IT Risk Management

TAWANTECH

📍 Riyadh, Riyadh Province, Saudi Arabia

Full time Computer Occupations Posted March 01, 2026

Job Description

Role Purpose

Responsible for identifying, assessing, monitoring, and reporting IT and Cyber risks to ensure regulatory compliance and protect the bank’s technology environment in alignment with enterprise risk management.

Key Responsibilities

  • Develop and maintain IT Risk Management Framework and IT Risk Register
  • Define and monitor IT Risk Appetite and KRIs
  • Conduct IT & Cyber risk assessments across applications, infrastructure, cloud, cybersecurity, and third parties
  • Perform inherent and residual risk analysis
  • Ensure compliance with:
    • Saudi Central Bank Cybersecurity Framework (CSF)
    • National Cybersecurity Authority Essential Cybersecurity Controls (ECC)
    • International Organization for Standardization ISO 27001
    • ISACA COBIT
    • PCI Security Standards Council PCI-DSS
  • Monitor remediation plans and control effectiveness
  • Prepare ...