وصف الوظيفة
المسؤولية عن كبار موظفي حوكمة تكنولوجيا المعلومات هو تطوير وتنفيذ والحفاظ على إطار الحوكمة لتكنولوجيا المعلومات والسياسات والعمليات لضمان مواءمة أنشطة التقنية مع الأهداف التجارية والمتطلبات التنظيمية ومستوى المخاطر.
الدور يوفر إشرافًا على ضوابط IT والامتثال والأداء، مما يمكّن اتخاذ قرارات شفافة، وإدارة مخاطر فعالة، وتوفير خدمات IT بشكل متسق ضمن توقعات الشركات المالية والتشريعية (مثلًا، إرشادات من البنك المركزي السعودي، ومعايير ISO).
• إطار الحوكمة وتطوير السياسات في IT o تطوير، صيانة، ومراجعة دورية لإطار الحوكمة لتكنولوجيا المعلومات، بما في ذلك السياسات والمعايير والإجراءات والإرشادات بما يتوافق مع SAMA ITGF، إطار التعهيد لدى SAMA، COBIT، ITIL، ISO/IEC 27001، والمتطلبات التنظيمية المحلية.
o ضمان أن تكون منتجات الحوكمة IT مطلوبة ومفهومة وتُطبق عبر وحدات IT والأعمال.
• إشراف مخاطر IT والضبط والامتثال o تنسيق تحديد المخاطر في تكنولوجيا المعلومات وتقييمها ومعالجتها بالتعاون مع فريق المخاطر وأمن المعلومات وأصحاب المصلحة المعنيين، مع التأكد من الدمج مع إطار إدارة مخاطر المؤسسة.
o الإشراف على تصميم وفعالية ضوابط IT، ومراقبة الامتثال للسياسات الداخلية واللوائح الخارجية، وتتبع معالجة الثغرات ونتائج التدقيق.
• إدارة الأداء والتقارير IT o تعريف ومراقبة مؤشرات الأداء الرئيسية (KPIs) ومؤشرات الخطر الرئيسية (KRIs) لحوكمة IT، وأداء الخدمة، والامتثال، مع ضمان التحليل الدوري وتصعيد القضايا.
o إعداد تقارير حوكمة ولوحات معلومات واضحة وموجزة لإدارة IT، ولجان المخاطر، وحيثما كان ذلك مناسبًا، المجلس أو لجان المجلس الفرعية.
• التدقيق والتقييم والضمان o تنسيق التدقيقات الداخلية والخارجية لتقنية المعلومات، والفحوص التنظيمية، والتقييمات المستقلة، بما في ذلك الإعداد وجمع الأدلة والردود والإجراءات التالية.
o الحفاظ على مستودع لملاحظات التدقيق وخطط العمل وأدلة الإغلاق، مع تطبيق الإجراءات التصحيحية والوقائية في الوقت المناسب.
• حوكمة التغيير والمشروعات والموردين o دعم حوكمة مشروعات IT وإدارة التغيير (مثال: الالتزام بمبادئ الهندسة، وبوابات الأمن والامتثال، ومعايير التوثيق).
o المساهمة في حوكمة مزودي IT الرئيسيين والخدمات المستعانة بمصادر خارجية، وضمان أن تعكس العقود، وSLA، ومراجعات الأداء توقعات الحوكمة والمخاطر والامتثال.
• التوعية والتدريب والتحسين المستمر o تعزيز الوعي بحوكمة IT والسياسات والممارسات الجيدة من خلال التدريب، وورش العمل، والاتصالات المستهدفة.
الاستمرار في مقارنة الأداء واقتراح تحسينات لعمليات الحوكمة بما يتماشى مع أفضل الممارسات الصناعية والاتجاهات التنظيمية/التكنولوجية الناشئة.
الدرجة الجامعية في علوم الكمبيوتر أو مجال ذو صلة.
5–7 سنوات من الخبرة التقدمية في حوكمة تكنولوجيا المعلومات، إدارة مخاطر IT، تدقيق IT، أو أدوار إدارة IT ذات صلة، ويفضل في قطاع البنوك والمدفوعات والخدمات المالية.
سجل مثبت في تنفيذ والحفاظ على أطر حوكمة IT، إجراء تقييمات وضبط ضوابط IT، والتعاون بفعالية مع الجهات التنظيمية ومراجعي الخارج لضمان الامتثال وتقوية ممارسات الحوكمة.
Job description
The IT Governance Senior Officer is responsible for developing, implementing, and maintaining the IT governance framework, policies, and processes to ensure that technology activities are aligned with business objectives, regulatory requirements, and risk appetite.
The role provides oversight over IT controls, compliance, and performance, enabling transparent decision-making, effective risk management, and consistent delivery of IT services within the fintech and regulatory expectations (e.
g., SAMA guidelines, ISO standards).
• IT Governance Framework and Policies o Develop, maintain, and periodically review the IT governance framework, including policies, standards, procedures, and guidelines aligned with SAMA ITGF, SAMA Outsourcing Framework, COBIT, ITIL, ISO/IEC 27001, and local regulatory requirements.
o Ensure IT governance artefacts are communicated, understood, and adopted across IT and business units.
• IT Risk, Control, and Compliance Oversight o Coordinate identification, assessment, and treatment of IT risks in collaboration with Risk, Information Security, and relevant stakeholders, and ensure integration with the enterprise risk management framework.
o Oversee the design and effectiveness of IT controls, monitor compliance with internal policies and external regulations, and track remediation of gaps and audit findings.
• IT Performance Management and Reporting o Define and monitor key performance indicators (KPIs) and key risk indicators (KRIs) for IT governance, service performance, and compliance, ensuring regular analysis and escalation of issues.
o Prepare clear and concise governance reports and dashboards for IT management, risk committees, and, where applicable, the Board or Board sub-committees.
• Audit, Assessment, and Assurance o Coordinate internal and external IT audits, regulatory inspections, and independent assessments, including preparation, evidence collection, responses, and follow-up actions.
o Maintain a repository of audit observations, action plans, and closure evidence, ensuring timely implementation of corrective and preventive actions.
• Governance of Change, Projects, and Vendors o Support governance of IT projects and change management (e.
g., adherence to architecture principles, security and compliance gates, documentation standards).
o Contribute to governance of key IT vendors and outsourced services, ensuring that contracts, SLAs, and performance reviews reflect governance, risk, and compliance expectations.
• Awareness, Training, and Continuous Improvement o Promote awareness of IT governance, policies, and good practices through training, workshops, and targeted communications.
Continuously benchmark and propose enhancements to governance processes in line with industry best practices and emerging regulatory/technology trends.
Bachelor's degree in Computer Science or a related field.
5–7 years of progressive experience in IT Governance, IT Risk Management, IT Audit, or related IT management roles, preferably within the banking, payments, or financial services sector.
Proven track record in implementing and maintaining IT governance frameworks , performing IT control assessments and audits , and collaborating effectively with regulatory bodies and external auditors to ensure compliance and strengthen governance practices.