VP – Information Security, BCM & Data Privacy – KSA
First Abu Dhabi Bank (FAB) · Riyadh, Saudi Arabia
Apply & track with Apply EdgeJOB PURPOSE: The selected candidate will assist the Country CRO and will Lead FAB KSA’s Cybersecurity, Business Continuity Management (BCM), and Data Privacy functions, acting as the Chief Information Security Officer (CISO) for the KSA franchise.The candidate is responsible to establish and operate a robust cybersecurity governance program that meets the Saudi Central Bank (SAMA) Cybersecurity Framework (CSF) requirements, ensures compliance with all applicable laws and regulations such as SAMA CSF and BCM Frameworks, PDPL, NCA’s controls, and supports secure, resilient banking operations.In doing this, he/she will work closely with the Group Risk Management units to ensure the Group methodologies, policies, procedures are established in KSA. Additionally, implement control frameworks, and continuously improve maturity levels across governance, risk management, operations, and third‑party security.KEY ACCOUNTABILITIES: Cybersecurity Leadership & GovernanceDefine, communicate, and maintain the KSA Cybersecurity Strategy and Policy framework, mapped to SAMA CSF domains and sub‑domains.Establish and maintain a cybersecurity governance structure endorsed by senior management, with clear charters, roles, and decision rights.In conjunction with, and as required by the Country Chief Risk Officer, manage the Information Security & Business Continuity framework for Country and Group Risk & Compliance Committee.Strategy Development and Implementation Assist the Country Chief Risk Officer in formulation, implementation and delivery of the FAB Franchise in KSA’s Risk, Cybersecurity and BCM strategies in line with the vision, mission, values and priorities.Maintain, execute and continuously improve FAB Franchise in KSA’s risk management strategy, frameworks and tolerances to assess and mitigate the risk and to ensure the region operates within its pre-defined risk appetite, aligned to the group’s risk & business strategy.Budgeting and Financial Performance Manage the preparation of the department budget and monitor financial & risk performance versus the budget while ensuring all departmental activities are conducted in line with the approved guidelines. Policies, Systems, Processes & ProceduresAssist in development and effective implementation of risk policies (Information Security, Business Continuity, and Data Privacy), procedures and controls covering all areas of assigned FAB Franchise in KSA so that all relevant procedural/legislative requirements fulfilled while delivering a quality, cost-effective service.Contribute in development of a risk culture within the assigned FAB Franchise in KSA to drive heightened awareness and understanding of prudent risk management practices; work with other risk teams on technical aspects so that key stakeholders are equipped with the necessary knowledge and capability to take risk-based decisions on behalf of the Group.Risk Management FrameworkDevelop a comprehensive Risk Review mechanism for information security policies & procedures to assure consistency, comprehensiveness, and adequacy to enable an effective information security risk management process, and the same are adjusted as appropriate to reflect changes in the risk profile and market dynamics.Develop & maintain security assessment methodologies for IT infrastructure changes in line with the bank’s information security policy, PCI DSS requirements, industry standards and other regulatory requirements.Information Risk Assessment and ManagementManage the data classification and risk categorization of information assets in coordination with respective business/information owners, in order to enable the identification, analysis and mitigation of risk in information technology and business systems.Conduct risk assessments and oversee the penetration tests results to identify current and future security vulnerabilities and flaws in information systems, determine the management-approved level of risk, and work closely with relevant teams to prepare and maintain action plans to mitigate issues/IS risks.Identify current potential legal and regulatory issues affecting information security and monitor the assessment of their impact on the organization, in order to recommend suitable action plans and enable informed decision making.Design and ensure implementation of governance structure for information security to manage conformity and compliancy to security KSA-wide. Bring pressing information security vulnerabilities/risks to top management's attention so that immediate remedial action can be taken.Cybersecurity ComplianceEnsure regulatory compliance with SAMA CSF, NCA and other applicable regulations; maintain evidence repositories and self‑assessment maturity reporting.Plan and coordinate periodic cybersecurity reviews and independent audits; track and remediate findings to closure.Cybersecurity Monitoring and AssuranceCoordinate with Group Security Office and ensure continuous monitoring and logging; maintain SOC capabilities for event detection, triage, and escalation.Manage the monitoring of information security violations, review and provide recommendations on corrective action in order to ensure that adequate information security in compliance with the necessary standards guidelines and policies.Manage the testing of security architecture to evaluate the security strengths and detect possible threats to IT systems.Business Continuity Framework, Planning & GovernanceEstablish business continuity plans commensurate with the nature, size and complexity of operations, taking into consideration different types of likely or plausible risks/scenarios to which the group may be vulnerable in order to provide resilience against such risks/scenarios. Ensure that BCM plans are defined, rigorously tested, and implemented across all departments (including call tree testing, Crisis Management plan simulation, planning of premises consolidated and/or integrated exercises), in response to threats and hazards identified through risk management processes. Conduct training and awareness programs and facilitate their implementation to ensure that staff can effectively execute BCM plans. Design, develop and implement the BC corporate governance model to develop effective guidelines for conducting the business continuity process. Incident/Disaster ManagementOwn the Cybersecurity Incident Response Plan; lead incident coordination, forensics, eradication, and recovery; conduct post‑incident reviews and lessons learned.Define communication and regulatory reporting workflows; ensure timely internal/external notifications per regulatory expectations.Ensure that the recovery capabilities meet the business requirements through conducting regular testing in coordination with IT and analyzing the future business needs, so that the decisions related to the design and procurement of the new recovery infrastructure are facilitated by key inputs and facts.Ensure maintaining a log of incidents and review reports before presenting to the top management to ensure they are comprehensive and accurate in their key findings and provide value added recommendations for improvements of the business continuity plans.Data PrivacyDevelop data privacy strategies. Act as the primary point of contact within FAB KSA for members of staff, regulators, and any relevant public bodies on issues related to data protection –when needed.Ensure the FAB’s policies and procedures are in accordance with Personal Data Privacy Law (PDPL) and codes of practice.Evaluate the existing data privacy controls and identify areas of none or partial compliance and rectify any issues in consultation with key stakeholders.Inform and advise the Data Controller or Data Processor on all matters related to data privacy.Promote a culture of data privacy compliance across all units of the organization.Provide education to employees on important data compliance requirements.Devise training plans and provide data protection advice and support for members of staff.Hold training with staff members across different business units who are involved in data handling or processing.Proactively conduct audits to ensure compliance and address potential issues.Maintain records of all data processing activities carried out by FAB KSA.Monitoring changes to local privacy laws and making recommendations when appropriate.Reporting incidents to regulator and/or customers (depending on the incident).Review and edit existing documents or compose new documentation to ensure including all the law’s requirements in the bank literature.Lead and involve in data privacy related projects and initiatives. Coordinate with HO and other stakeholders for better alignment and efficiency. Change ManagementIntegrate cybersecurity into project and change governance; perform security assessments for new initiatives and technology changes.Participate in management of change through continuous improvement of functional systems, processes and practices considering global standards and changes in the business environment which demand proactive action plansSecurity Awareness & Training• Coordinate with Group Security awareness team ad develop role‑based awareness and training programs; measure effectiveness and drive culture change.QUALIFICATIONS & EXPERIENCE: Minimum QualificationBachelor’s degree in IT or related discipline.Master’s degree in business administration, or a related discipline is preferred.Professional certifications preferred: CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer/Lead Auditor, CBCP/CMCE, CCSP, SANS (e.g., GCIH, GCIA). Minimum Experience+10 years’ relevant experience in the banking sector with at least 4 years in similar positions of progressively increasing managerial responsibilities in the Information Security & Business Continuity management function.