This page was automatically translated and may contain errors. View in English.
사이트맵

Governance Risk Compliance Specialist (GRC)

NourNet

Riyadh, Riyadh Province, Saudi Arabia · 정규직

가장 먼저 지원하세요

경험
5년 이상
샐러리
채용 공고
1
게시됨
7일 전
작업 모드
사무실에서
교육
Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field
재개하다
신청 시 필수 사항

당신이 일하게 될 곳

직무 설명

Role Overview

Our client in Riyadh is looking for a skilled Cybersecurity Governance Risk Compliance Specialist to join their technology team on a full-time, onsite basis. This position demands expertise in secure-by-design methodologies, cloud security practices, and governance of enterprise architecture.

Responsibilities

  • Develop, maintain, and update cybersecurity policies, standards, and procedures ensuring alignment with standards such as SAMA, NCA ECC, ISO 27001, NIST CSF, and relevant local regulations.
  • Conduct regular cyber risk assessments across various systems, projects, and business workflows.
  • Oversee the Cyber Risk Register by documenting risks, assigning ownership, creating mitigation plans, and tracking ongoing status.
  • Collaborate with business and IT stakeholders to coordinate risk treatment activities, including risk acceptance and mitigation efforts.
  • Create governance reports and dashboards incorporating Key Risk Indicators (KRIs) for leadership and risk committee reviews.
  • Ensure that Security Operations Center (SOC) activities align with governance frameworks and control requirements.
  • Support regulatory self-assessment initiatives, perform gap analyses, and assist with remediation planning.
  • Manage exceptions and address control weaknesses by following formal governance processes.
  • Engage stakeholders and provide training to promote governance framework adoption throughout the organization.

Qualifications and Experience

  • Minimum of five years of experience in Governance, Risk and Compliance (GRC) or cyber risk positions, ideally within banking or financial services sectors.
  • Deep understanding of ISO 27001, NIST Cybersecurity Framework, and regional banking regulatory requirements including SAMA and NCA ECC.
  • Proven track record in conducting risk assessments and managing risk registers effectively.
  • Experience in policy governance, mapping controls, handling exceptions, and preparing governance-related reports.
  • Strong abilities in stakeholder communication and management.

Certifications

Preferred candidates will hold certifications such as CISA, CRISC, or ISO 27001 Lead Implementer/Lead Auditor or equivalents.

Education Requirements

Bachelor’s degree in Computer Science, Information Security, Risk Management, or related discipline.

답변을 원하시면 남겨주세요. 다른 용도로는 사용하지 않습니다.

클릭하여 살펴보세요드래그 앤 드롭 또는 반죽 스크린샷

PNG, JPG, GIF, MP4, WebM, MOV · 파일당 최대 20MB · 최대 5개 파일

🤖
온라인 · 즉각적인 AI 도움말