VP – Information Security, BCM & Data Privacy – KSA
Listed on 2026-09-13
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The selected candidate will assist the Country CRO and will Lead FAB KSA’s Cybersecurity, Business Continuity Management (BCM), and Data Privacy functions, acting as the Chief Information Security Officer (CISO) for the KSA franchise.
The candidate is responsible to establish and operate a robust cybersecurity governance program that meets the Saudi Central Bank (SAMA) Cybersecurity Framework (CSF) requirements, ensures compliance with all applicable laws and regulations such as SAMA CSF and BCM Frameworks, PDPL, NCA’s controls, and supports secure, resilient banking operations.
In doing this, he/she will work closely with the Group Risk Management units to ensure the Group methodologies, policies, procedures are established in KSA. Additionally, implement control frameworks, and continuously improve maturity levels across governance, risk management, operations, and third‑party security.
KEY ACCOUNTABILITIES:Cybersecurity Leadership & Governance
- Define, communicate, and maintain the KSA Cybersecurity Strategy and Policy framework, mapped to SAMA CSF domains and sub‑domains.
- Establish and maintain a cybersecurity governance structure endorsed by senior management, with clear charters, roles, and decision rights.
- In conjunction with, and as required by the Country Chief Risk Officer, manage the Information Security & Business Continuity framework for Country and Group Risk & Compliance Committee.
- Assist the Country Chief Risk Officer in formulation, implementation and delivery of the FAB Franchise in KSA’s Risk, Cybersecurity and BCM strategies in line with the vision, mission, values and priorities.
- Maintain, execute and continuously improve FAB Franchise in KSA’s risk management strategy, frameworks and tolerances to assess and mitigate the risk and to ensure the region operates within its pre-defined risk appetite, aligned to the group’s risk & business strategy.
- Manage the preparation of the department budget and monitor financial & risk performance versus the budget while ensuring all departmental activities are conducted in line with the approved guidelines.
- Assist in development and effective implementation of risk policies (Information Security, Business Continuity, and Data Privacy), procedures and controls covering all areas of assigned FAB Franchise in KSA so that all relevant procedural/legislative requirements fulfilled while delivering a quality, cost-effective service.
- Contribute in development of a risk culture within the assigned FAB Franchise in KSA to drive heightened awareness and understanding of prudent risk management practices; work with other risk teams on technical aspects so that key stakeholders are equipped with the necessary knowledge and capability to take risk-based decisions on behalf of the Group.
- Develop a comprehensive Risk Review mechanism for information security policies & procedures to assure consistency, comprehensiveness, and adequacy to enable an effective information security risk management process, and the same are adjusted as appropriate to reflect changes in the risk profile and market dynamics.
- Develop & maintain security assessment methodologies for IT infrastructure changes in line with the bank’s information security policy, PCI DSS requirements, industry standards and other regulatory requirements.
- Manage the data classification and risk categorization of information assets in coordination with respective business/information owners, in order to enable the identification, analysis and mitigation of risk in information technology and business systems.
- Conduct risk assessments and oversee the penetration tests results to identify…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).