Lead Anti-Fraud Officer
AI in this role
The Lead Anti-Fraud Officer operates as a bridge between technical execution and programme leadership — collaborating with leads, legal, audit, and business stakeholders to drive mature and effective GRC outcomes aligned with the Saudi Fintech regulatory environment.
Key Responsibilities
- Lead the development, review, and continuous improvement of information security policies, standards, procedures, and governance frameworks.
- Serve as the subject matter expert for assigned regulatory domains, providing authoritative interpretation of requirements and translating them into implementable control objectives.
- Monitor and proactively track regulatory and legal developments affecting information security — assessing impact and recommending updates to the governance framework.
- Prepare and review governance documentation — RACI matrices, security charter updates, governance committee packs — and present findings to senior stakeholders.
- Lead the preparation of regulatory self-assessments and compliance attestations, coordinating evidence gathering and quality-reviewing submissions before senior sign-off.
- Mentor GR1–GR2 team members on governance documentation quality, regulatory interpretation, and risk assessment methodology.
Enterprise Risk Management
- Lead the execution of complex enterprise information security risk assessments, applying advanced qualitative and quantitative methodologies to produce risk profiles aligned with the organization's risk appetite.
- Own and maintain the enterprise information security risk register — ensuring accuracy, currency, and appropriate escalation of significant risks.
- Lead BIA processes for critical business functions — coordinating with asset owners, analysing recovery requirements, and producing BIA outputs for Business Continuity and Disaster Recovery planning.
- Design and execute control effectiveness testing programmes, producing findings reports with gap analysis and risk-ranked remediation recommendations.
- Lead third-party information security risk management — designing assessment frameworks, conducting in-depth vendor reviews, and maintaining the third-party risk register.
- Produce executive-quality risk reporting with trend analysis, emerging risk identification, and treatment progress tracking for senior management and committee consumption.
Compliance Programme Delivery
- Lead compliance monitoring activities for CFFR, NCA ECC, PDPL, ISO 27001, and PCI-DSS — producing gap analyses, treatment plans, and periodic compliance status reports.
- Manage internal and external audit cycles — coordinating evidence collection, reviewing evidence quality, engaging with auditors, and tracking remediation to closure.
- Design and deliver the security awareness programme — producing targeted content for different staff segments, conducting awareness sessions, and analysing effectiveness metrics.
- Develop and maintain GRC programme metrics dashboards, ensuring KPIs and KRIs are accurately measured and presented to senior management on schedule.
- Lead the integration of information security requirements into third-party contracts, procurement processes, and major project onboarding.
- Contribute to the development of the information security programme strategy, identifying capability improvement opportunities and recommending investment priorities to the Lead.
Cross-Functional Collaboration & Knowledge Leadership
- Serve as the primary GRC point of contact for assigned business and technology teams — providing expert guidance on security requirements, risk treatment, and compliance obligations.
- Lead information classification and security requirements reviews for significant IT, product, and business projects.
- Contribute to the GRC knowledge base — developing reusable templates, guidance documents, and training materials for internal use.
- Represent the GRC function in cross-functional working groups, project steering committees, and regulatory workstreams.
- Perform additional responsibilities as assigned by management.
Skills, Knowledge and Expertise
- Bachelor's degree in Information Technology, Computer Science, Software Engineering, Cybersecurity, Risk Management, or a related field.
- A Master's degree in Information Security, Risk Management, or Business Administration is an advantage.
- 3–5 years of progressive professional experience in information security governance, risk management, or compliance. Demonstrable experience independently leading risk assessment cycles, regulatory compliance programmes, or audit coordination activities.
- In-depth knowledge of the CFFR framework is required.
- Experience in a regulated Fintech or banking environment is strongly preferred.
How we rate this
Lead Anti-Fraud Officer at Tabby rates 36 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Classification
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new AI jobs by email
One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Other roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step