Information Security Specialist
AI in this role
Key Responsibilities
Information Security Governance- Maintain and update the information security governance framework documentation, policy library, and associated standards and procedures.
- Draft and revise information security policies, standards, and baselines, ensuring alignment with applicable regulatory requirements and business objectives.
- Monitor and track changes in legal, regulatory, and contractual requirements affecting information security (SAMA CSF, PDPL, NCA ECC, PCI-DSS), updating the compliance register accordingly.
- Maintain and update role and responsibility matrices (RACI), information security governance committee documentation, and reporting packs.
- Coordinate security governance committee meetings — preparing agendas, minutes, and action tracking.
- Produce internal and external communication materials related to information security governance, policies, and programme updates.
- Execute information security risk assessments independently, applying the organization's risk assessment methodology and producing complete risk registers with identified threats, vulnerabilities, likelihood, impact, and treatment plans.
- Maintain and update the information asset register — tracking asset owners, classifications, and associated risk profiles.
- Lead business impact assessment (BIA) data collection activities, coordinating with asset owners and business units to capture accurate recovery objectives and criticality ratings.
- Conduct control effectiveness evaluations for key information security controls, documenting findings and escalating gaps to the Lead for treatment.
- Coordinate third-party information security risk assessments — preparing assessment questionnaires, reviewing vendor responses, and producing risk summaries.
- Integrate risk and vulnerability data into procurement reviews, project onboarding, and change management processes.
- Prepare periodic risk reports for senior review, highlighting emerging risks, significant changes in the risk profile, and the status of risk treatment actions.
- Monitor the organization's compliance posture against SAMA CSF, NCA ECC, PDPL, ISO 27001, and PCI-DSS — tracking control status, identifying gaps, and coordinating remediation.
- Coordinate internal and external audit activities — gathering evidence packages, liaising with auditors, tracking findings, and monitoring remediation progress.
- Support the preparation of regulatory submissions, self-assessments, and compliance attestations required by SAMA, NCA, and PCI Council.
- Maintain and enhance the security awareness programme — developing training materials, scheduling communications, and tracking completion metrics.
- Monitor KPIs and KRIs for the information security programme, preparing accurate and timely dashboards for senior management review.
- Support the integration of information security requirements into procurement, project management, and change control processes.
- Maintain the information security policy, standard, and procedure library — managing version control, review cycles, and distribution.
- Support information security initiatives across business and technology teams, providing GRC subject matter expertise on projects and change programmes.
- Conduct information classification reviews and document security requirements for key business and IT projects.
- Deliver information security awareness sessions and materials to targeted staff groups.
- Provide analytical support for GRC team reporting, data gathering, and programme tracking activities.
Skills, Knowledge and Expertise
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
- 1–3 years of professional experience in information security governance, risk management, compliance, or a closely related field. Hands-on experience with risk assessment execution, policy development, or compliance monitoring is required. Prior exposure to SAMA CSF, ISO 27001, PDPL, or NCA ECC requirements is a strong advantage. Experience in a regulated Fintech or banking environment is preferred.
- ISO 27001 Foundation or Lead Implementer (preferred). CompTIA Security+ or equivalent.
- Working toward CRISC (Certified in Risk and Information Systems Control) or CISM.
How we rate this
Information Security Specialist at Tabby rates 35 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Classification
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new AI jobs by email
One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
BT Customer Site, BT Customer Site, United Kingdom | Site D, Sinfin, Derby, United Kingdomjust now
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step