Hiring.Camp

Senior Specialist, Information Security (GRC)

Tabby

·

6 days ago

Location
UAE
Type
Full-time
Department
Security
Seniority
Senior
Education
Master
Source
Pinpoint

Description

Senior Specialist, Information Security (GRC)

Department: InfoSec GRC

Employment Type: Full Time

Location: UAE

Reporting To: Rajat Rao



Description

About us:

Tabby is on a mission to give people power over their money. For too long, financial systems have worked for the institutions that built them, not the people using them. Runaway interest, fine print and limited access have left many behind, feeling shut out of a system that wasn't setting them up for success.

We're building a different kind of system—in a complete money app to send, spend and save. One that's clear, flexible and puts people and businesses in control. Founded in 2019, we serve customers and businesses across Saudi Arabia, the United Arab Emirates and Kuwait. Millions of customers and 65,000 global brands, government services and small businesses rely on us today.

What began as a better way to pay at checkout has grown into a financial system working the way it should have all along.

About the role:

The Senior Information Security Specialist (GRC) independently leads complex governance, risk, and compliance activities and serves as a subject matter expert in one or more GRC domains — enterprise information security governance, risk management frameworks, regulatory compliance, or third-party risk management. 

The role produces high-quality GRC deliverables, provides technical mentoring to junior and mid-level team members, and contributes directly to the continuous improvement of the organization's GRC framework, risk treatment processes, and compliance reporting mechanisms. The Senior Specialist bridges technical execution and programme leadership, collaborating with leads, legal, audit, and business stakeholders to deliver mature, effective GRC outcomes aligned with the UAE Fintech regulatory environment. 


Key Responsibilities

Information Security Governance Leadership:
  • Lead the development, review, and continuous improvement of information security policies, standards, procedures, and governance frameworks, ensuring alignment with CSF, NCA ECC, ISO 27001, and PCI-DSS.
  • Serve as the subject matter expert for assigned regulatory domains, providing authoritative interpretation of requirements and translating them into implementable control objectives.
  • Monitor and proactively track regulatory and legal developments affecting information security, assessing impact and recommending updates to the governance framework.
  • Prepare and review governance documentation (RACI matrices, security charter updates, governance committee packs) and present findings to senior stakeholders.
  • Lead the preparation of regulatory self-assessments and compliance attestations, coordinating evidence gathering and quality-reviewing submissions before senior sign-off.
  • Mentor junior team members on governance documentation quality, regulatory interpretation, and risk assessment methodology.
Enterprise Risk Management:
  • Lead the execution of complex enterprise information security risk assessments, applying advanced qualitative and quantitative methodologies to produce risk profiles aligned with the organisation's risk appetite.
  • Own and maintain the enterprise information security risk register, ensuring accuracy, currency, and appropriate escalation of significant risks.
  • Lead BIA processes for critical business functions, coordinating with asset owners, analysing recovery requirements, and producing BIA outputs for Business Continuity and Disaster Recovery planning.
  • Design and execute control effectiveness testing programmes, producing findings reports with gap analysis and risk-ranked remediation recommendations.
  • Lead third-party information security risk management, designing assessment frameworks, conducting in-depth vendor reviews, and maintaining the third-party risk register.
  • Produce executive-quality risk reporting with trend analysis, emerging risk identification, and treatment progress tracking for senior management and committee consumption.
Compliance Programme Delivery:
  • Lead compliance monitoring activities for CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS, producing gap analyses, treatment plans, and periodic compliance status reports.
  • Manage internal and external audit cycles, coordinating evidence collection, reviewing evidence quality, engaging with auditors, and tracking remediation to closure.
  • Design and deliver the security awareness programme, producing targeted content for different staff segments, conducting awareness sessions, and analysing effectiveness metrics.
  • Develop and maintain GRC programme metrics dashboards, ensuring KPIs and KRIs are accurately measured and presented to senior management on schedule.
  • Lead the integration of information security requirements into third-party contracts, procurement processes, and major project onboarding.
  • Contribute to the development of the information security programme strategy, identifying capability improvement opportunities and recommending investment priorities to the Lead.

Cross-Functional Collaboration & Knowledge Leadership:
  • Serve as the primary GRC point of contact for assigned business and technology teams, providing expert guidance on security requirements, risk treatment, and compliance obligations.
  • Lead information classification and security requirements reviews for significant IT, product, and business projects.
  • Contribute to the GRC knowledge base, developing reusable templates, guidance documents, and training materials for internal use.
  • Represent the GRC function in cross-functional working groups, project steering committees, and regulatory workstreams.


Skills, Knowledge and Expertise


Education:
  • Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
  • A Master's degree in Information Security, Risk Management, or Business Administration is an advantage.
Experience:
  • 3+ years of progressive professional experience in information security governance, risk management, or compliance.
  • Demonstrable experience independently leading risk assessment cycles, regulatory compliance programmes, or audit coordination activities.
  • In-depth knowledge of at least two regulatory frameworks applicable to Fintech environments (CSF, NCA ECC, PDPL, ISO 27001, PCI-DSS) is required.
  • Experience in a regulated Fintech or banking environment is strongly preferred.
Certifications & Licences:
  • ISO 27001 Lead Implementer (required).
  • CRISC (Certified in Risk and Information Systems Control) or CISM: required or actively working toward.
  • CDPSE (Certified Data Privacy Solutions Engineer) is an advantage for PDPL specialists.


Benefits

  • A working environment that gives you autonomy and responsibility from day one.
  • You should be comfortable with the idea that the quality of your work will influence the shape of your career.
  • Participation in the company’s employee stock options program.
  • Health Insurance
  • Flexi Perks: A monetary benefit that gives you the freedom to use it as you choose—whether for health and well-being, education and professional development or travel needs!

Skills

CybersecurityRisk ManagementComplianceProcurementISO 27001

Similar Jobs

30

Sr. Medical Information Communication Specialist

Bristolmyerssquibb·Field - China

Today

Sr. Medical Information Communication Specialist

Bristol Myers Squibb·Hohhot, CN

Today

Information Management / eDiscovery Specialist Senior

Gdit·USA VA Falls Church - 3150 Fairview Park Dr, US·Remote, Hybrid

1d ago

Information Management / eDiscovery Specialist Senior

GDIT·USA VA Falls Church - 3150 Fairview Park Dr, US·Remote, Hybrid

1d ago

Technology Manager (Senior Information Technology Specialist, Grade N28)

Montgomery County Government·100 Edison Park Dr Gaithersburg MD 20878 USA, MD·Hybrid

3d ago

Senior Information Security Specialist

Cibc·Toronto-141 Bay, 16th Floor·Remote, Hybrid, Onsite

3d ago

Senior Public Information Specialist

Slihrms·US.AL.Vestavia Hills, US

6d ago

Information Security Specialist (Senior-Level)

" Link Solutions, Inc."·Orlando, FL

1w ago

Senior Specialist, Information Security Analyst

0101022-GIA PROD US LOS ANGELES·Pittsburgh, PA

2w ago

SENIOR PUBLIC INFORMATION SPECIALIST

COUNTY OF LOS ANGELES·Los Angeles County, CA

2w ago

Sotyktu Sr. Medical Information Communication Specialist

Bristol Myers Squibb·Hangzhou, CN

2w ago

Sotyktu Sr. Medical Information Communication Specialist

Bristolmyerssquibb·Field - China

2w ago

Senior Medical Information Communication Specialist

Bristolmyerssquibb·Field - China

3w ago

Senior Medical Information Communication Specialist

Bristol Myers Squibb·Xi'An, CN

3w ago

Field Support Specialist-Senior _ Division of Information Systems

Ummc·Jackson, MS - Main Campus

3w ago

Senior Specialist, Information Operations

Nextgen·Remote MD, US·Remote

1mo ago

Senior Computer and Information Systems Engineer Specialist

Concurrent Technologies Corporation·Huntsville, AL

1mo ago

Information Management Specialist (Technical), Senior

Peraton·Camp H.M. Smith, HI·Onsite

1mo ago

Senior Health Information Specialist

Dartmouth Hitchcock·Lebanon, NH

1mo ago

Senior Specialist Information Security

Infineon·Malacca, MY +1

1mo ago

Senior Information Systems Security Specialist

Nwis·VA543: 22270 Pacific Blvd, VA·Remote, Onsite

2mo ago

Senior Library Information Specialist (Persian/Farsi)

LAC Federal·Dayton, OH

2mo ago

Senior Library Information Specialist (Chinese - NASIC)

LAC Federal·Dayton, OH

2mo ago

Senior Information Security Specialist

PEMCCO·Washington, District of Columbia

2mo ago

Senior Library Information Specialist (Russian)

LAC Federal·Dayton, OH

2mo ago

Information Technology Senior Specialist

Qvest.Us·Anywhere in the USA·Remote

3mo ago

Senior Information Security Specialist (German-speaking)

Secfix·Remote-Europe·Remote

3mo ago

Senior Classified Security Information Technology (IT) Solutions Specialist

Boeing·USA - Arlington, VA +15·Hybrid

3mo ago

Senior Systems Administrator (Information Systems Specialist 7)

Oregon Job Opportunities·Salem, OWRD·Remote, Hybrid, Onsite

3mo ago

MAINTENANCE MANAGEMENT INFORMATION SYSTEMS SPECIALIST (PLANNER VI) (SR-26) [1 vacancy]

City and County of Honolulu·Oahu, HI

4mo ago