About Bede
Bede, a Zain Fintech company launched in Sudan in April 2025, is dedicated to delivering innovative and secure digital financial solutions that enhance financial accessibility and convenience for individuals, businesses, and institutions. Through its digital wallet and expanding fintech ecosystem, the company provides integrated payment, transfer, and merchant services across Sudan. At Zain Fintech, we are committed to building trusted, accessible, and customer-centric financial solutions that contribute to the digital transformation and financial inclusion of Sudan.
Position Information
Division:Technology
Department/Section: Technology
Job Title: Risk Management & Information Security Advanced Specialist
Reports To: FinTech Technology Manager
About the Role
To lead the development and implementation of risk management and information security strategies within the technology sector for Zain FinTech. This role ensures the organization identifies, assesses, and mitigates risks associated with technology and financial operations, while maintaining compliance with regulatory standards. The job holder will foster a culture of security awareness and collaboration, enhancing overall resilience against potential threats.
Key Tasks /Accountabilities:
* Develop, implement, and maintain enterprise risk management frameworks, policies, and procedures for fintech operations.
* Assess and monitor risks associated with digital payment services, mobile money platforms, digital wallets, merchant acquiring, and electronic payment ecosystems.
* Evaluate transaction risks and recommend controls to ensure secure and reliable payment operations.
* Conduct risk assessments for new fintech products, services, partnerships, and digital initiatives.
* Maintain risk registers and track mitigation plan to ensure key risks are effectively managed.
* Monitor key risk indicators (KRIs) and provide regular risk reports to management.
* Provide risk and information security guidance during the design, development, and implementation of fintech products, digital platforms, and technology initiatives to ensure security-by-design and compliance-by-design principles are embedded throughout the project lifecycle.
* Support business continuity, disaster recovery, and operational resilience initiatives.
* Conduct root cause analysis of risk incidents and recommend corrective actions.
* Develop and enforce information security policies, standards, and controls across fintech systems and operations.
* Monitor information security risks and ensure the confidentiality, integrity, and availability of organizational data.
* Conduct information security assessments, vulnerability reviews, and security control evaluations.
* Support the implementation and maintenance of cybersecurity frameworks and best practices.
* Monitor security incidents and coordinate investigations, remediation activities, and lessons learned.
* Ensure secure management of customer, transaction, and organizational information assets.
* Promote security awareness and secure working practices across the organization.
* Monitor compliance with fintech regulations and cybersecurity requirements.
* Support regulatory audits and examinations.
* Ensure compliance with data privacy and protection requirements.
* Oversee incident response strategies and ensure effective resolution of security breaches or risks.
* Develop fraud prevention and detection mechanisms across digital channels and payment systems.
* Monitor suspicious transactions and coordinate investigations of potential fraud incidents.
* Conduct fraud risk assessments and recommend preventive controls.
* Collaborate with operational teams to strengthen anti-fraud controls and monitoring processes.
* Collaborate with internal and external stakeholders to align risk management initiatives with business objectives.
* Support management in strategic decision-making by providing risk-based recommendations.
* Conduct training programs to promote security awareness among employees.
* Ensure compliance with all applicable policies & regulatory requirements in information security.
Qualifications/Experience/Skills
Qualifications/Experience: -
- B.Sc. in Information Technology, Cybersecurity, Computer Science, Information Technology, Risk Management, or a related field.
- Minimum 3 years of experience in Information Security, Cybersecurity, Risk Management, or Governance, Risk & Compliance (GRC).
- Proven experience in conducting enterprise risk assessments, information security assessments, and control reviews.
- Experience in developing and implementing risk management frameworks, information security policies, standards, and procedures.
- Professional certifications such as CISSP, CISM, CISA, CRISC, or ISO 27001 are highly desirable.
- Experience with digital payments, mobile money, fraud risk management, and information security governance is preferred.
Skills: -
- Ability to interpret and apply best practice methods/processes.
- Highly developed communication and presentation skills (verbal and written) in both Arabic and English, including the ability to communicate and present effectively with various levels as well as top management.
- Hands on strong project management skills.
- Critical analytical thinking and problem solving.
- Ability to build excellent relationships with key suppliers/customers.
- Third party and vender management.
- Planning and organization skills.
- Able to persuade and influence senior manager and employee levels.
- Highly developed skills in use of relevant IT packages including Excel. Word, PowerPoint etc.
- Highly developed reporting skills, metrics, and analytics, including dashboard creation for executive leadership and board reporting.