Information Security Officer, Saudi National
Listed on 2026-05-24
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Job Summary
The Country Information Security Officer (CISO) for Saudi Arabia is a senior leadership position requiring a sophisticated blend of business insight and technical expertise in Information and Cyber Security (ICS). The role is critical in steering the strategic direction and operational management of risks to safeguard the bank’s assets, ensure compliance with regulatory frameworks, and reduce exposure to cyber threats. The CISO reports directly to the Cluster CISO for MENAP and maintains a matrix reporting relationship with the CEO and Head of Coverage for the Saudi Branch, commanding a comprehensive view of ICT across all business lines within the country.
The successful candidate will drive the adoption and full implementation of the IC Risk Type Framework, align local practices with global standards, and lead risk assessment, continuous monitoring, control validation, and risk mitigation activities while minimizing disruption to client services. The leader will cultivate relationships with stakeholders across technology, compliance, and business units and external partners including regulators and auditors, develop and execute a detailed plan to enhance the ICP posture in Saudi Arabia, and champion a culture of security awareness and continuous improvement.
- Provide authoritative leadership and direction on ICT risk management within the Saudi branch, fostering collaboration and alignment among key stakeholders, including CTOs, CIOs, security teams, and regulatory bodies.
- Champion the implementation and operationalisation of the ICT Risk Framework, working closely with management teams to identify critical information assets, perform comprehensive risk assessments, and prioritise mitigation efforts.
- Utilise both qualitative insights and quantitative metrics to validate the effectiveness of controls, accelerate risk evaluation processes, and maintain accurate risk profiles that inform strategic decision‑making.
- Deliver timely and insightful reports on ICT risk status, mitigation progress, and emerging threats to country and regional governance forums, ensuring transparency and informed oversight.
- Ensure seamless integration of security requirements within technology planning forums and influence the development of security technology roadmaps to address current and future risk landscapes.
- Lead the creation and execution of risk treatment plans in partnership with business and technology functions, balancing strategic priorities with operational constraints and navigating dependencies to achieve effective remediation.
- Coordinate cyber incident response planning and crisis management exercises, maintaining up‑to‑date playbooks, recovery strategies, and contingency measures to bolster organisational readiness.
- Drive security awareness initiatives targeted at senior leadership and staff, promoting a culture of risk accountability and resilience across the organisation.
- Manage responses to audit and regulatory inquiries pertaining to ICT strategies, controls, and compliance, ensuring timely and accurate resolution of issues.
- Maintain proactive engagement with local regulatory authorities, such as the Saudi Central Bank, to address submissions, advisory requests, and conduct assessments that align the organisation’s ICT posture with regulatory expectations.
- Support cross‑functional ICT initiatives including those related to capital market entities within Saudi Arabia, enhancing cohesive security practices across business units.
Office‑based role located in Riyadh, Saudi Arabia with a full‑time schedule, underpinning close collaboration with internal and external stakeholders within the region.
This is a critical strategic leadership role that demands a proactive, hands‑on approach to information security risk management and regulatory compliance in the Saudi financial services landscape. The Chief Information Security Officer for Saudi Arabia will anchor the organisation’s efforts to mitigate cyber and information risks while ensuring alignment with global and regional standards. The role mandates a comprehensive understanding of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).