Cybersecurity Manager
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 3+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Moneymoon
Moneymoon is Saudi Arabia’s first fintech platform offering peer-to-peer microlending with a fully automated and smooth user experience, licensed by the Saudi Central Bank (SAMA). We focus on transparent, safe, and trustworthy one-month lending.
Role Overview
We seek a Cybersecurity Manager, serving effectively as CISO, to oversee the entire cybersecurity function and reinforce our security posture amid rapid growth in a regulated fintech setting. This role merges governance, regulatory compliance with SAMA, cyber risk management, operational security, cloud and application security, incident handling, resilience, and technical supervision.
You will collaborate across departments including Technology, Product, Data & AI, Operations, Compliance, Risk, HR, Finance, and senior leadership, embedding cybersecurity across products, infrastructure, systems, processes, and vendor relationships. Success demands translating cybersecurity and regulatory mandates into actionable controls, measurable progress, and robust security operations.
Why the Role is Critical
- Protects the lending business from fraud, account compromises, identity theft, API threats, and security breaches that could cause direct financial loss.
- Accelerates go-to-market by integrating security early in development, preventing delays from late-stage security reviews.
- Ensures compliance with SAMA cybersecurity regulations vital for business scalability and regulatory clearance.
- Preserves customer trust by safeguarding their identities, financial and personal data.
Core Responsibilities
- Develop, manage, and enhance cybersecurity governance frameworks, policies, standards, controls, and improvement plans aligned with SAMA CSF and related regulatory standards (MVC, CRFR, CFFR, NCA ECC, PDPL, ISO/IEC 27001).
- Lead cybersecurity program maturity, audits, assessments, internal and external regulatory reviews, and ensure prompt remediation of findings.
- Owner of cybersecurity risk management lifecycle including risk identification, assessment, treatment, and reporting, maintaining detailed risk registers with responsible owners and deadlines.
- Measure, automate, and report cybersecurity KPIs and KRIs for senior management transparency.
- Oversee security operations and engineering across cloud platforms, identity and access management, endpoint security, application security, API safeguards, SIEM, and threat detection, including automation and process improvements.
- Collaborate on AI and security automation initiatives to enhance anomaly detection, alert triage, incident response, and safeguard AI/LLMs against leakage, injection, unauthorized access, and misuse.
- Embed security requirements throughout product lifecycle with threat modeling, secure SDLC practices, architecture assessments, and ensuring early security integration.
- Coordinate fraud and verification controls to prevent identity abuse and transaction anomalies, aligning with SAMA Minimum Verification Controls.
- Manage vulnerability lifecycle, penetration testing, incident response preparation, and business continuity and resilience exercises to learn and improve continuously.
- Administer third-party cybersecurity evaluations for vendors, cloud services, and integrations beyond questionnaires, incorporating security clauses into contracts and tracking risk remediation.
- Lead cybersecurity awareness programs to foster security culture and accountability across all employees and throughout their employment lifecycle.
- Design and implement AI-powered cybersecurity defense systems including anomaly detection and automated incident handling with full operational responsibility.
Required Qualifications and Experience
- Three or more years of advancing experience in cybersecurity roles related to security engineering, operations, cyber risk, or information security.
- Hands-on expertise implementing and managing the SAMA Cyber Security Framework and understanding of wider Saudi regulatory landscape including MVC, CRFR, CFFR, NCA ECC, PDPL, and ISO/IEC 27001.
- Practical experience with cloud security in environments like OCI, AWS, Azure, or GCP.
- Experience with cybersecurity governance, risk management processes, security controls in multiple domains (IAM/PAM, cloud, applications, APIs, vulnerability management, SIEM, incident response, endpoint security, and Secure SDLC).
- Proven ability to support audits, regulatory assessments, control testing, and remediation for cybersecurity.
- Strong skills communicating cybersecurity risks and collaborating with technical and business leadership.
- Independent prioritization capabilities and excellent analytical and problem-solving skills.
- Fluent written and spoken English communication.
Preferred Skills
- Experience in fintech, banking, lending, payments, or regulated financial services.
- Involvement in SAMA assessments, regulatory audits, licensing preparation, or cybersecurity remediation projects.
- Knowledge of SAMA BCMF, Operational Resilience, PCI DSS, Business Continuity, Disaster Recovery, or Cyber Resilience.
- Hands-on in fraud detection, transaction monitoring, identity verification, or account-takeover defenses.
- Familiarity with cybersecurity tools such as SIEM, EDR, MDM, IAM/PAM, and vulnerability management.
Industry
FinTech