img
Contract TypeFull-time
Workplace typeOn-site
LocationSaudi Arabia

Job Description

About the Role

Tabby is seeking an Information Security Specialist (GRC) to join its team. This full-time role requires 0-1 years of experience and involves independently executing governance, risk, and compliance activities within Tabby's information security program.

Key Responsibilities

  • Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures.
  • Draft and revise information security policies, standards, and baselines, ensuring alignment with applicable regulatory requirements and business objectives.
  • Monitor and track changes in legal, regulatory, and contractual requirements affecting information security (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating the compliance register accordingly.
  • Maintain and update role and responsibility matrices (RACI), information security governance committee documentation, and reporting packs.
  • Coordinate security governance committee meetings, including preparing agendas, minutes, and action tracking.
  • Produce internal and external communication materials related to information security governance, policies, and program updates.

Information Security Risk Management

  • Execute information security risk assessments independently, applying the organization's risk assessment methodology and producing complete risk registers with identified threats, vulnerabilities, likelihood, impact, and treatment plans.
  • Maintain and update the information asset register, tracking asset owners, classifications, and associated risk profiles.
  • Lead business impact assessment (BIA) data collection activities, coordinating with asset owners and business units to capture accurate recovery objectives and criticality ratings.
  • Conduct control effectiveness evaluations for key information security controls, documenting findings and escalating gaps to the Lead for treatment.
  • Coordinate third-party information security risk assessments, preparing assessment questionnaires, reviewing vendor responses, and producing risk summaries.
  • Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes.
  • Prepare periodic risk reports for senior review, highlighting emerging risks, significant changes in the risk profile, and the status of risk treatment actions.

Experience Required

Candidates should have 0-1 years of experience in a relevant information security role.

Work Type

This is a full-time position.

Application Process

Further details regarding the application process and salary will be disclosed to qualified candidates.


Requirements

  • No experience required

Similar Jobs