This page was automatically translated and may contain errors. View in English.
ネクタイ

Governance Risk Compliance Specialist (GRC)

NourNet

Riyadh, Riyadh Province, Saudi Arabia ・ フルタイム

最初に応募しよう

経験
5年以上
給料
求人情報
1
投稿済み
1時間前
作業モード
在任中
教育
Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field
再開する
応募必須

勤務地

仕事内容

Role Overview

Our client in Riyadh is looking for a skilled Cybersecurity Governance Risk Compliance Specialist to join their technology team on a full-time, onsite basis. This position demands expertise in secure-by-design methodologies, cloud security practices, and governance of enterprise architecture.

Responsibilities

  • Develop, maintain, and update cybersecurity policies, standards, and procedures ensuring alignment with standards such as SAMA, NCA ECC, ISO 27001, NIST CSF, and relevant local regulations.
  • Conduct regular cyber risk assessments across various systems, projects, and business workflows.
  • Oversee the Cyber Risk Register by documenting risks, assigning ownership, creating mitigation plans, and tracking ongoing status.
  • Collaborate with business and IT stakeholders to coordinate risk treatment activities, including risk acceptance and mitigation efforts.
  • Create governance reports and dashboards incorporating Key Risk Indicators (KRIs) for leadership and risk committee reviews.
  • Ensure that Security Operations Center (SOC) activities align with governance frameworks and control requirements.
  • Support regulatory self-assessment initiatives, perform gap analyses, and assist with remediation planning.
  • Manage exceptions and address control weaknesses by following formal governance processes.
  • Engage stakeholders and provide training to promote governance framework adoption throughout the organization.

Qualifications and Experience

  • Minimum of five years of experience in Governance, Risk and Compliance (GRC) or cyber risk positions, ideally within banking or financial services sectors.
  • Deep understanding of ISO 27001, NIST Cybersecurity Framework, and regional banking regulatory requirements including SAMA and NCA ECC.
  • Proven track record in conducting risk assessments and managing risk registers effectively.
  • Experience in policy governance, mapping controls, handling exceptions, and preparing governance-related reports.
  • Strong abilities in stakeholder communication and management.

Certifications

Preferred candidates will hold certifications such as CISA, CRISC, or ISO 27001 Lead Implementer/Lead Auditor or equivalents.

Education Requirements

Bachelor’s degree in Computer Science, Information Security, Risk Management, or related discipline.

返信をご希望の場合は、そのまま残してください。それ以外の目的には一切使用いたしません。

クリックして閲覧ドラッグ&ドロップ、または ペースト スクリーンショット

PNG、JPG、GIF、MP4、WebM、MOV形式 · 各ファイル最大20MB · 最大5ファイルまで

🤖
オンライン・即時AIサポート