N
Governance Risk Compliance Specialist (GRC)
Riyadh, Riyadh Province, Saudi Arabia · Tam zamanlı
Başvuran ilk kişi siz olun
- Deneyim
- 5+ yıl
- Maaş
- —
- Açılışlar
- 1
- Yayınlandı
- 6 saat önce
- Çalışma modu
- Ofiste
- Eğitim
- Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field
- Sürdürmek
- Başvuru yapılması gerekmektedir.
Çalışacağınız yer
İş tanımı
Role Overview
Our client in Riyadh is looking for a skilled Cybersecurity Governance Risk Compliance Specialist to join their technology team on a full-time, onsite basis. This position demands expertise in secure-by-design methodologies, cloud security practices, and governance of enterprise architecture.
Responsibilities
- Develop, maintain, and update cybersecurity policies, standards, and procedures ensuring alignment with standards such as SAMA, NCA ECC, ISO 27001, NIST CSF, and relevant local regulations.
- Conduct regular cyber risk assessments across various systems, projects, and business workflows.
- Oversee the Cyber Risk Register by documenting risks, assigning ownership, creating mitigation plans, and tracking ongoing status.
- Collaborate with business and IT stakeholders to coordinate risk treatment activities, including risk acceptance and mitigation efforts.
- Create governance reports and dashboards incorporating Key Risk Indicators (KRIs) for leadership and risk committee reviews.
- Ensure that Security Operations Center (SOC) activities align with governance frameworks and control requirements.
- Support regulatory self-assessment initiatives, perform gap analyses, and assist with remediation planning.
- Manage exceptions and address control weaknesses by following formal governance processes.
- Engage stakeholders and provide training to promote governance framework adoption throughout the organization.
Qualifications and Experience
- Minimum of five years of experience in Governance, Risk and Compliance (GRC) or cyber risk positions, ideally within banking or financial services sectors.
- Deep understanding of ISO 27001, NIST Cybersecurity Framework, and regional banking regulatory requirements including SAMA and NCA ECC.
- Proven track record in conducting risk assessments and managing risk registers effectively.
- Experience in policy governance, mapping controls, handling exceptions, and preparing governance-related reports.
- Strong abilities in stakeholder communication and management.
Certifications
Preferred candidates will hold certifications such as CISA, CRISC, or ISO 27001 Lead Implementer/Lead Auditor or equivalents.
Education Requirements
Bachelor’s degree in Computer Science, Information Security, Risk Management, or related discipline.