Governance Risk Compliance Specialist (GRC)
الوصف الوظيفي
About the Role
We are seeking a highly skilled and experienced Cybersecurity Governance Risk Compliance Specialist to join our client’s technology team in Riyadh. This is a fully on-site position that demands expertise in secure-by-design principles, cloud security, and enterprise architecture governance. The successful candidate will play a pivotal role in establishing and maintaining robust cybersecurity governance and risk management frameworks, ensuring strict adherence to regulatory and industry standards across all operations.
Key Responsibilities
As a Governance Risk Compliance Specialist, you will be responsible for the following core functions:
- Governance Framework Development: Maintain and update cybersecurity policies, standards, and procedures to ensure full alignment with regulatory requirements, including SAMA, NCA ECC, ISO 27001, NIST CSF, and all applicable local regulations.
- Risk Assessment Leadership: Lead and oversee periodic cyber risk assessments across systems, projects, and business processes to identify vulnerabilities and mitigate potential threats.
- Cyber Risk Register Management: Develop, maintain, and manage the Cyber Risk Register by documenting risks, assigning accountable owners, creating mitigation plans, and tracking the status of risk treatment activities.
- Stakeholder Coordination: Collaborate with business and IT stakeholders to facilitate risk treatment activities, including risk acceptance, mitigation tracking, and control remediation planning.
- Governance Reporting and Dashboards: Produce comprehensive governance reports and dashboards, including Key Risk Indicators (KRIs), for presentation to management and risk committees to support informed decision-making.
- SOC Alignment: Ensure that Security Operations Center (SOC) activities are fully mapped to governance requirements and control frameworks to maintain operational integrity.
- Regulatory Compliance Support: Assist in regulatory self-assessments, gap analyses, and remediation planning to ensure continuous compliance with evolving standards and regulations.
- Exception and Deficiency Management: Oversee the management of exceptions and control deficiencies through formal governance processes, ensuring timely resolution and mitigation.
- Stakeholder Engagement and Training: Drive stakeholder engagement initiatives and deliver training programs to foster a culture of governance adoption and cybersecurity awareness across the organization.
Qualifications and Experience
To excel in this role, candidates must meet the following requirements:
- Experience: Minimum of five years in Governance, Risk, and Compliance (GRC) or cyber risk roles, with a strong preference for candidates with experience in the banking or financial services sector.
- Technical Knowledge: In-depth understanding of ISO 27001, NIST CSF, and regional banking regulations, including SAMA and NCA ECC, with hands-on experience in policy governance, control mapping, exception management, and governance reporting.
- Risk Management Expertise: Proven track record in conducting risk assessments and maintaining detailed risk registers to support enterprise-wide risk mitigation strategies.
- Stakeholder Management: Exceptional communication and interpersonal skills, with the ability to engage effectively with stakeholders at all levels, from technical teams to senior management.
- Certifications: Preferred certifications include CISA, CRISC, or ISO 27001 Lead Implementer/Lead Auditor (or equivalent).
- Education: Bachelor’s degree in Computer Science, Information Security, Risk Management, or a related field.
Why Join Us?
This is an exceptional opportunity to contribute to the cybersecurity resilience of a leading organization in Riyadh. The successful candidate will work in a dynamic and collaborative environment, with the chance to shape and enhance the client’s governance frameworks while advancing their career in a high-impact role. If you are a proactive professional with a passion for cybersecurity governance and risk management, we invite you to apply and become a key player in safeguarding our client’s digital assets.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.