Cybersecurity GRC Lead
Tamara
About us
Tamara is the leading fintech platform in Saudi Arabia and the wider GCC region with a mission to help people make their dreams come true by building the most customer-centric financial super-app on earth. The company serves millions of users in the region and partners with leading global and regional brands such as SHEIN, Jarir, noon, IKEA and Amazon, as well as small and medium businesses.
Tamara is Saudi’s first fintech unicorn and is backed by Sanabil Investments, SNB Capital, Checkout.com, amongst others, operating out of its headquarters in Riyadh, Saudi Arabia with other regional and global support offices.
Your role
Tamara is seeking a Cyber Security specialist / lead to join our Cyber Security team. In this role, you will own the day-to-day governance, risk, and compliance operations that underpin Tamara’s cyber security program, ensuring the organization meets regulatory expectations, maintains a mature control environment, and continuously improves its security posture.
You will be responsible for end-to-end regulatory compliance activities — including SAMA inspections, NCA assessments, PCI-DSS compliance, and PDPL alignment — as well as the governance lifecycle of cyber security policies, standards, and procedures. You will drive internal follow-ups to remediate identified maturity gaps and observations, and serve as the primary point of coordination between the Cyber Security team and first-line technology, engineering, and business stakeholders on compliance matters.
As an experienced individual contributor, you are expected to operate independently, take ownership of GRC deliverables, and lead initiatives that advance the maturity of Tamara’s cyber security governance and compliance program.
Your responsibilities
- Support in SAMA inspection readiness (end-to-end), including compliance assessments, evidence coordination, gap analysis, and direct support during on-site regulatory visits.
- Lead compliance assessment and alignment activities across applicable regulatory frameworks, including SAMA CSF, NCA, PCI-DSS, and PDPL, ensuring timely closure of identified gaps and observations.
- Drive the governance lifecycle for cyber security policies, standards, and procedures including development, periodic review, version control, stakeholder approval, and communication to Tamarians.
- Maintain and manage compliance mappings, control inventories, and maturity tracking across all in-scope frameworks, ensuring accuracy and audit-readiness at all times.
- Follow up with first-line teams ( Technology, Engineering, IT Ops ) and relevant business stakeholders to ensure timely implementation and remediation of compliance requirements and control gaps.
- Coordinate and respond to regulatory initiatives, requests, and ad-hoc inquiries from regulators such as SAMA, NCA, and relevant payment scheme bodies.
- Prepare and present cyber security governance, compliance status, and maturity updates for the Cyber Security Committee and other internal governance forums.
- Produce GRC-related dashboards, metrics, and KPI reporting for leadership visibility on compliance posture, policy health, and remediation progress.
- Collaborate with Enterprise Risk and Compliance teams on cross-functional risk and compliance matters, including contributing to vendor risk assessment reviews from a cyber security perspective.
- Utilize and maintain the Tamara’s GRC platform to manage compliance workflows, control assessments, policy repositories, and audit evidence.
- Support audit activities by coordinating evidence collection, tracking findings, and following up on remediation and mitigation actions to closure.
- Stay current on regulatory updates, emerging cyber security risks, and industry best practices relevant to fintech and financial services in the GCC region.
Your expertise
- 4–6 years of experience in Cyber Security GRC, Technology Risk, IT Governance, IT Audit, or a related field within financial services, fintech, or banking.
- Demonstrated experience with regulatory compliance frameworks, particularly SAMA CSF (required) and NCA (preferred). Experience with PCI-DSS and/or PDPL is a strong advantage.
- Solid understanding of cyber security governance principles, policy lifecycle management, and control assessment methodologies.
- Experience conducting or supporting regulatory inspections, compliance assessments, and maturity evaluations.
- Proven ability to manage compliance remediation programs, track findings to closure, and coordinate across multiple stakeholders.
- Strong documentation and reporting skills, with the ability to produce clear, structured deliverables for both technical and executive audiences.
- Experience working with GRC platforms and tools for compliance management, policy governance, and audit tracking are a plus.
- ...Job Description – ServiceNow GRC SME (5+ Years Experience) Job Location: Riyadh - KSA We are looking for an experienced ServiceNow... ...and governance frameworks, including: NCA Essential Cybersecurity Controls (ECC) NCA Cloud Cybersecurity Controls (CCC) Saudi...
- ...consulting and technology services firm specializing in cybersecurity, IAM, cloud, AI-driven platforms, and custom... ...meet growth and renewal targets Lead consultative selling across cybersecurity services (GRC, SOC/MDR, IR, security assessments) and solutions...
- ...About ExeQut ExeQut is an IT consulting, cybersecurity, and digital transformation firm headquartered in Lanham, MD, with delivery operations... ...Saudi cybersecurity regulations, and experience working with leading cybersecurity vendors and enterprise customers. What...
- ...Description WE ARE HIRING – Cybersecurity Architect Work Location: Dhahran, Saudi Arabia Preferred Nationality: Saudi / Expat Experience: 10+ Years Education: Bachelor's in Computer Science (Master's Preferred) Key Responsibilities Enterprise Cybersecurity...
- ...Who Are We HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future... ...licensed by the Saudi Arabian Central Bank. Role Summary The Cybersecurity Offense Specialist is primarily responsible for executing the...
- ...ServiceNow GRC Consultant We are looking for an experienced ServiceNow GRC SME with strong expertise in , information security, risk, compliance, SecOps operation and audit management . Key Requirements Must possess relevant certifications such as ISO 2700...
- * Please note Only candidates matching JD will be shorlisted* Engagement: ServiceNow GRC & SecOps Implementation Modules in Scope: IRM (Policy, Compliance, Risk Management, TPRM), BCM, SecOps (SIR, VR, TI) Regulatory Scope: SAMA Banking Frameworks ITGF/CFF/CSF etc...
- Information Security GRC Process Consultant, Auditor Region: Riyadh Hiring: information security GRC Process Consultant / Auditor... ...Experience and Expertise- Strong experience in: SAMA CSF NCA cybersecurity regulations SWIFT CTI (Cyber Threat Intelligence) Key...
- ...Lead Specialist, Cybersecurity Architect II Job Info Job Identification 8373 Job Category Lead Specialist Posting Date 07/06/2026, 08:33 AM Locations Riyadh, Riyadh, 11537, SA Apply Before 07/30/2026, 09:00 PM Job Schedule Full time Job Description...
- A leading cybersecurity firm in Riyadh is seeking a Cybersecurity Analyst to develop and maintain cybersecurity policies, assess risks, and ensure... ...3-5 years of experience in Governance, Risk, and Compliance (GRC), and fluency in English and Arabic. This role offers an...
- ...Job Title: Cybersecurity Analyst Location: Riyadh, KSA (incumbent must be willing to travel within KSA.) (on-site) Mandatory Requirement: Saudi National Job type: Full Time Job Summary Our client is looking for Cybersecurity Analyst responsible for...
- ...Job Summary We are seeking a dynamic and results-driven Sales Consultant to join our Cybersecurity team. The Sales Consultant in Cybersecurity is responsible for driving revenue growth by identifying, developing, and closing sales opportunities for cybersecurity solutions...
- ...Job summary Responsible for designing, implementing, and maintaining the organization’s cybersecurity infrastructure and controls to protect information assets, systems, and networks from cyber threats. This role delivers proactive threat detection, incident response...
- ...Maaden Saudi Arabian Mining Company is seeking a Lead Specialist, Cybersecurity Architect II to define and manage enterprise cybersecurity architecture across Maaden Corporate and business units in multiple regions. The role ensures security controls, standards, and architecture...
- ...As part of our Cyber Technology Consulting practice, you will lead the delivery of AI Governance, AI Risk Management, Responsible... ...Compliance NIST AI RMF ISO/IEC 42001 ISO 27001 NIST Cybersecurity Framework GDPR EU AI Act PDPL SAMA-related...
- ...Managed Services is looking for an entry-level Cybersecurity Engineer in the Riyadh Region, Saudi Arabia. The role offers opportunities across Governance, Risk & Compliance, Penetration Testing, and SOC activities. Ideal for recent graduates, this position will allow you...
- ...for services and Eviden for products. European number one in cybersecurity, cloud and high performance computing, Atos Group is committed... ...Solution Architect is a critical, high-impact role responsible for leading and shaping technology and transformation initiatives for Atos...
- A leading cybersecurity firm located in the Riyadh Region seeks a motivated Cybersecurity Engineer. This entry-level position offers opportunities in Governance, Risk & Compliance, Penetration Testing, and Security Operations Center. The ideal candidate will hold a Bachelor...
- ...Lead Functional Consultant Job Location : Riyadh - KSA Experience: 5+ Years Implement/Standardize/Optimize Risk, Policy and... ...by multiple service providers Designing and implementing the GRC solution using industry best practices. Experience in risk, compliance...
- ...TAWANTECH in Riyadh, Saudi Arabia, is seeking an experienced cybersecurity production support professional to manage Splunk (SIEM), SOAR, and VPN infrastructure, ensuring high availability and reliable service. You will monitor security platforms and alerts, perform root...
- A leading technology solutions firm in Riyadh is seeking an experienced sales professional to own a high-growth territory in networking and cybersecurity. The successful candidate will generate and close opportunities across mid-market and enterprise accounts, collaborating...
- ...Rawaj HCM Jobs is looking for an IT Manager to lead our IT operations within a prominent Saudi Insurance firm. You will manage IT infrastructure, applications, and cybersecurity initiatives while transforming digital capabilities to support business objectives. Ideal...
- ...Qiddiya Investment Company in Riyadh is seeking a Senior Manager - Cybersecurity Security Architecture to lead the development and implementation of a comprehensive cybersecurity framework. You will be pivotal in ensuring that security measures support organizational growth...
- ...SPIMACO invites a seasoned Cybersecurity Senior Supervisor to lead complex security programs in Riyadh. You will supervise teams, oversee incidents, and ensure compliance with standards while aligning with strategic goals. The ideal candidate has at least 7 years of...
- ...Job Summary: We are seeking a motivated and detail-oriented Cybersecurity Engineer to join our growing security team. This entry-level role... ...in various domains including Governance, Risk & Compliance (GRC), Penetration Testing, and Security Operations Center (SOC) activities...
- ...and we are interested to bring more talented individuals into our team. Key Responsibilities: Governance, Risk, and Compliance (GRC) framework design and implementation* aligned with international standards (ISO 27001, NIST CSF) and Saudi regulations (NESA, CISO...
- ...onboarding process. Role Summary Develops, updates and maintains cybersecurity policies to support and align with an organization’s... ...Security or related field. Experience: 3-5 years of experience in GRC. Language: Very Good English and Arabic. Skills,...
- A leading online grocery service in Riyadh is seeking a highly skilled Cybersecurity Products Manager to lead the development and management of its cybersecurity product portfolio. The ideal candidate will innovate and ensure product security compliance while aligning...
- ...SENSYS Inc. is seeking a Senior Sales Manager in Riyadh to lead sales cycles for Digital Solutions and OT Cybersecurity. You'll engage with high-value accounts, driving transformation across industries like Oil & Gas and Manufacturing. With responsibilities that include...
- ...Job Title – Operations Lead Location: Riyadh, Saudi Arabia About the Role We are seeking an experienced and proactive Operations Lead to oversee day-to-day operational activities, drive business performance, and ensure consistent service excellence across...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity GRC Lead. Be the first to apply!

