This page was automatically translated and may contain errors. View in English.

Governance Risk Compliance Specialist (GRC)

NourNet

Riyadh, Riyadh Province, Saudi Arabia · 全职

抢先申请

经验
5年以上
薪水
职位空缺
1
发布
2小时前
工作模式
在办公室
学历
Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field
恢复
需要申请

你的工作地点

职位描述

Role Overview

Our client in Riyadh is looking for a skilled Cybersecurity Governance Risk Compliance Specialist to join their technology team on a full-time, onsite basis. This position demands expertise in secure-by-design methodologies, cloud security practices, and governance of enterprise architecture.

Responsibilities

  • Develop, maintain, and update cybersecurity policies, standards, and procedures ensuring alignment with standards such as SAMA, NCA ECC, ISO 27001, NIST CSF, and relevant local regulations.
  • Conduct regular cyber risk assessments across various systems, projects, and business workflows.
  • Oversee the Cyber Risk Register by documenting risks, assigning ownership, creating mitigation plans, and tracking ongoing status.
  • Collaborate with business and IT stakeholders to coordinate risk treatment activities, including risk acceptance and mitigation efforts.
  • Create governance reports and dashboards incorporating Key Risk Indicators (KRIs) for leadership and risk committee reviews.
  • Ensure that Security Operations Center (SOC) activities align with governance frameworks and control requirements.
  • Support regulatory self-assessment initiatives, perform gap analyses, and assist with remediation planning.
  • Manage exceptions and address control weaknesses by following formal governance processes.
  • Engage stakeholders and provide training to promote governance framework adoption throughout the organization.

Qualifications and Experience

  • Minimum of five years of experience in Governance, Risk and Compliance (GRC) or cyber risk positions, ideally within banking or financial services sectors.
  • Deep understanding of ISO 27001, NIST Cybersecurity Framework, and regional banking regulatory requirements including SAMA and NCA ECC.
  • Proven track record in conducting risk assessments and managing risk registers effectively.
  • Experience in policy governance, mapping controls, handling exceptions, and preparing governance-related reports.
  • Strong abilities in stakeholder communication and management.

Certifications

Preferred candidates will hold certifications such as CISA, CRISC, or ISO 27001 Lead Implementer/Lead Auditor or equivalents.

Education Requirements

Bachelor’s degree in Computer Science, Information Security, Risk Management, or related discipline.

如果您希望收到回复,请留下您的信息——我们不会将您的信息用于其他用途。

点击浏览拖放,或 粘贴 截图

PNG、JPG、GIF、MP4、WebM、MOV 格式 · 每个文件最大 20MB · 最多 5 个文件

🤖
在线·即时人工智能帮助