Apply Edge Start your job search

Chief Information Security Officer

فلووس | Flooss · Riyadh, Saudi Arabia

Apply & track with Apply Edge

About FloossAL-AN Alkhaligia for Consumer Microfinance Company (Flooss) provides consumer microfinance solutions in Saudi Arabia and operates in the regulated financial sector under the supervision of the Saudi Central Bank (SAMA).We are building a customer-focused, technology-enabled, and well-governed organization, and we are looking for leaders who will help shape its next stage of growth.Role PurposeLead the Company's independent Cybersecurity function and protect the Company's information assets, customer data, and digital services against cyber threats, while ensuring full compliance with SAMA and other applicable regulatory requirements.The CISO will own the cybersecurity strategy, governance framework, risk management, and security operations, and will partner closely with the IT Manager, Risk, Compliance, and executive management to embed security across the business.Key Responsibilities1. Cybersecurity Strategy & GovernanceDefine and execute the cybersecurity strategy and roadmap in alignment with the Company's business strategy and risk appetite.Establish and maintain the cybersecurity governance framework, policies, standards, and procedures.Prepare and manage the cybersecurity budget and investment priorities.Chair or support the Cybersecurity Steering Committee and report cybersecurity posture, risks, and key metrics to executive management, the Board, and relevant committees.Maintain the independence of the Cybersecurity function from IT operations, in line with SAMA requirements.2. Cyber Risk & Regulatory ComplianceEnsure compliance with the SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, and other applicable regulations and standards.Identify, assess, and manage cybersecurity risks across systems, processes, projects, and third parties.Conduct periodic cybersecurity maturity self-assessments and drive remediation plans.Lead the cybersecurity aspects of regulatory examinations and internal and external audits, and ensure timely closure of findings.Monitor regulatory developments and update the Company's cybersecurity controls accordingly.3. Security Operations & Incident ResponseOversee security monitoring and threat detection, whether through an in-house or outsourced Security Operations Center (SOC).Lead cyber incident response, investigation, and reporting to SAMA and other authorities within required timelines.Manage vulnerability management, penetration testing, and threat intelligence programs.Ensure cyber resilience is integrated into Business Continuity and Disaster Recovery plans and tested regularly.Oversee identity and access management, including privileged access controls.4. Security Architecture & Data ProtectionDefine security architecture standards and ensure secure-by-design principles across infrastructure, cloud, applications, APIs, and digital channels.Review and approve the security of new systems, integrations, changes, and technology projects before go-live.Lead data protection controls in coordination with the Data Protection Officer, in line with the Personal Data Protection Law (PDPL).Oversee application security, including secure development practices and security testing of mobile and web channels.Ensure controls are in place to prevent fraud and protect customer data and transactions.5. Third Parties, Awareness & People ManagementAssess and monitor the cybersecurity posture of vendors and outsourcing arrangements, in line with SAMA outsourcing requirements.Define cybersecurity requirements in contracts and service level agreements with third parties.Lead cybersecurity awareness and training programs for employees, management, and the Board.Lead, coach, and develop the cybersecurity team.Build succession plans and develop national cybersecurity talent.Qualifications & ExperienceEducationBachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.Master's degree in Cybersecurity, Information Security, or an MBA is preferred.ExperienceMinimum 10 years of experience in cybersecurity or information security.At least 5 years in a cybersecurity leadership role.Experience in financial services, fintech, or consumer finance is required.Proven experience leading a cybersecurity function within a SAMA-regulated entity is preferred.Professional CertificationsCISSP, CISM, or equivalent senior cybersecurity certification is required.CISA, CRISC, ISO 27001 Lead Implementer/Auditor, and relevant cloud security certifications (e.g., CCSP) are an advantage.Technical SkillsStrong knowledge and practical experience in:Cybersecurity governance, risk, and compliance (GRC)Security operations, SOC, and incident responseCloud, network, and application securityIdentity and access management (IAM/PAM)API and digital channel securityVulnerability management and penetration testingData protection and data loss preventionThird-party cybersecurity risk managementCyber resilience, Business Continuity, and Disaster RecoveryRegulatory & Compliance KnowledgeIn-depth knowledge of the SAMA Cyber Security Framework and SAMA outsourcing requirements.Knowledge of NCA cybersecurity controls and the Personal Data Protection Law (PDPL).Familiarity with international standards such as ISO 27001, NIST, and PCI DSS.Experience leading regulatory examinations and audits.LanguagesFluent in Arabic and English.NationalitySaudi national