IT Governance, Risk Management, Compliance – Saudi Nationality

Sanaam
الرياض, الرياض دوام كامل
نشر: 1448/1/21 | 2026/07/06 ينتهي: 1448/2/22 | 2026/08/05 ✨ وصف بالذكاء الاصطناعي
تقدم للوظيفة الآن

الوصف الوظيفي

About the Role

We are seeking a dedicated and proactive IT Governance, Risk Management, and Compliance (GRC) Specialist to join our organization. In this pivotal position, you will play a key role in shaping and executing our IT GRC framework, ensuring robust governance, adherence to regulatory standards, and effective risk mitigation across all operations. This role is ideal for individuals with a strong background in IT governance, information security, and a commitment to driving continuous improvement within a fast-paced and collaborative corporate environment.

Key Responsibilities

  • GRC Framework Development and Implementation: Lead the creation, deployment, and ongoing maintenance of a comprehensive IT Governance, Risk, and Compliance framework tailored to the organization’s strategic objectives and regulatory obligations.
  • Policy and Control Management: Establish, document, and enforce IT governance policies, standards, procedures, and internal controls to safeguard organizational assets and ensure operational integrity.
  • Risk Identification and Mitigation: Conduct thorough assessments to identify IT-related risks, evaluate their potential impact, and implement robust mitigation strategies to minimize exposure and enhance resilience.
  • Risk Register Management: Develop and maintain a dynamic IT risk register, systematically tracking identified risks, their status, and remediation progress to ensure timely resolution and accountability.
  • Regulatory and Legal Compliance: Ensure strict adherence to applicable regulatory requirements, industry standards, and organizational policies, mitigating legal and operational risks through proactive compliance measures.
  • Audit Coordination and Remediation: Facilitate seamless coordination with internal and external auditors, manage audit findings, and drive corrective actions to closure, ensuring continuous improvement in controls and processes.
  • Information Security Oversight: Monitor compliance with information security policies, standards, and frameworks, collaborating with security teams to strengthen defenses against evolving threats.
  • Performance Metrics and Reporting: Design and deliver comprehensive IT governance, risk, and compliance reports, including Key Risk Indicators (KRIs), to provide actionable insights to senior management and stakeholders.
  • Business Continuity and Resilience: Contribute to the enhancement of business continuity, disaster recovery, and operational resilience initiatives, ensuring the organization remains prepared for unforeseen disruptions.
  • Stakeholder Engagement and Awareness: Serve as a trusted advisor on GRC matters, providing guidance, training, and awareness programs to foster a culture of compliance and risk-aware decision-making across the organization.
  • Process Improvement: Continuously evaluate and refine GRC processes to align with industry best practices, emerging regulatory trends, and the organization’s evolving strategic priorities.

Qualifications and Experience

To excel in this role, you should possess the following qualifications and professional attributes:

  • Educational Background: A bachelor’s degree in Information Technology, Computer Science, Information Security, Risk Management, Business Administration, or a closely related field is required.
  • Professional Certifications (Preferred): Certifications such as COBIT Foundation, ITIL Foundation, ISO/IEC 27001 Foundation, or CISA (or in the process of obtaining these certifications) are highly desirable and demonstrate a commitment to professional excellence in GRC.
  • Relevant Experience: A minimum of 2–4 years of hands-on experience in IT Governance, Risk Management, Compliance, Information Security, IT Audit, or a similar IT-focused role, with a proven track record of delivering GRC initiatives.
  • Technical Knowledge: Solid understanding of IT governance frameworks, including COBIT, ISO/IEC 27001, NIST, and ITIL, along with practical experience in risk assessments, compliance audits, and policy development.
  • Regulatory Acumen: Familiarity with regulatory requirements, internal control frameworks, and risk management principles, particularly within the context of IT operations and information security.
  • Analytical and Reporting Skills: Proven ability to analyze complex data, prepare detailed reports, maintain accurate risk registers, and track remediation activities with precision and clarity.
  • Soft Skills: Exceptional analytical thinking, strong written and verbal communication abilities, and the capacity to liaise effectively with stakeholders at all levels to drive GRC initiatives forward.

يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.

المصدر: لينكد إن ↗ • 10 مشاهدة

وظائف مشابهة

تقدم للوظيفة الآن