The Lead Anti-Fraud Officer independently leads complex governance, risk, and compliance activities and serves as a subject matter expert in one or more GRC domains enterprise information security governance, risk management frameworks, regulatory compliance, or third-party risk management. The role produces high-quality GRC deliverables, provides technical mentoring to junior and mid-level team members, and contributes directly to the continuous improvement of the organization's GRC framework, risk treatment processes, and compliance reporting mechanisms. The Lead Anti-Fraud Officer operates as a bridge between technical execution and programme leadership collaborating with leads, legal, audit, and business stakeholders to drive mature and effective GRC outcomes aligned with the Saudi Fintech regulatory environment. Lead the development, review, and continuous improvement of information security policies, standards, procedures, and governance frameworks. Serve as the subject matter expert for assigned regulatory domains, providing authoritative interpretation of requirements and translating them into implementable control objectives. Monitor and proactively track regulatory and legal developments affecting information security assessing impact and recommending updates to the governance framework. Prepare and review governance documentation RACI matrices, security charter updates, governance committee packs and present findings to senior stakeholders. Lead the preparation of regulatory self-assessments and compliance attestations, coordinating evidence gathering and quality-reviewing submissions before senior sign-off. Mentor GR1 GR2 team members on governance documentation quality, regulatory interpretation, and risk assessment methodology. Enterprise Risk Management Lead the execution of complex enterprise information security risk assessments, applying advanced qualitative and quantitative methodologies to produce risk profiles aligned with the organization's risk appetite. Own and maintain the enterprise information security risk register ensuring accuracy, currency, and appropriate escalation of significant risks. Lead BIA processes for critical business functions coordinating with asset owners, analysing recovery requirements, and producing BIA outputs for Business Continuity and Disaster Recovery planning. Design and execute control effectiveness testing programmes, producing findings reports with gap analysis and risk-ranked remediation recommendations. Lead third-party information security risk management designing assessment frameworks, conducting in-depth vendor reviews, and maintaining the third-party risk register. Produce executive-quality risk reporting with trend analysis, emerging risk identification, and treatment progress tracking for senior management and committee consumption. Compliance Programme Delivery Lead compliance monitoring activities for CFFR, NCA ECC, PDPL, ISO 27001, and PCI-DSS producing gap analyses, treatment plans, and periodic compliance status reports. Manage internal and external audit cycles coordinating evidence collection, reviewing evidence quality, engaging with auditors, and tracking remediation to closure. Design and deliver the security awareness programme producing targeted content for different staff segments, conducting awareness sessions, and analysing effectiveness metrics. Develop and maintain GRC programme metrics dashboards, ensuring KPIs and KRIs are accurately measured and presented to senior management on schedule. Lead the integration of information security requirements into third-party contracts, procurement processes, and major project onboarding. Contribute to the development of the information security programme strategy, identifying capability improvement opportunities and recommending investment priorities to the Lead. Cross-Functional Collaboration & Knowledge Leadership Serve as the primary GRC point of contact for assigned business and technology teams providing expert guidance on security requirements, risk treatment, and compliance obligations. Lead information classification and security requirements reviews for significant IT, product, and business projects. Contribute to the GRC knowledge base developing reusable templates, guidance documents, and training materials for internal use. Represent the GRC function in cross-functional working groups, project steering committees, and regulatory workstreams. Perform additional responsibilities as assigned by management.
Desired Candidate Profile
Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field. A Master's degree in Information Security, Risk Management, or Business Administration is an advantage. 3 5 years of progressive professional experience in information security governance, risk management, or compliance. Demonstrable experience independently leading risk assessment cycles, regulatory compliance programmes, or audit coordination activities. In-depth knowledge of the CFFR framework is required. Experience in a regulated Fintech or banking environment is strongly preferred.
يتولى مسؤول مكافحة الاحتيال الرئيسي قيادة أنشطة الحوكمة وإدارة المخاطر والامتثال المعقدة بشكل مستقل، ويعد خبيرًا في أحد أو أكثر من مجالات الحوكمة وإدارة المخاطر والامتثال، مثل حوكمة أمن المعلومات المؤسسي، وإطارات إدارة المخاطر، والامتثال التنظيمي، أو إدارة مخاطر الأطراف الثالثة. ويقوم هذا الدور بإنتاج مخرجات عالية الجودة في مجال الحوكمة وإدارة المخاطر والامتثال، ويقدم التوجيه الفني لأعضاء الفريق المبتدئين والمتوسطي المستوى، ويساهم بشكل مباشر في التحسين المستمر لإطار الحوكمة وإدارة المخاطر لدى المؤسسة، وعمليات معالجة المخاطر، وآليات إعداد تقارير الامتثال. ويعمل مسؤول مكافحة الاحتيال الرئيسي كجسر بين التنفيذ الفني والقيادة البرنامجية، بالتعاون مع القادة والإدارات القانونية والتدقيق وأصحاب المصلحة في الأعمال لدفع عجلة تحقيق نتائج ناضجة وفعالة في الحوكمة وإدارة المخاطر والامتثال بما يتوافق مع البيئة التنظيمية السعودية للقطاع المالي التقني. ويقود تطوير ومراجعة والتحسين المستمر لسياسات وإجراءات معايير حوكمة أمن المعلومات، والإطارات التنظيمية. ويعد خبيرًا في المجالات التنظيمية المخصصة، ويقدم تفسيرات رسمية للمتطلبات وترجمتها إلى أهداف رقابية قابلة للتنفيذ. ويراقب ويتابع بشكل استباقي التطورات التنظيمية والقانونية التي تؤثر على أمن المعلومات، ويقيم تأثيرها ويوصي بتحديثات إطار الحوكمة. ويعد ويُراجع الوثائق التنظيمية مثل مصفوفات المسؤوليات (RACI)، وتحديثات ميثاق الأمن، وحزم لجان الحوكمة، ويعرض النتائج على أصحاب المصلحة الرئيسيين. ويقود إعداد التقييمات الذاتية التنظيمية وشهادات الامتثال، ويتنسيق جمع الأدلة ومراجعتها قبل التوقيع عليها من قبل الإدارة العليا. ويرشد أعضاء فريق GR1 وGR2 على جودة وثائق الحوكمة، وتفسير المتطلبات التنظيمية، ومنهجية تقييم المخاطر.
إدارة المخاطر المؤسسية
يقود تنفيذ تقييمات معقدة لمخاطر أمن المعلومات المؤسسي، ويطبق منهجيات نوعية وكمية متقدمة لإنتاج ملفات تعريف للمخاطر تتوافق مع تحمل المؤسسة للمخاطر. ويمتلك ويدير سجل مخاطر أمن المعلومات المؤسسي، ويضمن دقته وحداثته ورفع المخاطر الهامة بشكل مناسب. ويقود عمليات تحليل التأثير على الأعمال للوظائف الحيوية للأعمال، بالتعاون مع أصحاب الأصول، وتحليل متطلبات الاسترداد، وإنتاج مخرجات تحليل التأثير على الأعمال للتخطيط لاستمرارية الأعمال والتعافي من الكوارث. ويصمم وينفذ برامج اختبار فعالية الضوابط، وينتج تقارير النتائج مع تحليل الفجوات وتوصيات المعالجة المصنفة حسب المخاطر. ويقود إدارة مخاطر أمن المعلومات للأطراف الثالثة، بتصميم أطر التقييم، وإجراء مراجعات متعمقة للموردين، والحفاظ على سجل مخاطر الأطراف الثالثة. وينتج تقارير مخاطر عالية الجودة للمستوى التنفيذي مع تحليل الاتجاهات، وتحديد المخاطر الناشئة، وتتبع تقدم معالجة المخاطر لاستهلاك الإدارة العليا واللجان.
تسليم برنامج الامتثال
يقود أنشطة مراقبة الامتثال لـ CFFR وNCA ECC وPDPL وISO 27001 وPCI-DSS، وينتج تحليلات الفجوات وخطط المعالجة وتقارير الحالة الدورية للامتثال. ويدير دورات التدقيق الداخلي والخارجي، ويتنسيق جمع الأدلة، ويراجع جودة الأدلة، ويتفاعل مع المدققين، ويتابع معالجة أوجه القصور حتى الإغلاق. ويصمم وينفذ برنامج التوعية الأمنية، وينتج محتوى مستهدف لفئات مختلفة من الموظفين، ويجري جلسات توعية، ويحلل مؤشرات الفعالية. ويطور ويحافظ على لوحات معلومات مؤشرات أداء برنامج الحوكمة وإدارة المخاطر والامتثال، ويضمن قياس مؤشرات الأداء الرئيسية ومؤشرات المخاطر الرئيسية بدقة وعرضها على الإدارة العليا في الوقت المحدد. ويقود دمج متطلبات أمن المعلومات في عقود الأطراف الثالثة، وعمليات المشتريات، وعلى متن المشاريع الرئيسية. ويساهم في تطوير استراتيجية برنامج أمن المعلومات، ويحدد فرص تحسين القدرات ويوصي بfirstويات الاستثمار للمسؤول.
التعاون عبر الوظائف والقيادة المعرفية في الحوكمة وإدارة المخاطر والامتثال
يكون مسؤول الحوكمة وإدارة المخاطر والامتثال الرئيسي للنقطة الأساسية للفرق المخصصة من الأعمال والتكنولوجيا، ويقدم التوجيه الخبير بشأن متطلبات الأمن، ومعالجة المخاطر، والتزامات الامتثال. ويقود مراجعات تصنيف المعلومات ومتطلبات الأمن للمشاريع التكنولوجية والمنتجات والأعمال الهامة. ويساهم في قاعدة المعرفة الخاصة بالحوكمة وإدارة المخاطر والامتثال، ويطور قوالب قابلة لإعادة الاستخدام، ووثائق إرشادية، ومواد تدريبية للاستخدام الداخلي. ويمثل وظيفة الحوكمة وإدارة المخاطر والامتثال في المجموعات العاملة عبر الوظائف، ولجان توجيه المشاريع، ومسارات العمل التنظيمية. وينفذ المهام الإضافية المسندة إليه من قبل الإدارة.
الملف الشخصي المرغوب للمرشح
حاصل على درجة البكالوريوس في تكنولوجيا المعلومات أو علوم الحاسب أو هندسة البرمجيات أو الأمن السيبراني أو إدارة المخاطر أو مجال ذي صلة. وتعد درجة الماجستير في أمن المعلومات أو إدارة المخاطر أو إدارة الأعمال ميزة إضافية. 3 إلى 5 سنوات من الخبرة المهنية المتقدمة في حوكمة أمن المعلومات أو إدارة المخاطر أو الامتثال. إثبات خبرة في قيادة دورات تقييم المخاطر أو برامج الامتثال التنظيمي أو أنشطة تنسيق التدقيق بشكل مستقل. المعرفة العميقة بإطار CFFR مطلوبة. ويُفضل بشدة وجود خبرة في بيئة مصرفية أو قطاع مالي تقني منظم.