IT Governance Senior Officer
الوصف الوظيفي
Position Overview
The IT Governance Senior Officer plays a pivotal role in establishing, enhancing, and sustaining a robust IT governance framework that ensures technology initiatives are seamlessly aligned with organizational objectives, regulatory mandates, and risk tolerance levels. This position is instrumental in providing comprehensive oversight of IT controls, compliance protocols, and performance metrics, thereby fostering transparent decision-making, proactive risk mitigation, and the consistent delivery of high-quality IT services within the fintech and regulatory landscape. The role demands adherence to stringent frameworks such as SAMA guidelines, ISO standards, and other industry-recognized benchmarks to uphold operational excellence and regulatory compliance.
Key Responsibilities
IT Governance Framework and Policy Development
- Design, implement, and maintain a dynamic IT governance framework, encompassing policies, standards, procedures, and guidelines that align with SAMA IT Governance Framework (ITGF), SAMA Outsourcing Framework, COBIT, ITIL, ISO/IEC 27001, and local regulatory requirements;
- Ensure the continuous review and updating of governance artefacts to reflect evolving business needs, technological advancements, and regulatory changes;
- Facilitate the dissemination, comprehension, and adoption of IT governance principles across all IT and business units through targeted communication strategies and training initiatives.
IT Risk, Control, and Compliance Oversight
- Collaborate with Risk, Information Security, and cross-functional stakeholders to identify, assess, and address IT risks, integrating these efforts with the broader enterprise risk management framework;
- Oversee the design, implementation, and effectiveness of IT controls, ensuring alignment with internal policies and external regulatory obligations;
- Monitor compliance with established standards, track remediation of identified gaps, and address audit findings in a timely and systematic manner.
Performance Management and Reporting
- Define, track, and analyze key performance indicators (KPIs) and key risk indicators (KRIs) related to IT governance, service delivery, and compliance;
- Prepare and present comprehensive governance reports and interactive dashboards for IT leadership, risk committees, and, where applicable, the Board or its sub-committees, ensuring clarity and actionable insights;
- Escalate critical issues and deviations to senior management for prompt resolution and strategic decision-making.
Audit, Assessment, and Assurance Coordination
- Coordinate and manage internal and external IT audits, regulatory inspections, and independent assessments, including evidence collection, response formulation, and follow-up actions;
- Maintain a centralized repository of audit observations, corrective action plans, and closure evidence to ensure full accountability and continuous improvement;
- Drive the implementation of corrective and preventive measures to address identified deficiencies and enhance operational resilience.
Governance of Change, Projects, and Vendors
- Provide governance oversight for IT projects and change initiatives, ensuring adherence to architectural principles, security protocols, compliance gates, and documentation standards;
- Contribute to the governance of critical IT vendors and outsourced services, verifying that contracts, service level agreements (SLAs), and performance evaluations incorporate governance, risk, and compliance expectations;
- Monitor vendor performance and conduct periodic reviews to ensure alignment with organizational and regulatory requirements.
Awareness, Training, and Continuous Improvement
- Champion a culture of IT governance excellence by promoting awareness through structured training programs, workshops, and targeted communications;
- Identify opportunities for process optimization and innovation to enhance the effectiveness and efficiency of the IT governance framework;
- Collaborate with stakeholders to drive continuous improvement initiatives that support organizational growth and regulatory adherence.
Qualifications and Experience
To excel in this role, candidates must possess the following qualifications and experience:
- A Bachelor’s degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Business Administration, or a related discipline;
- A minimum of five years of progressive experience in IT Governance, IT Risk Management, IT Compliance, IT Audit, or Information Security Governance;
- Proven track record within banking, fintech, financial services, or other highly regulated industries;
- In-depth knowledge of IT governance frameworks, risk management principles, IT controls, and compliance protocols;
- Hands-on expertise with COBIT, ITIL, ISO/IEC 27001, SAMA IT Governance Framework, SAMA Cybersecurity Framework, and SAMA Outsourcing Framework;
- Extensive experience in coordinating internal and external IT audits and regulatory assessments;
- Strong understanding of IT service management, project governance, and vendor governance principles;
- Exceptional analytical acumen, meticulous documentation skills, and the ability to prepare clear and concise reports;
- Outstanding stakeholder management capabilities, with the ability to engage effectively at all organizational levels.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.