Specialist - Cybersecurity GRC
الوصف الوظيفي
Role Overview
As a Specialist - Cybersecurity GRC, you will play a pivotal role in strengthening the organization’s cybersecurity posture by developing, implementing, and enhancing Governance, Risk Management, and Compliance (GRC) frameworks. This position is instrumental in ensuring that cybersecurity policies, procedures, and controls are meticulously aligned with National Cybersecurity Authority (NCA) requirements, regulatory mandates, and globally recognized standards. Your contributions will provide executive leadership with comprehensive visibility into cybersecurity risks and compliance status, enabling informed decision-making and strategic risk mitigation.
Key Responsibilities
- Policy Development & Maintenance: Collaborate with cross-functional teams to draft, update, and maintain robust cybersecurity policies and procedures that adhere to NCA guidelines and regulatory obligations. Ensure these documents remain current and reflective of evolving threats, technological advancements, and organizational changes.
- Risk & Compliance Management: Support the identification, assessment, and mitigation of cybersecurity risks while ensuring adherence to local regulations, international standards (e.g., ISO 27001, NIST), and industry best practices. Facilitate compliance activities to minimize exposure to regulatory penalties and reputational damage.
- Policy Review & Continuous Improvement: Conduct periodic reviews of cybersecurity policies—at least annually or following significant organizational or operational shifts—to evaluate effectiveness and identify gaps. Champion continuous improvement initiatives to elevate security maturity and align with emerging threats and regulatory expectations.
- Stakeholder Communication & Reporting: Prepare and deliver insightful reports for senior management and the Board of Directors, highlighting critical cybersecurity risks, compliance status, and strategic recommendations. Translate complex technical risks into actionable business insights to drive informed governance decisions.
- Cross-Functional Collaboration: Work closely with IT, legal, risk, and business teams to ensure cybersecurity policies are seamlessly integrated into daily operations. Foster a culture of security awareness by coordinating training, awareness campaigns, and policy dissemination efforts.
- Audit & Assessment Support: Assist in audit preparations by providing accurate documentation, evidence, and remediation plans. Act as a liaison between auditors and internal teams to address findings promptly and ensure timely resolution of compliance gaps.
Talent Profile
- Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field. Relevant certifications (e.g., CISSP, CISM, CRISC) are highly desirable.
- Experience: Minimum of 2–5 years of hands-on experience in cybersecurity, with a strong focus on GRC frameworks, risk assessment methodologies, and compliance audits. Prior exposure to NCA regulations or similar regulatory environments is a significant advantage.
- Technical & Analytical Skills: Proficiency in cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and risk management tools. Strong analytical abilities to interpret regulatory requirements and translate them into actionable security controls.
- Soft Skills: Excellent communication and interpersonal skills to engage stakeholders at all levels. Ability to articulate complex security concepts clearly and influence decision-making processes.
Job Nature & Benefits
This is a site-based, project-oriented role, offering a dynamic work environment where you will contribute to critical cybersecurity initiatives. In addition to a competitive monthly salary, we provide a comprehensive benefits package, including:
- Social Allowance: Financial support to enhance work-life balance and employee well-being.
- Mobile Allowance: Coverage for professional communication needs.
- Medical Insurance: Comprehensive health coverage for employees, their families, and parents, ensuring peace of mind for you and your loved ones.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.