About the company
Tabby is looking for an Information Security Specialist (GRC) to join the team. The successful candidate will independently execute governance, risk, and compliance activities across Tabby's information security programme.
Responsibilities
Information Security Governance
- Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures.
- Draft and revise information security policies, standards, and baselines, ensuring alignment with applicable regulatory requirements and business objectives.
- Monitor and track changes in legal, regulatory, and contractual requirements affecting information security (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating the compliance register accordingly.
- Maintain and update role and responsibility matrices (RACI), information security governance committee documentation, and reporting packs.
- Coordinate security governance committee meetings — preparing agendas, minutes, and action tracking.
- Produce internal and external communication materials related to information security governance, policies, and programme updates.
Information Risk Management
- Execute information security risk assessments independently, applying the organization's risk assessment methodology and producing complete risk registers.
- Maintain and update the information asset register — tracking asset owners, classifications, and associated risk profiles.
- Lead business impact assessment (BIA) data collection activities.
- Conduct control effectiveness evaluations for key information security controls.
- Coordinate third-party information security risk assessments.
- Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes.
- Prepare periodic risk reports for senior review.
Compliance & Programme Development
- Monitor the organization's compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS.
- Coordinate internal and external audit activities.
- Support the preparation of regulatory submissions, self-assessments, and compliance attestations.
- Maintain and enhance the security awareness programme.
- Monitor KPIs and KRIs for the information security programme.
- Support the integration of information security requirements into procurement, project management, and change control processes.
Cross-Functional & General GRC Support
- Maintain the information security policy, standard, and procedure library.
- Support information security initiatives across business and technology teams.
- Conduct information classification reviews.
- Deliver information security awareness sessions and materials.
- Provide analytical support for GRC team reporting, data gathering, and programme tracking activities.
Requirements
- Knowledge of SAMA CSF, NCA ECC, PDPL, ISO 27001, PCI-DSS
- Experience in information security governance, risk, and compliance
- Experience with risk assessments, BIA, control effectiveness evaluations
- Experience coordinating audits and regulatory submissions