ന
Governance Risk Compliance Specialist (GRC)
Riyadh, Riyadh Province, Saudi Arabia · മുഴുവൻ സമയവും
അപേക്ഷിക്കുന്ന ആദ്യയാളാകൂ
- അനുഭവം
- 5+ വർഷം
- ശമ്പളം
- —
- ഓപ്പണിംഗുകൾ
- 1
- പോസ്റ്റ് ചെയ്തു
- 10 മണിക്കൂർ മുമ്പ്
- പ്രവർത്തന രീതി
- ഓഫീസിൽ
- വിദ്യാഭ്യാസം
- Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field
- പുനരാരംഭിക്കുക
- അപേക്ഷിക്കാൻ നിർബന്ധം
നിങ്ങൾ എവിടെ ജോലി ചെയ്യും
ജോലി വിവരണം
Role Overview
Our client in Riyadh is looking for a skilled Cybersecurity Governance Risk Compliance Specialist to join their technology team on a full-time, onsite basis. This position demands expertise in secure-by-design methodologies, cloud security practices, and governance of enterprise architecture.
Responsibilities
- Develop, maintain, and update cybersecurity policies, standards, and procedures ensuring alignment with standards such as SAMA, NCA ECC, ISO 27001, NIST CSF, and relevant local regulations.
- Conduct regular cyber risk assessments across various systems, projects, and business workflows.
- Oversee the Cyber Risk Register by documenting risks, assigning ownership, creating mitigation plans, and tracking ongoing status.
- Collaborate with business and IT stakeholders to coordinate risk treatment activities, including risk acceptance and mitigation efforts.
- Create governance reports and dashboards incorporating Key Risk Indicators (KRIs) for leadership and risk committee reviews.
- Ensure that Security Operations Center (SOC) activities align with governance frameworks and control requirements.
- Support regulatory self-assessment initiatives, perform gap analyses, and assist with remediation planning.
- Manage exceptions and address control weaknesses by following formal governance processes.
- Engage stakeholders and provide training to promote governance framework adoption throughout the organization.
Qualifications and Experience
- Minimum of five years of experience in Governance, Risk and Compliance (GRC) or cyber risk positions, ideally within banking or financial services sectors.
- Deep understanding of ISO 27001, NIST Cybersecurity Framework, and regional banking regulatory requirements including SAMA and NCA ECC.
- Proven track record in conducting risk assessments and managing risk registers effectively.
- Experience in policy governance, mapping controls, handling exceptions, and preparing governance-related reports.
- Strong abilities in stakeholder communication and management.
Certifications
Preferred candidates will hold certifications such as CISA, CRISC, or ISO 27001 Lead Implementer/Lead Auditor or equivalents.
Education Requirements
Bachelor’s degree in Computer Science, Information Security, Risk Management, or related discipline.