Technology Risk GRC Lead
Tamara
Date: 15 hours ago
City: Riyadh
Contract type: Full time
About Us
Tamara is the leading fintech platform in Saudi Arabia and the wider GCC region with a mission to help people make their dreams come true by building the most customer-centric financial super-app on earth. The company serves millions of users in the region and partners with leading global and regional brands such as SHEIN, Jarir, noon, IKEA and Amazon, as well as small and medium businesses.
Tamara is Saudi’s first fintech unicorn and is backed by Sanabil Investments, SNB Capital, Checkout.com, amongst others, operating out of its headquarters in Riyadh, Saudi Arabia with other regional and global support offices.
Your role
Tamara is seeking a Cyber Security specialist / lead to join our Cyber Security team. In this role, you will own the day-to-day governance, risk, and compliance operations that underpin Tamara’s cyber security program, ensuring the organization meets regulatory expectations, maintains a mature control environment, and continuously improves its security posture.
You will be responsible for end-to-end regulatory compliance activities — including SAMA inspections, NCA assessments, PCI-DSS compliance, and PDPL alignment — as well as the governance lifecycle of cyber security policies, standards, and procedures. You will drive internal follow-ups to remediate identified maturity gaps and observations, and serve as the primary point of coordination between the Cyber Security team and first-line technology, engineering, and business stakeholders on compliance matters.
As an experienced individual contributor, you are expected to operate independently, take ownership of GRC deliverables, and lead initiatives that advance the maturity of Tamara’s cyber security governance and compliance program.
Your responsibilities
Tamara is the leading fintech platform in Saudi Arabia and the wider GCC region with a mission to help people make their dreams come true by building the most customer-centric financial super-app on earth. The company serves millions of users in the region and partners with leading global and regional brands such as SHEIN, Jarir, noon, IKEA and Amazon, as well as small and medium businesses.
Tamara is Saudi’s first fintech unicorn and is backed by Sanabil Investments, SNB Capital, Checkout.com, amongst others, operating out of its headquarters in Riyadh, Saudi Arabia with other regional and global support offices.
Your role
Tamara is seeking a Cyber Security specialist / lead to join our Cyber Security team. In this role, you will own the day-to-day governance, risk, and compliance operations that underpin Tamara’s cyber security program, ensuring the organization meets regulatory expectations, maintains a mature control environment, and continuously improves its security posture.
You will be responsible for end-to-end regulatory compliance activities — including SAMA inspections, NCA assessments, PCI-DSS compliance, and PDPL alignment — as well as the governance lifecycle of cyber security policies, standards, and procedures. You will drive internal follow-ups to remediate identified maturity gaps and observations, and serve as the primary point of coordination between the Cyber Security team and first-line technology, engineering, and business stakeholders on compliance matters.
As an experienced individual contributor, you are expected to operate independently, take ownership of GRC deliverables, and lead initiatives that advance the maturity of Tamara’s cyber security governance and compliance program.
Your responsibilities
- Support in SAMA inspection readiness (end-to-end), including compliance assessments, evidence coordination, gap analysis, and direct support during on-site regulatory visits.
- Lead compliance assessment and alignment activities across applicable regulatory frameworks, including SAMA CSF, NCA, PCI-DSS, and PDPL, ensuring timely closure of identified gaps and observations.
- Drive the governance lifecycle for cyber security policies, standards, and procedures including development, periodic review, version control, stakeholder approval, and communication to Tamarians.
- Maintain and manage compliance mappings, control inventories, and maturity tracking across all in-scope frameworks, ensuring accuracy and audit-readiness at all times.
- Follow up with first-line teams (Technology, Engineering, IT Ops) and relevant business stakeholders to ensure timely implementation and remediation of compliance requirements and control gaps.
- Coordinate and respond to regulatory initiatives, requests, and ad-hoc inquiries from regulators such as SAMA, NCA, and relevant payment scheme bodies.
- Prepare and present cyber security governance, compliance status, and maturity updates for the Cyber Security Committee and other internal governance forums.
- Produce GRC-related dashboards, metrics, and KPI reporting for leadership visibility on compliance posture, policy health, and remediation progress.
- Collaborate with Enterprise Risk and Compliance teams on cross-functional risk and compliance matters, including contributing to vendor risk assessment reviews from a cyber security perspective.
- Utilize and maintain the Tamara’s GRC platform to manage compliance workflows, control assessments, policy repositories, and audit evidence.
- Support audit activities by coordinating evidence collection, tracking findings, and following up on remediation and mitigation actions to closure.
- Stay current on regulatory updates, emerging cyber security risks, and industry best practices relevant to fintech and financial services in the GCC region.
- 4–6 years of experience in Cyber Security GRC, Technology Risk, IT Governance, IT Audit, or a related field within financial services, fintech, or banking.
- Demonstrated experience with regulatory compliance frameworks, particularly SAMA CSF (required) and NCA (preferred). Experience with PCI-DSS and/or PDPL is a strong advantage.
- Solid understanding of cyber security governance principles, policy lifecycle management, and control assessment methodologies.
- Experience conducting or supporting regulatory inspections, compliance assessments, and maturity evaluations.
- Proven ability to manage compliance remediation programs, track findings to closure, and coordinate across multiple stakeholders.
- Strong documentation and reporting skills, with the ability to produce clear, structured deliverables for both technical and executive audiences.
- Experience working with GRC platforms and tools for compliance management, policy governance, and audit tracking are a plus.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Senior Project Manager Job
Elm Company,
Riyadh
17 hours ago
OverviewJob Description Job TitleSenior Project ManagerJob Code599613GradeI3GroupCorporate Planning & EnablementDivisionCorporate TechnologyDepartmentCorporate Digital SystemsUnitDelivery & SupportROLE PURPOSEThe aim is to state the overall significance of the job from the organization’s perspective.The role exists to manage technology projects and delivery initiatives by planning, coordinating, and monitoring project activities throughout the project lifecycle. The role ensures successful delivery of technology solutions by coordinating...
Domain Support Specialist
Ericsson,
Riyadh
3 days ago
About this opportunity:This Job Role is responsible for the coordination, management and execution of proactive and reactive maintenance activities that require a higher level of support and for implementations of the change request in a timely and correct manner, by focusing on the allocation, implementation, configuration, activation and testing of specific services or resources.What you will do:General ResponsibilitiesEnsure that the...
Investor Responsibility & Engagement Analyst - Saudi Arabia
Fisher Investments,
Riyadh
4 days ago
OverviewThe Opportunity:The Investor Responsibility & Engagement Analyst is part of the Responsible Investment (RI) team. The Analyst is the local RI subject matter expert and also supports various institutional sales and service-related activities. The Analyst conducts corporate engagement on environmental, social and governance (ESG) issues. In addition, the Analyst serves as a resource to relationship managers and, as requested, attends...