Cybersecurity GRC Lead
Job Overview
-
Date PostedAugust 4, 2026
-
Location
-
Expiration dateNovember 4, 2026
Job Description
Job Description
Job Title: Cybersecurity GRC Lead
Job Description: As Cybersecurity GRC Lead at Saudi Arabia’s first fintech unicorn, you will own the day-to-day governance, risk, and compliance operations underpinning the company’s cyber security program, ensuring the organization meets regulatory expectations, maintains a mature control environment, and continuously improves its security posture across SAMA, NCA, PCI-DSS, and PDPL frameworks.
Responsibilities:
- Support SAMA inspection readiness end-to-end, including compliance assessments, evidence coordination, gap analysis, and direct support during on-site regulatory visits
- Lead compliance assessment and alignment activities across SAMA CSF, NCA, PCI-DSS, and PDPL, ensuring timely closure of identified gaps and observations
- Drive the governance lifecycle for cyber security policies, standards, and procedures, including development, periodic review, version control, and stakeholder approval
- Maintain compliance mappings, control inventories, and maturity tracking across all in-scope frameworks, ensuring audit-readiness at all times
- Follow up with first-line technology, engineering, and IT operations teams to ensure timely implementation and remediation of compliance requirements
- Coordinate and respond to regulatory initiatives, requests, and ad-hoc inquiries from regulators including SAMA, NCA, and payment scheme bodies
- Prepare and present cyber security governance and compliance status updates for the Cyber Security Committee and internal governance forums
- Utilize and maintain the company’s GRC platform to manage compliance workflows, control assessments, policy repositories, and audit evidence
Qualifications Needed:
- 4–6 years of experience in Cyber Security GRC, Technology Risk, IT Governance, IT Audit, or a related field within financial services, fintech, or banking
- Demonstrated experience with SAMA CSF (required) and NCA (preferred); experience with PCI-DSS and/or PDPL is a strong advantage
- Solid understanding of cyber security governance principles, policy lifecycle management, and control assessment methodologies
- Experience conducting or supporting regulatory inspections, compliance assessments, and maturity evaluations
- Proven ability to manage compliance remediation programs and track findings to closure across multiple stakeholders
- Strong documentation and reporting skills for both technical and executive audiences
What the Company Offers:
- Cybersecurity GRC Lead role owning regulatory compliance operations at Saudi Arabia’s first fintech unicorn, headquartered in Riyadh
- Direct engagement with regulators including SAMA and NCA as the primary coordination point between Cyber Security and business stakeholders
- Opportunity to advance the maturity of a cyber security governance program at a fintech serving millions of users across the GCC
Are you interested in this position? Apply by clicking on the “Apply Now” button below!
#LibertyloomJobs #FintechCareers #JobOpportunities #FinanceJobs #TechTalent #FintechRecruitment #CareerInFinance#
To apply for this job email your details to info@libertyloomtalent.com