IT Governance & Risk Specialist / Manager
الوصف الوظيفي
About the Role
We are seeking a seasoned IT Governance & Risk Specialist / Manager to spearhead the design, implementation, and ongoing enhancement of robust technology governance, risk management, compliance, audit, business processes, and IT continuity frameworks. This pivotal role will ensure that IT governance structures, policies, processes, controls, and documentation are meticulously aligned with organizational goals while adhering to stringent regulatory and international standards. The ideal candidate will bring hands-on expertise in ISO implementations and certifications, particularly ISO 20000-1, ISO 27001, and ISO 56002, to drive excellence in IT governance and risk management.
Key Responsibilities
- IT Governance Development: Design, maintain, and refine IT governance frameworks, standards, policies, and procedures in strict alignment with business objectives and regulatory mandates.
- Regulatory Compliance: Ensure adherence to critical regulatory frameworks, including SAMA Cyber Security Framework (CSFW), National Cybersecurity Authority (NCA) guidelines, and National Data Management Office - Personal Data Protection Law (NDMO-PDPL) requirements.
- Process Transformation: Lead IT process improvement and transformation initiatives to elevate operational efficiency, service quality, and overall governance maturity.
- Documentation & Reporting: Oversee the creation, maintenance, and governance of IT documentation, policies, procedures, and comprehensive reporting mechanisms to ensure transparency and accountability.
- Audit & Compliance Management: Manage end-to-end IT audits, controls, compliance assessments, and the remediation of audit findings to mitigate risks and ensure continuous improvement.
- Risk Management: Identify, assess, and manage technology risks through the development of Key Risk Indicators (KRIs), risk registers, and robust mitigation strategies to safeguard organizational assets.
- Business Continuity & Disaster Recovery: Develop, implement, and maintain IT Business Continuity and Disaster Recovery plans, including Business Impact Analysis (BIA), Threat and Risk Assessments (TRA), Recovery Time Objectives (RTO), Recovery Point Objectives (RPO), and regular testing protocols.
- ISO Certification Leadership: Lead ISO implementation and certification initiatives, with a primary focus on ISO 20000-1, ISO 27001, and ISO 56002, to ensure alignment with global best practices.
- Stakeholder Collaboration: Partner with IT, Risk, Audit, Cybersecurity, and other key stakeholders to foster a culture of continuous improvement in technology governance, resilience, and compliance.
Key Requirements
Essential Qualifications & Experience
- ISO Implementation Expertise: Proven hands-on experience in ISO implementation and certification, specifically ISO 20000-1, ISO 27001, and ISO 56002.
- IT Governance, Risk & Compliance (GRC): Extensive experience in developing and implementing IT governance frameworks, standards, policies, and procedures.
- Audit & Compliance Proficiency: Strong background in IT audit, controls, audit observations, corrective actions, and compliance monitoring.
- Regulatory Knowledge: In-depth understanding and practical experience with the SAMA Cyber Security Framework (CSFW), NDMO-PDPL, and NCA guidelines.
- Risk Management: Demonstrated expertise in IT risk management, including risk registers, KRIs, risk assessments, and mitigation strategies.
- Business Continuity & Disaster Recovery: Hands-on experience in IT Business Continuity and Disaster Recovery, including BIA, TRA, IT BCP, RTO, and RPO.
- Process Management: Solid experience in IT process management and continuous improvement methodologies.
- Stakeholder Engagement: Exceptional stakeholder management, reporting, documentation, and communication skills to drive alignment and accountability.
Preferred Qualifications
- Regulated Environment Experience: Candidates with prior experience in a regulated environment, particularly where SAMA, NCA, NDMO-PDPL, ISO, IT audit, and technology risk requirements are integral to IT governance, will be given priority.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.