Cybersecurity Specialist (GRC & Operations)
WePay | Trustworthy Partner · Riyadh, Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجWanna join the world of Fintech?At WePay, we're building the future of secure digital transactions in Saudi Arabia through an escrow platform designed to give buyers and sellers the confidence to transact with trust.If you thrive in a fast-paced environment, love storytelling, and are passionate about creating meaningful connections — this role is for you! This is an opportunity to shape how millions of customers and partners across Saudi Arabia understand and experience the future of escrow payments.Role Details:Location: Riyadh, Saudi ArabiaEmployment type: Full-time, OnsiteRole Overview: The Cybersecurity Specialist will support the development, implementation, and monitoring of WePay’s cybersecurity framework. The role will help protect our systems, data, customers, and operations while ensuring compliance with SAMA and NCA requirements as WePay grows.Responsibilities:Develop and maintain a cybersecurity program aligned with SAMA and NCA requirements.Act as the main point of contact for cybersecurity and GRC matters with external partners.Support responses to SAMA inquiries and observations and ensure gaps are closed on time.Review cybersecurity policies, procedures, and controls and recommend improvements.Monitor systems, applications, and networks for threats and vulnerabilities.Conduct risk assessments and track findings and corrective actions.Coordinate vulnerability assessments, penetration testing, and remediation.Investigate cybersecurity incidents and document findings and actions.Review access controls, privileged access, and multi-factor authentication.Prepare cybersecurity reports, audit evidence, and regulatory submissions.Work with internal teams to strengthen cybersecurity awareness and resilience.Preferred qualifications:Saudi national, as required by SAMA.3 to 5 years of cybersecurity experience in fintech, payments, banking, or another regulated financial institution.Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.Strong knowledge of SAMA CSF, NCA ECC, NCA CCC, and relevant cybersecurity requirements.Experience in security monitoring, vulnerability management, incident response, risk assessments, and regulatory audits.Experience in policy reviews, control assessments, gap management, and regulatory submissions.Familiarity with SIEM, endpoint security, access management, network security, and cloud security tools.Security+, ISO 27001, CISA, CISM, CRISC, CEH, or an equivalent certification is an advantage.Strong analytical, communication, and report-writing skills in Arabic and English.High integrity, sound judgement, confidentiality, and the ability to work independently in a growing startup.Why join WePay?Build from the beginning. Help shape one of Saudi Arabia’s first escrow platforms.Make your mark. Bring your ideas, own your work, and contribute to real decisions from day one.Learn through building. Grow by solving new challenges, experimenting, and creating something meaningful.Join a team that cares. We value ambition, balance, and life beyond work.Come build the beginning with us.