Job description
Role Overview
Cybersecurity GRC Manager at HALA, a leading fintech player in the MENAP region, based in the UAE with operations across Saudi Arabia and Egypt.
Company Overview
HALA is a fintech company founded in 2017 that aims to redefine financial services and build the future bank of SMEs. The company empowers small and medium enterprises to start, run, and grow their businesses by providing cutting-edge financial and technological tools. HALA currently holds multiple entities in the UAE, Saudi Arabia, and Egypt, including HALA Payments and HALA Logistics, and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations. HALA is licensed by the Saudi Arabian Central Bank.
Role Purpose
Lead the organization's governance, risk management, compliance, and audit functions to establish and maintain a robust cybersecurity program aligned with business goals and regulatory requirements across the MENAP region.
Key Responsibilities
Governance & Strategy
- Develop, implement, and continuously improve the organization's Information Security Governance framework, policies, standards, and procedures.
- Lead the creation and execution of the Cyber Security Strategy in alignment with the company's overall business goals.
- Provide regular reports to the Board of Directors and executive management on the state of cybersecurity.
- Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure the effectiveness of the security program and report on progress.
- Oversee the information security budget, ensuring resources are allocated effectively to manage risk.
Risk Management
- Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program.
- Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks.
- Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation, acceptance, or transfer strategies are implemented.
- Manage the vendor risk management program, assessing the security posture of third-party vendors and partners, especially cloud service providers and payment gateways.
- Integrate risk management into the Software Development Life Cycle (SDLC) and change management processes.
Regulatory Compliance
- Serve as the primary point of contact and subject matter expert for all regulatory examinations and audits related to cybersecurity, including SAMA and CMA.
- Ensure continuous compliance with SAMA's Cyber Security Framework (CSF), Payment Card Industry Data Security Standard (PCI DSS) requirements, and other relevant regulations.
- Manage the process for obtaining and maintaining necessary regulatory licenses and certifications from a cybersecurity perspective.
- Prepare and submit accurate and timely regulatory reports, questionnaires, and evidence requests.
- Monitor the regulatory landscape for changes in laws, regulations, and standards, and proactively advise the business on required adjustments.
Audit & Assurance
- Manage all internal and external security audits, including coordinating with auditors, providing evidence, and tracking remediation of findings.
- Develop and maintain a robust control testing program to validate the effectiveness of key security controls.
- Manage the remediation of all audit and assessment findings, ensuring they are closed out effectively and permanently.
Awareness & Culture
- Develop and deliver a security awareness and training program tailored to different roles within the organization, with a focus on local context and threats.
- Champion a strong security culture, ensuring that every employee understands their role in protecting the company's information assets.
Additional Information
- Inclusive and diverse culture that encourages innovation and flexibility in remote, in-office, and hybrid work setups.
- Highly competitive compensation packages, including the potential for shares.
- Regular training and annual learning stipend to support personal development and career growth in a hyper-growth environment.
- Opportunity to work with a talented team of over 30 nationalities across 7 countries.
- Autonomy, mentoring, and challenging goals that create opportunities for both personal and company growth.
- Significant responsibility and trust with freedom to execute function priorities independently.