
Tawantech
IT Risk Management Specialist
- Permanent
- Riyadh, Saudi Arabia
- Experience 5 - 10 yrs
Job expiry date: 20/04/2026
Job overview
Date posted
06/03/2026
Location
Riyadh, Saudi Arabia
Salary
SAR 20,000 - 30,000 per month
Compensation
Job description
IT Risk Management role responsible for identifying, assessing, monitoring, and reporting IT and Cyber risks to ensure regulatory compliance and protect the bank’s technology environment in alignment with enterprise risk management within a banking or financial services context in Saudi Arabia. The position develops and maintains the IT Risk Management Framework and IT Risk Register, defines and monitors IT Risk Appetite and Key Risk Indicators (KRIs), and conducts comprehensive IT and Cyber risk assessments across applications, infrastructure, cloud environments, cybersecurity controls, and third-party technology providers. The role performs inherent risk and residual risk analysis to evaluate exposure levels and control effectiveness, while ensuring compliance with key regulatory and international frameworks including the Saudi Central Bank Cybersecurity Framework (SAMA CSF), National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC), International Organization for Standardization ISO 27001, ISACA COBIT, and PCI Security Standards Council PCI-DSS. Responsibilities include monitoring remediation plans and evaluating control effectiveness across the bank’s IT environment, preparing IT Risk reports and risk dashboards for Senior Management, Risk Committee, and Board-level oversight, managing third-party IT risk assessments, and supporting internal audits and regulatory audits. The role requires experience managing an IT Risk Register and leveraging Governance, Risk, and Compliance (GRC) platforms including RSA Archer, ServiceNow GRC, MetricStream, and AuditBoard to track risks, controls, and remediation activities. Candidates are expected to possess strong IT and Cyber Risk assessment capabilities and hold or pursue professional certifications such as CISA, CISM, CRISC, or CISSP, with strong exposure to regulatory frameworks used within the banking sector in Saudi Arabia.
Required skills
Key responsibilities
- Develop and maintain the IT Risk Management Framework and IT Risk Register to identify, document, and manage technology and cybersecurity risks across applications, infrastructure, cloud environments, cybersecurity controls, and third-party providers
- Define, track, and monitor IT Risk Appetite and Key Risk Indicators (KRIs) while performing inherent risk and residual risk analysis to evaluate exposure levels and determine risk mitigation strategies
- Conduct comprehensive IT and Cyber risk assessments across banking technology systems including applications, infrastructure, cloud platforms, cybersecurity environments, and third-party service providers
- Ensure regulatory compliance with Saudi Central Bank Cybersecurity Framework (SAMA CSF), National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC), ISO 27001, ISACA COBIT, and PCI-DSS standards across the organization’s IT environment
- Monitor remediation plans, validate control effectiveness, manage third-party IT risk assessments, and support internal audits and regulatory audits related to IT risk and cybersecurity compliance
- Prepare and present IT Risk reports, risk dashboards, and risk posture updates for Senior Management, Risk Committee, and Board to support enterprise risk management and regulatory oversight
Experience & skills
- Demonstrate 8+ years of experience in IT Risk or Cyber Risk management within banking or financial services environments, preferably in Saudi Arabia
- Manage and maintain an IT Risk Register and perform IT and Cyber risk assessments across applications, infrastructure, cloud environments, cybersecurity controls, and third-party technology providers
- Ensure regulatory compliance and risk governance aligned with Saudi Central Bank Cybersecurity Framework (SAMA CSF) and National Cybersecurity Authority Essential Cybersecurity Controls (NCA ECC)
- Utilize Governance Risk and Compliance platforms including RSA Archer, ServiceNow GRC, MetricStream, or AuditBoard to manage IT risk documentation, monitoring, and remediation workflows
- Support internal audits and regulatory audits and demonstrate strong regulatory audit exposure within banking IT environments
- Hold or pursue professional certifications such as CISA, CISM, CRISC, or CISSP and demonstrate strong IT and Cyber risk assessment expertise