← All jobs

Cybersecurity GRC Manager

Hala

Easy apply
Location
Riyadh, SA
Work mode
On-site
Seniority
Mid
Sector
Startup
Posted
September 20, 2026

Job description

Who Are We


HALA is a leading fintech player in the MENAP region that aims to redefine financial services and build the future bank of SMEs. HALA aims at empowering SMEs to start, run, and grow their businesses by providing them with cutting-edge financial and technological tools.


HALA currently holds multiple entities in UAE, Saudi Arabia and Egypt (including HALA Payments and HALA Logistics) and offers solutions that enable merchants to digitize their payments as well as manage their sales and operations.


Founded in 2017, HALA is currently licensed by the Saudi Arabian Central Bank.

 

Responsibilities 
 

Governance & Strategy:

     Develop, implement, and continuously improve the organization's Information Security Governance framework, policies, standards, and procedures.

     Lead the creation and execution of the Cyber Security Strategy in alignment with the company's overall business goals.

     Providing regular reports to the Board of Directors and executive management on the state of cybersecurity.

     Establish and manage a security metrics and Key Performance Indicator (KPI) program to measure the effectiveness of the security program and report on progress.

     Oversee the information security budget, ensuring resources are allocated effectively to manage risk.

  Risk Management:

     Design and manage a comprehensive enterprise-wide Cyber Security Risk Management program.

     Conduct regular risk assessments, including Business Impact Analysis (BIA), to identify, analyze, and evaluate information security risks.

     Facilitate risk treatment planning with business and technology owners, ensuring appropriate mitigation, acceptance, or transfer strategies are implemented.

     Manage the vendor risk management program, assessing the security posture of third-party vendors and partners, especially cloud service providers and payment gateways.

     Integrate risk management into the Software Development Life Cycle (SDLC) and change management processes.

    

Regulatory Compliance:

     Serve as the primary point of contact and subject matter expert for all regulatory examinations and audits related to cybersecurity (e.g., SAMA, CMA).

     Ensure continuous compliance with SAMA's Cyber Security Framework (CSF), Payment Card Industry Data Security Standard (PCI DSS) requirements, and other relevant regulations.

     Manage the process for obtaining and maintaining necessary regulatory licenses and certifications from a cybersecurity perspective.

     Prepare and submit accurate and timely regulatory reports, questionnaires, and evidence requests.

     Monitor the regulatory landscape for changes in laws, regulations, and standards, and proactively advise the business on required adjustments.

    

Audit & Assurance:

     Manage all internal and external security audits, including coordinating with auditors, providing evidence, and tracking remediation of findings.

     Develop and maintain a robust control testing program to validate the effectiveness of key security

Apply directly at Hala