Information Security GRC Lead Specialist
الوصف الوظيفي
Position Overview
We are seeking an experienced Information Security Governance, Risk, and Compliance (GRC) Lead Specialist to join our team. In this pivotal role, you will be responsible for developing and implementing robust information security policies, standards, and processes that align with regulatory requirements and industry best practices. Your expertise will drive the creation of comprehensive GRC programs, ensuring our organization maintains a strong security posture while meeting compliance obligations. This position requires a strategic thinker with the ability to analyze complex challenges, identify gaps, and recommend actionable improvements to mitigate cybersecurity risks.
Key Responsibilities
The Information Security GRC Lead Specialist will play a critical role in safeguarding our organization’s digital assets by overseeing the following functions:
Information Security Governance
- Policy and Standard Development: Lead the creation, review, and maintenance of information security policies, standards, and procedures, ensuring full alignment with cybersecurity regulatory requirements, including those mandated by ZATCA and other relevant authorities.
- Framework Design: Develop and implement information security frameworks and procedures to ensure consistent application of security controls across the organization.
- GRC Program Development: Design and oversee the execution of comprehensive GRC programs that effectively manage IT and security risks while meeting compliance requirements.
- Awareness and Training: Develop and deliver cybersecurity awareness programs, including workshops, seminars, and educational initiatives, to foster a culture of security mindfulness among employees and enhance their understanding of governance processes.
Information Security Risk Management
- Risk Assessment and Mitigation: Conduct thorough cybersecurity risk assessments to identify potential threats, evaluate their impact, and develop tailored mitigation and remediation plans in accordance with the organization’s risk appetite.
- Risk Register Management: Establish and maintain a cybersecurity risk register to log, track, and monitor risks, ensuring compliance with established standards, policies, and governance frameworks.
- Follow-Up and Control Implementation: Monitor the implementation of mitigation controls as outlined in risk management plans and update the risk register accordingly to reflect progress and emerging risks.
- Non-Conformity Resolution: Conduct risk assessments for identified non-conformities during security audits and recommend improvements to enhance protection and detection capabilities.
Information Security Compliance
- Audit and Assessment: Perform semiannual assessments against the National Cybersecurity Authority (NCA) framework and annual assessments against ISO 27001 standards to identify patterns of non-compliance with cybersecurity policies and recommend corrective actions.
- Non-Compliance Management: Oversee the resolution of non-compliance cases, improving business processes and operations by supporting external assessments against the NCA framework.
- Reporting and Documentation: Develop and present periodic reports consolidating the status of information security compliance, ensuring alignment with ISO 27001 and NCA requirements.
Organizational and Operational Responsibilities
- Policy Adherence: Ensure all work is conducted in accordance with relevant policies, processes, and standard operating procedures to maintain consistency and control.
- Problem Escalation and Support: Address escalated issues, provide guidance to junior team members, and ensure efficient resolution of complex problems by escalating them to the appropriate stakeholders as needed.
- Additional Duties: Perform other tasks as assigned to support the overall objectives of the information security team.
People Management
- Team Development: Train junior staff on various job activities to facilitate knowledge transfer and skill development.
- Task Delegation and Monitoring: Provide clear direction, prioritize tasks, assign responsibilities, and monitor workflow to ensure efficient execution of duties by subordinates and junior staff.
- Support and Guidance: Offer ongoing support to junior staff and direct reports to ensure adherence to established policies and processes.
Qualifications and Competencies
To excel in this role, candidates must meet the following requirements:
- Education: Bachelor’s degree in Cybersecurity, Computer Science, or a related field is required. Advanced certifications in information security (e.g., CISSP, CISM, CRISC) are highly desirable.
- Experience: Minimum of 4 years of relevant experience in information security, governance, risk management, or compliance, with a proven track record in developing and implementing GRC programs.
- Competencies:
- Collaboration and Communication: Ability to work effectively in cross-functional teams and communicate complex security concepts to diverse audiences.
- IT Operations Management: Proficient in managing IT operations with a focus on security and compliance.
- Professionalism: Demonstrated ability to maintain high ethical standards and professionalism in all interactions.
- Project Management: Strong project management skills with the ability to lead initiatives from conception to completion.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.