img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Tabby is seeking a Lead Anti-Fraud Officer to join their team in Riyadh, Saudi Arabia. This full-time role involves independently leading complex governance, risk, and compliance activities, serving as a subject matter expert in areas such as enterprise information security governance, risk management frameworks, regulatory compliance, or third-party risk management. The Lead Anti-Fraud Officer will produce high-quality GRC deliverables, mentor junior and mid-level team members, and contribute to the continuous improvement of the organization's GRC framework, risk treatment processes, and compliance reporting mechanisms. This position requires 2-5 years of relevant experience.

Key Responsibilities

  • Lead the development, review, and continuous improvement of information security policies, standards, procedures, and governance frameworks.
  • Serve as the subject matter expert for assigned regulatory domains, interpreting requirements and translating them into implementable control objectives.
  • Monitor and track regulatory and legal developments affecting information security, assessing impact and recommending updates to the governance framework.
  • Prepare and review governance documentation, including RACI matrices, security charter updates, and governance committee packs, presenting findings to senior stakeholders.
  • Lead the preparation of regulatory self-assessments and compliance attestations, coordinating evidence gathering and quality-reviewing submissions.
  • Mentor GR1–GR2 team members on governance documentation quality, regulatory interpretation, and risk assessment methodology.

Enterprise Risk Management

  • Lead complex enterprise information security risk assessments, applying advanced methodologies to produce risk profiles aligned with the organization's risk appetite.
  • Own and maintain the enterprise information security risk register, ensuring accuracy, currency, and appropriate escalation of significant risks.
  • Lead Business Impact Analysis (BIA) processes for critical business functions, coordinating with asset owners and analyzing recovery requirements.
  • Design and execute control effectiveness testing programmes, producing findings reports with gap analysis and risk-ranked remediation recommendations.
  • Lead third-party information security risk management, designing assessment frameworks, conducting vendor reviews, and maintaining the third-party risk register.
  • Produce executive-quality risk reporting with trend analysis, emerging risk identification, and treatment progress tracking.

Compliance Programme Delivery

  • Lead compliance monitoring activities for CFFR, NCA ECC, PDPL, ISO 27001, and PCI-DSS, producing gap analyses, treatment plans, and periodic compliance status reports.
  • Manage internal and external audit cycles, coordinating evidence collection, reviewing evidence quality, engaging with auditors, and tracking remediation.
  • Design and deliver the security awareness programme, producing targeted content, conducting awareness sessions, and analyzing effectiveness metrics.
  • Develop and maintain GRC programme metrics dashboards, ensuring KPIs and KRIs are accurately measured and presented.
  • Lead the integration of information security requirements into third-party contracts, procurement processes, and major project onboarding.
  • Contribute to the development of the information security programme strategy, identifying capability improvement opportunities and recommending investment priorities.

Cross-Functional Collaboration and Knowledge Leadership

  • Serve as the primary GRC point of contact for assigned business and technology teams, providing expert guidance on security requirements, risk treatment, and compliance obligations.
  • Lead information classification and security requirements reviews for significant IT, product, and business projects.
  • Contribute to the GRC knowledge base by developing reusable templates, guidance documents, and training materials.
  • Represent the GRC function in cross-functional working groups, project steering committees, and regulatory workstreams.
  • Perform additional responsibilities as assigned by management.

Experience Required

Candidates should possess 2-5 years of experience in a relevant field, demonstrating expertise in governance, risk, and compliance activities within a regulatory environment, preferably within Fintech in Saudi Arabia.


Requirements

  • Requires 5-10 Years experience

Similar Jobs