Zakat, Tax and Customs Authority

Information Security GRC Lead Specialist

Zakat, Tax and Customs Authority

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
4+ yrs
Salary
Openings
1
Posted
2 hours ago
Work mode
In office
Education
Bachelor’s degree in Cybersecurity or equivalent
Resume
Required to apply

Where you'll work

Job description

Job Purpose

This role is designed for experienced professionals tasked with handling complex challenges through analysis and resolution, supporting junior staff, and providing strategic solutions in information security governance, risk, and compliance (GRC). The position involves formulating policies, developing security programs, reviewing assessments, managing risk registers, and recommending improvements.

Key Responsibilities

  • Establish and maintain information security policies and standards aligned with cybersecurity regulations.
  • Design consistent security procedures and frameworks for effective control implementation.
  • Create and manage governance, risk, and compliance programs for IT and security risk management meeting compliance needs.
  • Develop cybersecurity awareness initiatives including workshops and seminars to enhance employee knowledge and diligence.
  • Conduct cybersecurity risk assessments; identify potential risks and updates; develop and track mitigation and remediation plans.
  • Maintain and monitor the risk register, ensuring proper documentation and follow-ups on mitigation controls.
  • Analyze results from audits and assessments (NCA and ISO 27001), identifying non-compliance patterns and recommending improvements.
  • Coordinate non-compliance management and support external evaluations against NCA frameworks.
  • Regularly prepare and submit consolidated reports on information security compliance status to regulators.
  • Adhere to all organizational policies and standard operating procedures ensuring consistent and controlled work processes.
  • Support junior staff by resolving escalated issues, providing guidance, training, and performance monitoring.
  • Delegate responsibilities and monitor workflow within the team to ensure efficiency.
  • Escalate unresolved or complex issues appropriately to guarantee proper closure.
  • Perform additional duties as required.

Qualifications

  • Bachelor’s degree in Cybersecurity or a related scientific discipline.
  • At least 4 years of relevant professional experience in information security and governance.

Competencies

  • Developing skills in collaboration and communication.
  • Proficient in IT operations management, professionalism, project management, results orientation, information security, customer focus, vendor management, and cybersecurity incident handling.
  • Advanced capabilities in IT compliance.
  • Developing abilities in change enablement and innovation.

Work styles they’re looking for

Communication Collaboration Team Leadership Professionalism

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help