Cybersecurity GRC Specialist
الوصف الوظيفي
Position Overview
We are seeking a highly skilled and motivated Cybersecurity Governance, Risk, and Compliance (GRC) Specialist to join our team at Tibah Airports Operation Co. in Medina. In this critical role, you will be responsible for developing, implementing, and maintaining robust cybersecurity policies, procedures, and frameworks to ensure the protection of our digital assets, infrastructure, and sensitive data. Your expertise will be instrumental in aligning our cybersecurity practices with industry standards, regulatory requirements, and best practices to mitigate risks and safeguard our operations.
Key Responsibilities
- Governance: Establish and enforce cybersecurity governance frameworks, including the development of policies, standards, and guidelines that align with organizational objectives and regulatory obligations. Ensure adherence to frameworks such as ISO 27001, NIST, and other relevant standards.
- Risk Management: Conduct comprehensive risk assessments to identify vulnerabilities, threats, and potential impacts on our cybersecurity posture. Develop and implement risk mitigation strategies to minimize exposure and enhance resilience against cyber threats.
- Compliance Management: Monitor and ensure compliance with local and international cybersecurity regulations, including data protection laws, aviation industry standards, and corporate policies. Coordinate with internal and external stakeholders to address compliance gaps and implement corrective actions.
- Incident Response & Reporting: Collaborate with the incident response team to investigate security incidents, document findings, and recommend improvements. Prepare and present compliance reports to senior management, highlighting key risks, mitigation efforts, and strategic recommendations.
- Awareness & Training: Develop and deliver cybersecurity awareness programs to educate employees on best practices, emerging threats, and compliance requirements. Foster a culture of security consciousness across the organization.
- Vendor & Third-Party Risk Management: Assess and monitor the cybersecurity posture of third-party vendors and partners to ensure they meet our security standards. Conduct due diligence reviews and manage contractual obligations related to cybersecurity.
- Audit Support: Assist in preparing for and supporting internal and external cybersecurity audits. Provide evidence of compliance, address audit findings, and implement recommendations to enhance security controls.
Qualifications & Skills
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field. Relevant certifications such as CISSP, CISM, CRISC, or CISA are highly desirable.
- Minimum of 5 years of experience in cybersecurity, with a strong focus on GRC, risk management, and compliance.
- In-depth knowledge of cybersecurity frameworks (e.g., ISO 27001, NIST CSF, COBIT) and regulatory requirements (e.g., GDPR, NIS2, aviation-specific standards).
- Proven experience in conducting risk assessments, developing mitigation strategies, and managing compliance programs.
- Excellent analytical, problem-solving, and communication skills, with the ability to articulate complex security concepts to non-technical stakeholders.
- Strong project management skills, with the ability to prioritize tasks and meet deadlines in a fast-paced environment.
- Familiarity with cybersecurity tools such as SIEM, GRC platforms, vulnerability scanners, and risk assessment methodologies is a plus.
- Ability to work independently and collaboratively in a team-oriented environment, with a commitment to continuous learning and professional development.
Why Join Tibah Airports Operation Co.?
As a key player in the aviation industry, Tibah Airports Operation Co. offers a dynamic and rewarding work environment where you can contribute to the security and success of one of the region’s most critical infrastructure sectors. You will have the opportunity to work with cutting-edge technologies, collaborate with industry experts, and make a tangible impact on the cybersecurity posture of a leading airport operator. We offer competitive compensation, professional growth opportunities, and a supportive culture that values innovation, integrity, and excellence.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.