Cybersecurity GRC Specialist
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
About the Role
About SiFi SiFi is a fast-growing B2B FinTech company specializing in spend management and card issuance solutions. We help companies take control of their spending, streamline expense workflows, and operate with greater efficiency.
Key Skills for This Role
Full Job Posting
About Sifi
SiFi is a fast-growing B2B FinTech company specializing in spend management and card issuance solutions.
We help companies take control of their spending, streamline expense workflows, and operate with greater efficiency.
Role Overview
The Cybersecurity GRC Specialist plays a critical role in maintaining SiFi’s cybersecurity compliance posture and ensuring audit readiness across all regulatory frameworks.
This role is responsible for managing the full Governance, Risk, and Compliance (GRC) lifecycle — including evidence management, policy governance, risk tracking, and KPI/KRI reporting — ensuring that all cybersecurity controls are measurable, defensible, and aligned with regulatory expectations.
1. Regulatory Compliance & Audit Readiness
- Maintain and manage the compliance tracker across SAMA CSF, PDPL/NDMO, and PCI-DSS
- Own the full evidence lifecycle: collection, validation, and documentation
- Ensure continuous audit readiness with traceable, control-aligned evidence
- Track regulatory findings and remediation plans, ensuring timely closure
- Provide regular compliance status reports to the CISO and relevant committees
2. Governance & Policy Management
- Develop and maintain cybersecurity policies, standards, and procedures
- Ensure documentation aligns with SiFi governance structure and regulatory expectations
- Manage document lifecycle (versioning, approvals, reviews)
- Map all policies and procedures to SAMA CSF controls
3. Cyber Risk Management
- Maintain and update the cybersecurity risk register
- Conduct third-party risk assessments (TPRA) and vendor due diligence
- Support risk reviews and reporting cycles
- Collaborate with Risk and Compliance teams to align enterprise risk frameworks
4. KPI And KRI Monitoring & Reporting
- Collect and validate cybersecurity KPIs/KRIs from relevant stakeholders
- Maintain a centralized KPI/KRI tracker
- Prepare periodic reports with trend analysis to support regulatory maturity (Level 3+)
- Identify and escalate performance gaps
Requirements
- Minimum 2 years in a dedicated Cybersecurity GRC role
- Hands-on experience with SAMA CSF compliance within regulated entities
- Experience in audit evidence preparation and regulatory assessments
- Strong background in drafting cybersecurity policies and procedures
- Experience using GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust, etc.)
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field
- Certifications in ISO 27001 Lead Implementer / Lead Auditor, Security+, (ISC)² CC, CGRC or CISA or CRISC
- Speaks English and Arabic
Preferred Qualifications
- Experience with PDPL and NDMO regulations
- PCI-DSS compliance exposure
- Knowledge of cloud security (AWS, Azure, GCP, OCI)
- Experience in fintech or financial services\
- Familiarity with frameworks like ISO 27001, NIST, COBIT
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at SiFi
Infrastructure Manager
Riyadh, KSA
ABOUT SIFI SiFi is a corporate expense management platform designed to empower finance and accounting teams with seamless control over corporate spending. Our platform allows companies to issue cards with specific spendi
Customer Success Specialist
Riyadh, KSA
About Us: SiFi is a rapidly growing B2B Fin-Tech company transforming expense management for businesses in Saudi Arabia. As a licensed EMI from the Saudi Central Bank, we empower companies with innovative tools to simpli
AML officer ( Saudi Nationality only)
Riyadh, KSA
About SiFi SiFi is building the future of spend management and financial operations in Saudi Arabia. Following our expansion into domestic and cross-border remittances, we are hiring a specialist who can bridge the gap b
Internal Audit Manager
Riyadh, KSA
About Us: SiFi is a rapidly growing B2B Fin-Tech company transforming expense management for businesses in Saudi Arabia. As a licensed EMI from the Saudi Central Bank, we empower companies with innovative tools to simpli
Tamheer Opportunity – Internal Audit
Riyadh, KSA
About SiFi: SiFi is a corporate expense management platform designed to empower /accounting teams with seamless control over corporate spending. Our platform allows companies to issue cards with specific spending restric
Senior Data Engineer (Data & AI)
Riyadh, KSA
About Us We are building the next-generation Office of the CFO that simplifies finance for all businesses. SiFi is a corporate expense management platform designed to empower accounting teams with seamless control over c
Customer Support Specialist
Riyadh, KSA
About SiFi: SiFi is a corporate expense management platform designed to empower /accounting teams with seamless control over corporate spending. Our platform allows companies to issue cards with specific spending restric
AI Engineer
Riyadh, KSA
About Us SiFi is building the next-generation Office of the CFO — a corporate expense management platform that gives accounting teams seamless control over company spending. We let companies issue cards with precise spen
Infrastructure Manager
Riyadh, KSA
Customer Success Specialist
Riyadh, KSA
AML officer ( Saudi Nationality only)
Riyadh, KSA
Internal Audit Manager
Riyadh, KSA
Tamheer Opportunity – Internal Audit
Riyadh, KSA
Senior Data Engineer (Data & AI)
Riyadh, KSA
Customer Support Specialist
Riyadh, KSA
AI Engineer
Riyadh, KSA