Cybersecurity GRC Lead

Job Overview

  • Date Posted
    August 4, 2026
  • Location
  • Expiration date
    November 4, 2026

Job Description

  • Anywhere

Job Description

Job Title: Cybersecurity GRC Lead

Job Description: As Cybersecurity GRC Lead at Saudi Arabia’s first fintech unicorn, you will own the day-to-day governance, risk, and compliance operations underpinning the company’s cyber security program, ensuring the organization meets regulatory expectations, maintains a mature control environment, and continuously improves its security posture across SAMA, NCA, PCI-DSS, and PDPL frameworks.

Responsibilities:

  • Support SAMA inspection readiness end-to-end, including compliance assessments, evidence coordination, gap analysis, and direct support during on-site regulatory visits
  • Lead compliance assessment and alignment activities across SAMA CSF, NCA, PCI-DSS, and PDPL, ensuring timely closure of identified gaps and observations
  • Drive the governance lifecycle for cyber security policies, standards, and procedures, including development, periodic review, version control, and stakeholder approval
  • Maintain compliance mappings, control inventories, and maturity tracking across all in-scope frameworks, ensuring audit-readiness at all times
  • Follow up with first-line technology, engineering, and IT operations teams to ensure timely implementation and remediation of compliance requirements
  • Coordinate and respond to regulatory initiatives, requests, and ad-hoc inquiries from regulators including SAMA, NCA, and payment scheme bodies
  • Prepare and present cyber security governance and compliance status updates for the Cyber Security Committee and internal governance forums
  • Utilize and maintain the company’s GRC platform to manage compliance workflows, control assessments, policy repositories, and audit evidence

Qualifications Needed:

  • 4–6 years of experience in Cyber Security GRC, Technology Risk, IT Governance, IT Audit, or a related field within financial services, fintech, or banking
  • Demonstrated experience with SAMA CSF (required) and NCA (preferred); experience with PCI-DSS and/or PDPL is a strong advantage
  • Solid understanding of cyber security governance principles, policy lifecycle management, and control assessment methodologies
  • Experience conducting or supporting regulatory inspections, compliance assessments, and maturity evaluations
  • Proven ability to manage compliance remediation programs and track findings to closure across multiple stakeholders
  • Strong documentation and reporting skills for both technical and executive audiences

What the Company Offers:

  • Cybersecurity GRC Lead role owning regulatory compliance operations at Saudi Arabia’s first fintech unicorn, headquartered in Riyadh
  • Direct engagement with regulators including SAMA and NCA as the primary coordination point between Cyber Security and business stakeholders
  • Opportunity to advance the maturity of a cyber security governance program at a fintech serving millions of users across the GCC

Are you interested in this position? Apply by clicking on the “Apply Now” button below!

#LibertyloomJobs #FintechCareers #JobOpportunities #FinanceJobs #TechTalent #FintechRecruitment #CareerInFinance#

To apply for this job email your details to info@libertyloomtalent.com