical third parties.
  • Drive cybersecurity awareness and training initiatives across Moneymoon.

Required Qualifications and Experience

  • 3+ years of progressive experience in cybersecurity, security engineering, security operations, information security, cyber risk, or a related function.
  • Strong practical knowledge of the SAMA Cyber Security Framework (SAMA CSF) and experience implementing or maintaining cybersecurity controls.
  • Understanding of the wider Saudi cybersecurity and financial regulatory environment, including MVC, CRFR, CFFR, NCA ECC, PDPL, and ISO/IEC 27001.
  • Demonstrated hands-on cybersecurity capability with experience in security controls, configurations, automation, tooling, or technical improvements.
  • Practical cloud security experience with OCI, AWS, Azure, GCP, or similar production cloud environments.
  • Strong experience in cybersecurity governance and risk management, including risk assessments, risk registers, treatment plans, KPIs, and KRIs.
  • Practical experience across multiple security domains such as IAM/PAM, cloud security, application and API security, vulnerability management, SIEM, detection engineering, incident response, endpoint security, and Secure SDLC.
  • Experience supporting cybersecurity audits, regulatory assessments, control testing, evidence preparation, and remediation activities.
  • Good understanding of cybersecurity incident management, vulnerability remediation, security monitoring, and threat detection.
  • Ability to work effectively with Technology and Engineering teams and communicate cybersecurity risks clearly to business stakeholders and senior management.
  • Strong analytical thinking, problem-solving, ownership, and stakeholder management skills.
  • Strong written and verbal communication skills in English.

Preferred Qualifications

  • Previous experience within fintech, lending, banking, payments, financial services, or another regulated environment.
  • Experience supporting a SAMA assessment, regulatory examination, licensing readiness exercise, or cybersecurity remediation program.
  • Experience with SAMA BCMF, Operational Resilience, PCI DSS, Business Continuity, Disaster Recovery, or Cyber Resilience.
  • Hands-on exposure to fraud detection, transaction monitoring, identity verification, or account-takeover controls.
  • Experience with cybersecurity tooling across SIEM, EDR, MDM, IAM/PAM, vulnerability management, GRC, endpoint protection, cloud security, and security monitoring.
  • Scripting or automation experience using Python, Bash, PowerShell, or similar technologies.
  • Experience building or implementing security automation, detection engineering, AI-enabled security capabilities, or AI/LLM security controls.
  • Previous experience coordinating cybersecurity team members, cross-functional initiatives, security vendors, or managed security service providers.
  • Relevant professional certifications such as CISM, CISSP, CRISC, CCSP, Security+, CySA+, SecurityX, ISO 27001 Lead Implementer/Lead Auditor, GRCP/GRCA, or equivalent.

AI Defense Capability

This role includes designing and building AI-driven detection and response capabilities within Moneymoon’s infrastructure, such as anomaly detection across transaction and access patterns, automated alert triage, automated evidence collection, and agent-assisted incident handling. The Cybersecurity Manager will define the approach and be accountable for effective implementation in production. Additionally, the role involves owning the security of Moneymoon’s use of AI and Large Language Models (LLMs), including protecting against risks such as prompt injection, sensitive data leakage, unauthorized access, insecure integrations, and model abuse.


Requirements

  • Requires 5-10 Years experience

Similar Jobs