Apply Edge Start your job search

Cyber Security Specialist / Senior Specialist

The Lending Hub SA · Riyadh, Saudi Arabia

Apply & track with Apply Edge
About the RoleWe are seeking a proactive and experienced Cybersecurity Specialist to lead the company’s cybersecurity function and ensure the protection of its information assets, cloud infrastructure, and digital services.The role is responsible for implementing and maintaining a robust cybersecurity program aligned with the Saudi Central Bank (SAMA) Cyber Security Framework (CSF), National Cybersecurity Authority (NCA) requirements, and industry best practices.The Specialist will oversee cybersecurity governance, risk management, compliance, threat monitoring, incident response, and security awareness initiatives while working closely with senior management to strengthen the organization’s cybersecurity posture.Key ResponsibilitiesCybersecurity Strategy & Governance* Develop, implement, and maintain the company’s cybersecurity policies, standards, and procedures.* Ensure cybersecurity governance aligns with SAMA CSF, NCA regulations, and industry best practices.* Establish cybersecurity architecture principles and ensure security requirements are integrated into technology solutions.* Monitor cybersecurity KPIs and KRIs and provide regular reports to senior management.* Support the continuous improvement of the company’s cybersecurity program.Cybersecurity Risk Management* Conduct cybersecurity risk assessments and oversee the implementation of mitigation plans.* Maintain the cybersecurity risk management framework and risk register.* Perform information and system classification to ensure appropriate protection of critical assets.* Support security reviews for new systems, applications, and projects.Security Operations & Incident Management* Oversee vulnerability management, security monitoring, and incident response activities.* Coordinate cybersecurity incident investigations and ensure timely reporting and remediation.* Monitor emerging cyber threats and recommend appropriate security controls.* Work closely with IT and business teams to strengthen the organization’s security posture.Regulatory Compliance & Assurance* Ensure compliance with SAMA CSF, NCA ECC, and internal cybersecurity policies.* Support cybersecurity audits, regulatory assessments, and compliance reviews.* Coordinate remediation activities for audit findings and regulatory observations.* Act as the primary cybersecurity contact for auditors and regulatory assessments.Cloud & Third-Party Security* Support cloud security governance and third-party cybersecurity risk assessments.* Review technology vendors and outsourcing arrangements to ensure compliance with security requirements.* Monitor third-party security risks and recommend mitigation measures.Security Awareness & Leadership* Lead cybersecurity awareness and training initiatives across the organization.* Promote a strong cybersecurity culture and provide security guidance to business teams.* Collaborate with internal stakeholders to ensure cybersecurity is embedded across business operations.Key Competencies* Strong understanding of cybersecurity governance, risk management, and compliance.* Knowledge of SAMA CSF, NCA ECC, Counter Fraud Fundamental Framework and cybersecurity best practices.* Strong analytical and problem-solving skills.* Excellent communication and stakeholder management abilities.* Ability to manage multiple priorities in a fast-paced, regulated environment.* Experience coordinating cybersecurity incidents and regulatory activities.Qualifications & Experience* Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.* 3–5 years of experience in cybersecurity or information security with a background in governance, risk, or compliance, preferably within fintech, banking, or another regulated industry.* Working knowledge of SAMA Cyber Security Framework (CSF) and NCA Essential Cybersecurity Controls (ECC).* Experience in cybersecurity risk assessments, incident response, vulnerability management, security awareness, and compliance activities.* Familiarity with cloud security concepts and third-party risk management.* Professional certifications such as Security+, ISO 27001 Lead Implementer/Auditor, CEH, CISM, or CISSP are considered an advantage.* Excellent communication skills in Arabic and English, written and verbal.