Information Security Specialist

Tabby
Riyadh
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 1-3 yearsEducation: bachelorsSkills: ["Communication","Analytical","Stakeholder coordination"]

Own and maintain Tabby’s information security GRC program by updating the governance framework, policies, and standards, and ensuring alignment with SAMA CSF, PDPL, NCA ECC, ISO 27001, and PCI-DSS. Independently execute risk assessments, manage risk and asset registers, perform control effectiveness evaluations, and support audits and regulatory submissions. Coordinate governance committees, monitor KPIs/KRIs, and provide GRC expertise across business and technology change initiatives.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Tabby
Tabby
1 day ago

Information Security Specialist

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Own and maintain Tabby’s information security GRC program by updating the governance framework, policies, and standards, and ensuring alignment with SAMA CSF, PDPL, NCA ECC, ISO 27001, and PCI-DSS. Independently execute risk assessments, manage risk and asset registers, perform control effectiveness evaluations, and support audits and regulatory submissions. Coordinate governance committees, monitor KPIs/KRIs, and provide GRC expertise across business and technology change initiatives.
Location: Riyadh
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Entry level

Key Responsibilities

  • •Maintain and update the information security governance framework, including the policy library, standards, procedures, and role/responsibility matrices (RACI).
  • •Independently execute information security risk assessments and produce risk registers, including threats, vulnerabilities, likelihood, impact, and treatment plans.
  • •Monitor compliance posture and coordinate audit and regulatory support activities, including evidence gathering and remediation tracking against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS.
  • •Maintain information asset registers, lead business impact assessment (BIA) data collection, and evaluate control effectiveness with escalation of gaps for treatment.
  • •Coordinate security governance committee meetings and prepare governance reporting packs, risk dashboards, and internal/external security governance communications.

Pay and Benefits

Equity and Bonus:Equity
Perks:RelocationEquity

Key Requirements

  • •Bachelor’s degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
  • •1–3 years of experience in information security governance, risk management, compliance, or a closely related field.
  • •Hands-on experience executing risk assessments, policy development, or compliance monitoring.
  • •Strong advantage with prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements.
  • •Preferred certifications: ISO 27001 Foundation or Lead Implementer; CompTIA Security+ or equivalent; working toward CRISC or CISM.
Experience:1-3 yearsFintechBanking
Education:Bachelor's
Skills:CommunicationAnalyticalStakeholder coordination
Certifications:ISO 27001 FoundationISO 27001 Lead ImplementerCompTIA Security+CRISCCISM
Tech Stack:SAMA CSFPDPLNCA ECCPCI-DSSISO 27001RACIRisk registersCRISCCISM

Company Brief

Tabby
Tabby is a MENA buy‑now‑pay‑later and fintech platform that enables customers to split purchases into installments, offers in‑store and online payment products, a consumer app, and merchant services across Saudi Arabia, UAE, Kuwait and the wider region.
Industry: Lending
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Riyadh, Saudi Arabia
Founded: 2019
Glassdoor
Glassdoor: 4.0
WebsiteLinkedInGlassdoor