Cybersecurity GRC Lead

Tamara UAE
Riyadh
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Documentation","Reporting","Stakeholder coordination","Ownership","Independent execution"]

Own Tamara’s cybersecurity governance, risk, and compliance (GRC) operations, ensuring regulatory expectations are met and the control environment matures continuously. Lead end-to-end regulatory compliance activities including SAMA inspections, NCA assessments, PCI-DSS compliance, and PDPL alignment. Manage the policy and control governance lifecycle, track remediation to closure, coordinate with first-line stakeholders, and report GRC KPIs to governance forums.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Tamara UAE
Tamara UAE
2 weeks ago

Cybersecurity GRC Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Own Tamara’s cybersecurity governance, risk, and compliance (GRC) operations, ensuring regulatory expectations are met and the control environment matures continuously. Lead end-to-end regulatory compliance activities including SAMA inspections, NCA assessments, PCI-DSS compliance, and PDPL alignment. Manage the policy and control governance lifecycle, track remediation to closure, coordinate with first-line stakeholders, and report GRC KPIs to governance forums.
Location: Riyadh
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Support SAMA inspection readiness end-to-end, including compliance assessments, evidence coordination, gap analysis, and on-site regulatory support.
  • •Lead compliance assessment and alignment across SAMA CSF, NCA, PCI-DSS, and PDPL to ensure timely closure of gaps and observations.
  • •Drive the cybersecurity policy governance lifecycle (development, review, version control, approvals, and communication) and maintain compliance mappings and control inventories.
  • •Follow up with first-line teams (Technology, Engineering, IT Ops) and business stakeholders to remediate compliance requirements and control gaps.
  • •Produce GRC dashboards, metrics, and KPI reporting; coordinate regulatory initiatives and respond to ad-hoc regulator inquiries; support audit evidence collection and follow-up to closure.

Key Requirements

  • •4–6 years of experience in cybersecurity GRC, technology risk, IT governance, IT audit, or a related field in financial services, fintech, or banking.
  • •Demonstrated regulatory compliance experience, particularly SAMA CSF (required) and NCA (preferred), with PCI-DSS and/or PDPL as an advantage.
  • •Solid understanding of cybersecurity governance principles, policy lifecycle management, and control assessment methodologies.
  • •Experience conducting or supporting regulatory inspections, compliance assessments, and maturity evaluations.
  • •Proven ability to manage compliance remediation programs, track findings to closure, and coordinate across multiple stakeholders.
Experience:FintechFinancial servicesBanking
Skills:DocumentationReportingStakeholder coordinationOwnershipIndependent execution
Languages:English
Tech Stack:GRCGRC platformPolicy repositoriesPCI-DSSSAMA CSFNCAPDPL

Company Brief

Tamara UAE
Provides buy now, pay later and consumer financing services for shoppers and merchants across the Middle East. The platform lets customers split purchases into installments while helping businesses increase conversion and average order value.
Industry: Lending
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: Riyadh, Saudi Arabia
Founded: 2020
WebsiteLinkedIn