img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Tabby | تابي is seeking an Information Security Specialist (GRC) to join their team in Riyadh, Saudi Arabia. This full-time role involves independently executing governance, risk, and compliance activities within Tabby's information security program. The position requires 0-1 years of experience.

Information Security Governance Responsibilities

  • Maintain and update information security governance framework documentation, policy library, and associated standards and procedures.
  • Draft and revise information security policies, standards, and baselines, ensuring alignment with regulatory requirements (SAMA CSF, PDPL, NCA ECC, PCI-DSS) and business objectives.
  • Monitor and track changes in legal, regulatory, and contractual requirements affecting information security, updating the compliance register.
  • Maintain and update role and responsibility matrices (RACI), governance committee documentation, and reporting packs.
  • Coordinate security governance committee meetings, including preparing agendas, minutes, and action tracking.
  • Produce internal and external communication materials related to information security governance, policies, and program updates.

Information Risk Management Responsibilities

  • Execute information security risk assessments independently, applying the organization's methodology and producing complete risk registers.
  • Maintain and update the information asset register, tracking asset owners, classifications, and associated risk profiles.
  • Lead business impact assessment (BIA) data collection activities, coordinating with asset owners and business units.
  • Conduct control effectiveness evaluations for key information security controls, documenting findings and escalating gaps.
  • Coordinate third-party information security risk assessments, preparing questionnaires, reviewing vendor responses, and producing risk summaries.
  • Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes.
  • Prepare periodic risk reports for senior review, highlighting emerging risks and the status of treatment actions.

Compliance and Program Development

  • Monitor the organization's compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS, tracking control status and coordinating remediation.
  • Coordinate internal and external audit activities, gathering evidence, liaising with auditors, and monitoring remediation progress.
  • Support the preparation of regulatory submissions, self-assessments, and compliance attestations required by SAMA, NCA, and PCI Council.
  • Maintain and enhance the security awareness program, developing training materials and tracking completion metrics.
  • Monitor KPIs and KRIs for the information security program, preparing dashboards for senior management review.
  • Support the integration of information security requirements into procurement, project management, and change control processes.

Cross-Functional and General GRC Support

  • Maintain the information security policy, standard, and procedure library, managing version control, review cycles, and distribution.
  • Support information security initiatives across business and technology teams, providing GRC subject matter expertise.
  • Conduct information classification reviews and document security requirements for key business and IT projects.
  • Deliver information security awareness sessions and materials to targeted staff groups.
  • Provide analytical support for GRC team reporting, data gathering, and program tracking activities.

Qualifications and Experience

  • 0-1 years of experience in information security, governance, risk, or compliance.

Requirements

  • No experience required

Similar Jobs