Information Security Specialist
About the role
We're looking for an Information Security Specialist (GRC) to join Tabby! The successful candidate will independently execute governance, risk, and compliance activities across the Tabby's information security programme.
Responsibilities
Information Security Governance
- Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures.
- Draft and revise information security policies, standards, and baselines, ensuring alignment with applicable regulatory
requirements
and business objectives.
- Monitor and track changes in legal, regulatory, and contractual
requirements
affecting information security (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating the compliance register accordingly.
- Maintain and update role and responsibility matrices (RACI), information security governance committee documentation, and reporting packs.
- Coordinate security governance committee meetings - preparing agendas, minutes, and action tracking.
- Produce internal and external communication materials related to information security governance, policies, and programme updates.
Information Risk Management
- Execute information security risk assessments independently, applying the organization's risk assessment methodology and producing complete risk registers with identified threats, vulnerabilities, likelihood, impact, and treatment plans.
- Maintain and update the information asset register - tracking asset owners, classifications, and associated risk profiles.
- Lead business impact assessment (BIA) data collection activities, coordinating with asset owners and business units to capture accurate recovery objectives and criticality ratings.
- Conduct control effectiveness evaluations for key information security controls, documenting findings and escalating gaps to the Lead for treatment.
- Coordinate third-party information security risk assessments - preparing assessment questionnaires, reviewing vendor responses, and producing risk summaries.
- Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes.
- Prepare periodic risk reports for senior review, highlighting emerging risks, significant changes in the risk profile, and the status o…
Requirements
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
- 1-3 years of professional experience in information security governance, risk management, compliance, or a closely related field. Hands-on experience with risk assessment execution, policy development, or compliance monitoring is required. Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC
requirements
is a strong advantage. Experience in a regulated Fintech or banking environment is preferred.
- ISO 27001 Foundation or Lead Implementer (preferred). CompTIA Security+ or equivalent.
- Working toward CRISC (Certified in Risk and Information Systems Control) or CISM.
Benefits & compensation
- We are an international Team of inspired professionals located all over the globe.
- We have an inclusive company culture, embracing diversity, integrity and transparency. We strive for work-life balance and cherish the moments you spend with your loved ones, off-work. In the same spirit as for our product, we are caring and nurturing for our employees.
- Our people are granted 100% trust and freedom to apply their own vision and come up with their ideas from day 1 at Tabby. You are the one who takes responsibility for your area of work. We encourage everyone to think and make decisions like Tabby was their own business, well because it is. Our employee stock options programme is available for everyone.
- You will have an opportunity to learn and grow in one of the fastest growing fin tech companies in the region
- We offer you relocation support as well as we guide you through all the process.
- We'll set you up with the devices required for your work.