Talent.com
This job offer is not available in your country.
Chief Risk Officer- KSA | Riyadh, SA

Chief Risk Officer- KSA | Riyadh, SA

Bank of JordanRiyadh, Saudi Arabia
30+ days ago
Job description

Ensures compliance with all applicable cybersecurity regulations and standards in the region, especially those issued by the Saudi Arabian Monetary Authority (SAMA), and provides necessary support and cooperation to regulatory bodies during audits and inquiries. Follows up on the review of security procedures and mechanisms, participates in defining security responsibilities and controls, and works with external information security consultants to enhance the bank's information security posture. Conducts in-depth analysis of past cybersecurity incidents to prevent recurrence and to continuously improve the cybersecurity system. Oversees, reviews, and periodically updates the bank's Information Security Policy and technology framework (COBIT), assesses risks based on NIST standards, evaluates data protection mechanisms and encryption practices, and ensures proper access controls to backup media and devices. Reviews them periodically in line with the branch's strategy by analyzing and managing cybersecurity risks, access controls, and information security documentation standards, and contributes to developing and implementing these policies to improve information governance. Manages the implementation of the cybersecurity program, develops an approach to integrate cybersecurity into bank operations at all levels, manages cyber risk assessments, recommends mitigation controls and procedures, defines cybersecurity requirements for current and new projects, and oversees information / system classification processes. Evaluates the adequacy of cybersecurity risk controls and approves exceptions based on acceptable risk levels and regulatory guidelines, in coordination with the group-level information security team. Measures and develops the performance of cybersecurity programs and key risk indicators, ensures compliance with cybersecurity policies, standards, and procedures, and regularly reports the cybersecurity program status to the Board of Directors and relevant committees as needed. Reviews system user reports to ensure the application of authorized user access policies across bank data, identifies users violating approved policies, and takes corrective actions to prevent future breaches. Assesses the efficiency of IT infrastructure security by monitoring performance indicators, using appropriate tools, and reviewing configuration reports. Manages security and cyber incident response and digital forensics, and implements necessary actions to address and minimize impacts in alignment with business continuity plans and in coordination with relevant internal and external parties. Manages access control policies at all levels in coordination with information owners and helps develop the necessary procedures for access transitions. Ensures the bank's compliance with information protection laws and regulations, including the General Data Protection Regulation (GDPR) and the Personal Data Protection Law (PDPL) in Saudi Arabia, by monitoring data handling, processing, and storage practices. Develops and enhances cybersecurity procedures by simulating cyberattack scenarios such as phishing and penetration testing to safeguard the bank's interests. Ensures external service providers comply with the bank's cybersecurity standards by conducting regular security assessments and ongoing monitoring to protect the bank's rights. Collaborates with external information security consultants to improve the bank's information security framework. Prepares periodic information security reports for relevant departments and committees at the branch and head office levels. Reviews activities of various automated systems and prepares periodic reports on the Information Security / Business Continuity unit, reflecting relevant security events. Submits detailed cybersecurity risk reports to relevant committees and stakeholders, including trends, breach probabilities, and mitigation strategies quarterly or as required. Oversees the review of information systems / cybersecurity control measures, periodically assesses information risk, recommends new technologies and countermeasures to align with global trends, and supervises the security of any new services or projects planned by the bank. Develops and delivers information security awareness and training programs for bank staff in collaboration with the group-level information security team. Ensures compliance with all applicable cybersecurity regulations and standards in the region, especially those issued by the Saudi Arabian Monetary Authority (SAMA), and provides necessary support and cooperation to regulatory bodies during audits and inquiries. Follows up on the review of security procedures and mechanisms, participates in defining security responsibilities and controls, and works with external information security consultants to enhance the bank's information security posture. Conducts in-depth analysis of past cybersecurity incidents to prevent recurrence and to continuously improve the cybersecurity system. Oversees, reviews, and periodically updates the bank's Information Security Policy and technology framework (COBIT), assesses risks based on NIST standards, evaluates data protection mechanisms and encryption practices, and ensures proper access controls to backup media and devices. Reviews them periodically in line with the branch's strategy by analyzing and managing cybersecurity risks, access controls, and information security documentation standards, and contributes to developing and implementing these policies to improve information governance. Manages the implementation of the cybersecurity program, develops an approach to integrate cybersecurity into bank operations at all levels, manages cyber risk assessments, recommends mitigation controls and procedures, defines cybersecurity requirements for current and new projects, and oversees information / system classification processes. Evaluates the adequacy of cybersecurity risk controls and approves exceptions based on acceptable risk levels and regulatory guidelines, in coordination with the group-level information security team. Measures and develops the performance of cybersecurity programs and key risk indicators, ensures compliance with cybersecurity policies, standards, and procedures, and regularly reports the cybersecurity program status to the Board of Directors and relevant committees as needed. Reviews system user reports to ensure the application of authorized user access policies across bank data, identifies users violating approved policies, and takes corrective actions to prevent future breaches. Assesses the efficiency of IT infrastructure security by monitoring performance indicators, using appropriate tools, and reviewing configuration reports. Manages security and cyber incident response and digital forensics, and implements necessary actions to address and minimize impacts in alignment with business continuity plans and in coordination with relevant internal and external parties. Manages access control policies at all levels in coordination with information owners and helps develop the necessary procedures for access transitions. Ensures the bank's compliance with information protection laws and regulations, including the General Data Protection Regulation (GDPR) and the Personal Data Protection Law (PDPL) in Saudi Arabia, by monitoring data handling, processing, and storage practices. Develops and enhances cybersecurity procedures by simulating cyberattack scenarios such as phishing and penetration testing to safeguard the bank's interests. Ensures external service providers comply with the bank's cybersecurity standards by conducting regular security assessments and ongoing monitoring to protect the bank's rights. Collaborates with external information security consultants to improve the bank's information security framework. Prepares periodic information security reports for relevant departments and committees at the branch and head office levels. Reviews activities of various automated systems and prepares periodic reports on the Information Security / Business Continuity unit, reflecting relevant security events. Submits detailed cybersecurity risk reports to relevant committees and stakeholders, including trends, breach probabilities, and mitigation strategies quarterly or as required. Oversees the review of information systems / cybersecurity control measures, periodically assesses information risk, recommends new technologies and countermeasures to align with global trends, and supervises the security of any new services or projects planned by the bank. Develops and delivers information security awareness and training programs for bank staff in collaboration with the group-level information security team. Responsibilities : Ensures compliance with all applicable cybersecurity regulations and standards in the region, especially those issued by the Saudi Arabian Monetary Authority (SAMA), and provides necessary support and cooperation to regulatory bodies during audits and inquiries. Follows up on the review of security procedures and mechanisms, participates in defining security responsibilities and controls, and works with external information security consultants to enhance the bank's information security posture. Conducts in-depth analysis of past cybersecurity incidents to prevent recurrence and to continuously improve the cybersecurity system. Oversees, reviews, and periodically updates the bank's Information Security Policy and technology framework (COBIT), assesses risks based on NIST standards, evaluates data protection mechanisms and encryption practices, and ensures proper access controls to backup media and devices. Reviews them periodically in line with the branch's strategy by analyzing and managing cybersecurity risks, access controls, and information security documentation standards, and contributes to developing and implementing these policies to improve information governance. Manages the implementation of the cybersecurity program, develops an approach to integrate cybersecurity into bank operations at all levels, manages cyber risk assessments, recommends mitigation controls and procedures, defines cybersecurity requirements for current and new projects, and oversees information / system classification processes. Evaluates the adequacy of cybersecurity risk controls and approves exceptions based on acceptable risk levels and regulatory guidelines, in coordination with the group-level information security team. Measures and develops the performance of cybersecurity programs and key risk indicators, ensures compliance with cybersecurity policies, standards, and procedures, and regularly reports the cybersecurity program status to the Board of Directors and relevant committees as needed. Reviews system user reports to ensure the application of authorized user access policies across bank data, identifies users violating approved policies, and takes corrective actions to prevent future breaches. Assesses the efficiency of IT infrastructure security by monitoring performance indicators, using appropriate tools, and reviewing configuration reports. Manages security and cyber incident response and digital forensics, and implements necessary actions to address and minimize impacts in alignment with business continuity plans and in coordination with relevant internal and external parties. Manages access control policies at all levels in coordination with information owners and helps develop the necessary procedures for access transitions. Ensures the bank's compliance with information protection laws and regulations, including the General Data Protection Regulation (GDPR) and the Personal Data Protection Law (PDPL) in Saudi Arabia, by monitoring data handling, processing, and storage practices. Develops and enhances cybersecurity procedures by simulating cyberattack scenarios such as phishing and penetration testing to safeguard the bank's interests. Ensures external service providers comply with the bank's cybersecurity standards by conducting regular security assessments and ongoing monitoring to protect the bank's rights. Collaborates with external information security consultants to improve the bank's information security framework. Prepares periodic information security reports for relevant departments and committees at the branch and head office levels. Reviews activities of various automated systems and prepares periodic reports on the Information Security / Business Continuity unit, reflecting relevant security events. Submits detailed cybersecurity risk reports to relevant committees and stakeholders, including trends, breach probabilities, and mitigation strategies quarterly or as required. Oversees the review of information systems / cybersecurity control measures, periodically assesses information risk, recommends new technologies and countermeasures to align with global trends, and supervises the security of any new services or projects planned by the bank. Develops and delivers information security awareness and training programs for bank staff in collaboration with the group-level information security team.

Requirements

Skills and Competencies (as previously translated) : A university degree in Computer Engineering or any related field. A minimum of 10 years of experience in Information Technology (IT), including at least 5 years in Information / Cyber Security. Preferably holds certifications such as CISM, ISO 27001, PCIP, or any related certification. Strong planning and organizational skills. Decision-making capabilities. Full fluency in English (spoken and written). Strong analytical abilities. Proficiency in computer usage and working with implemented systems. Thorough knowledge of internal and external policies and procedures governing the work. Excellent interpersonal and communication skills. In-depth knowledge of PCI, COBIT, ISO 22301, cybersecurity standards, and any information security regulations issued by regulatory bodies. Ability to work under pressure.

Boost your career Find thousands of job opportunities by signing up to eFinancialCareers today. #J-18808-Ljbffr

Create a job alert for this search

Risk Officer • Riyadh, Saudi Arabia

Related jobs
  • Promoted
Risk Manager

Risk Manager

Jasara Program Management CompanyRiyadh, Riyadh Region, Saudi Arabia
JASARA PMC is currently seeking a highly skilled and motivated Risk Manager to join our team.As a Risk Manager at JASARA PMC, you will play a critical role in identifying, assessing, and mitigating...Show moreLast updated: 30+ days ago
  • Promoted
Risk Manager

Risk Manager

ITALCONSULTRiyadh, Riyadh Region, Saudi Arabia
Department : Project Control Office.To conduct project risks and issues identification, evaluation, mitigation and development of risk and issues prevention strategies. Assist all Project members in ...Show moreLast updated: 1 day ago
  • Promoted
Risk Manager

Risk Manager

WSP Global Inc.Riyadh, Saudi Arabia
We are seeking a highly skilled.The ideal candidate will have experience in.This role involves close coordination with project, commercial, and technical teams to proactively manage risks and ensur...Show moreLast updated: 30+ days ago
  • Promoted
Senior Risk Manager

Senior Risk Manager

Turner & TownsendRiyadh, Riyadh Region, Saudi Arabia
Turner & Townsend is a global professional services company with over 22,000 people in more than 60 countries.Working with our clients across real estate, infrastructure, energy and natural resourc...Show moreLast updated: 7 days ago
Senior Risk Manager

Senior Risk Manager

JASARA PMCRiyadh, Riyadh Province, SA
Quick Apply
JASARA PMC is looking for a highly skilled Senior Risk Manager to join our dynamic team.As a collaborative joint venture involving the Public Investment Fund (PIF), Jacobs, and Saudi Aramco, we str...Show moreLast updated: 30+ days ago
Risk Manager

Risk Manager

Premium Solutions ConsultancyRiyadh, Riyadh Province, SA
Quick Apply
Our client in KSA is seeking a Risk Manager to join our team in Saudi Arabia.The Risk Manager will be responsible for identifying, assessing, and prioritizing risks to ensure successful project del...Show moreLast updated: 30+ days ago
Risk Manager

Risk Manager

Arthur LawrenceRiyadh, SA
Quick Apply
Arthur Lawrence is urgently looking for a Risk Manager for a client in Riyadh, KSA.Kindly review the Job requirements below. Your immediate application will enable us to place you successfully.Must-...Show moreLast updated: 30+ days ago
  • Promoted
IT Risk Manager

IT Risk Manager

VisionX Technologies, Inc.Riyadh, Riyadh Region, Saudi Arabia
At VisionX, we cut through the noise.Since 2017, we’ve been on a mission to demolish business complexity with AI—no off-the-shelf solutions, just custom, agile systems designed for your unique chal...Show moreLast updated: 30+ days ago
  • Promoted
Governance, Risk, Compliance, GRC

Governance, Risk, Compliance, GRC

Confidential GovernmentRiyadh, Saudi Arabia
We're seeking a Governance, Risk, and Compliance experience to lead our efforts in maintaining a robust GRC framework.The ideal candidate will have extensive experience in developing and implementi...Show moreLast updated: 12 days ago
  • Promoted
Risk Management Analyst

Risk Management Analyst

TweeqRiyadh, Saudi Arabia
Description About the role : The Risk Management Analyst will support the Risk Manager in developing, implementing, and maintaining effective risk management strategies that protect the organization...Show moreLast updated: 30+ days ago
  • Promoted
Risk Manager

Risk Manager

JASARA PMCRiyadh, Saudi Arabia
JASARA PMC is looking to hire a Risk Manager.In this critical role, you will be responsible for developing and implementing robust risk management strategies to ensure the successful delivery of ou...Show moreLast updated: 30+ days ago
  • Promoted
4B3 - Risk Manager - [WB & RR]

4B3 - Risk Manager - [WB & RR]

Parsons OmanRiyadh, Saudi Arabia
In a world of possibilities, pursue one with endless opportunities.Imagine Next! When it comes to what you want in your career, if you can imagine it, you can do it at Parsons.Imagine a career work...Show moreLast updated: 30+ days ago
  • Promoted
Risk Manager

Risk Manager

SHAFONS Recruitment ServicesRiyadh, Saudi Arabia
SHAFONS Recruitment Services is a Private Limited Company (Pvt.Human Resource consultancy services in Dubai, UAE.We provide comprehensive employment services including job placements, recruitment, ...Show moreLast updated: 15 days ago
  • Promoted
Risk Management Specialist

Risk Management Specialist

AY Consultants LimitedRiyadh, Saudi Arabia
Our Client, a leading International Consultancy specialising in engineering and project management for the building industry, has recently been awarded one of the largest Healthcare projects in Sau...Show moreLast updated: 30+ days ago
  • Promoted
Risk Management Specialist

Risk Management Specialist

National Company for Business Solutions - NCBSRiyadh, Saudi Arabia
ISO 31000 مهارات تنظيمية وإدارة الوقت ممتازة.Show moreLast updated: 26 days ago
  • Promoted
Risk Manager (Theme Park - DB)

Risk Manager (Theme Park - DB)

Jasara Program Management CompanyRiyadh, Riyadh Region, Saudi Arabia
JASARA PMC is currently seeking a highly skilled and motivated Risk Manager to join our team.As a Risk Manager at JASARA PMC, you will play a critical role in identifying, assessing, and mitigating...Show moreLast updated: 30+ days ago
  • Promoted
Senior Risk Manager

Senior Risk Manager

Jasara Program Management CompanyRiyadh, Saudi Arabia
Overview JASARA PMC is looking for a highly skilled Senior Risk Manager to join our dynamic team.As a collaborative joint venture involving the Public Investment Fund (PIF), Jacobs, and Saudi Aramc...Show moreLast updated: 30+ days ago
  • Promoted
Senior Risk Manager – Brokerage

Senior Risk Manager – Brokerage

Huxley AssociatesRiyadh, Saudi Arabia
Our client, a leading local Investment bank based in Saudi Arabia, is seeking a Senior Risk Manager to join their team.Senior Risk Manager - Brokerage Client : . Leading Bank in Saudi Arabia Location : ...Show moreLast updated: 30+ days ago
Risk Manager (Theme Park - DB)

Risk Manager (Theme Park - DB)

JASARA PMCRiyadh, Riyadh Province, SA
Quick Apply
JASARA PMC is currently seeking a highly skilled and motivated Risk Manager to join our team.As a Risk Manager at JASARA PMC, you will play a critical role in identifying, assessing, and mitigating...Show moreLast updated: 30+ days ago
  • Promoted
Risk Manager

Risk Manager

Wood PLCQuwayiyah, Riyadh, Saudi Arabia
Remarkable people, trusted by clients to design and advance the world.Wood is currently seeking a Risk Manager to support our Projects business. Ma'aden is executing a strategic project to develop a...Show moreLast updated: 6 days ago