About Flooss
AL-AN Alkhaligia for Consumer Microfinance Company (Flooss) provides consumer microfinance solutions in Saudi Arabia and operates in the regulated financial sector under the supervision of the Saudi Central Bank (SAMA).
We are building a customer-focused, technology-enabled, and well-governed organization, and we are looking for leaders who will help shape its next stage of growth.
Role Purpose
Lead the Company's independent Cybersecurity function and protect the Company's information assets, customer data, and digital services against cyber threats, while ensuring full compliance with SAMA and other applicable regulatory requirements.
The CISO will own the cybersecurity strategy, governance framework, risk management, and security operations, and will partner closely with the IT Manager, Risk, Compliance, and executive management to embed security across the business.
Key Responsibilities
1. Cybersecurity Strategy & Governance
- Define and execute the cybersecurity strategy and roadmap in alignment with the Company's business strategy and risk appetite.
- Establish and maintain the cybersecurity governance framework, policies, standards, and procedures.
- Prepare and manage the cybersecurity budget and investment priorities.
- Chair or support the Cybersecurity Steering Committee and report cybersecurity posture, risks, and key metrics to executive management, the Board, and relevant committees.
- Maintain the independence of the Cybersecurity function from IT operations, in line with SAMA requirements.
2. Cyber Risk & Regulatory Compliance
- Ensure compliance with the SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, and other applicable regulations and standards.
- Identify, assess, and manage cybersecurity risks across systems, processes, projects, and third parties.
- Conduct periodic cybersecurity maturity self-assessments and drive remediation plans.
- Lead the cybersecurity aspects of regulatory examinations and internal and external audits, and ensure timely closure of findings.
- Monitor regulatory developments and update the Company's cybersecurity controls accordingly.
3. Security Operations & Incident Response
- Oversee security monitoring and threat detection, whether through an in-house or outsourced Security Operations Center (SOC).
- Lead cyber incident response, investigation, and reporting to SAMA and other authorities within required timelines.
- Manage vulnerability management, penetration testing, and threat intelligence programs.
- Ensure cyber resilience is integrated into Business Continuity and Disaster Recovery plans and tested regularly.
- Oversee identity and access management, including privileged access controls.
4. Security Architecture & Data Protection
- Define security architecture standards and ensure secure-by-design principles across infrastructure, cloud, applications, APIs, and digital channels.
- Review and approve the security of new systems, integrations, changes, and technology projects before go-live.
- Lead data protection controls in coordination with the Data Protection Officer, in line with the Personal Data Protection Law (PDPL).
- Oversee application security, including secure development practices and security testing of mobile and web channels.
- Ensure controls are in place to prevent fraud and protect customer data and transactions.
5. Third Parties, Awareness & People Management
- Assess and monitor the cybersecurity posture of vendors and outsourcing arrangements, in line with SAMA outsourcing requirements.
- Define cybersecurity requirements in contracts and service level agreements with third parties.
- Lead cybersecurity awareness and training programs for employees, management, and the Board.
- Lead, coach, and develop the cybersecurity team.
- Build succession plans and develop national cybersecurity talent.
Qualifications & Experience
Education
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
- Master's degree in Cybersecurity, Information Security, or an MBA is preferred.
Experience
- Minimum 10 years of experience in cybersecurity or information security.
- At least 5 years in a cybersecurity leadership role.
- Experience in financial services, fintech, or consumer finance is required.
- Proven experience leading a cybersecurity function within a SAMA-regulated entity is preferred.
Professional Certifications
- CISSP, CISM, or equivalent senior cybersecurity certification is required.
- CISA, CRISC, ISO 27001 Lead Implementer/Auditor, and relevant cloud security certifications (e.g., CCSP) are an advantage.
Technical Skills
Strong knowledge and practical experience in:
- Cybersecurity governance, risk, and compliance (GRC)
- Security operations, SOC, and incident response
- Cloud, network, and application security
- Identity and access management (IAM/PAM)
- API and digital channel security
- Vulnerability management and penetration testing
- Data protection and data loss prevention
- Third-party cybersecurity risk management
- Cyber resilience, Business Continuity, and Disaster Recovery
Regulatory & Compliance Knowledge
- In-depth knowledge of the SAMA Cyber Security Framework and SAMA outsourcing requirements.
- Knowledge of NCA cybersecurity controls and the Personal Data Protection Law (PDPL).
- Familiarity with international standards such as ISO 27001, NIST, and PCI DSS.
- Experience leading regulatory examinations and audits.
Languages
- Fluent in Arabic and English.
Nationality