Tabbio
Login to App
yesterday

Cybersecurity Governance, Risk & Compliance (GRC) Specialist

CCDS · Riyadh, Riyadh Province, Saudi Arabia
WorkableApply on company site
Full Time
Onsite

Role overview

Location: On-site – Riyadh, Saudi Arabia Contract/engagement: Project-based managed cybersecurity services (13-month) Minimum experience: 6+ years

Role Purpose Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

Key Responsibilities · Review and periodically update cybersecurity policies, procedures, standards, and guidelines. · Perform cybersecurity risk assessments covering assets, systems, projects, and third parties. · Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite. · Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks. · Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure. · Operate or support eGRC and cybersecurity risk-management tools. · Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.

Requirements Technical and Professional Requirements · Bachelor’s degree in Computer Science, Information Security, or a related field. · At least 6 years of experience in cybersecurity governance, risk, and compliance. · Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001. · Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.

Personal Requirements · Strong stakeholder-management skills and confidence working with senior leadership. · Excellent analytical, writing, presentation, and documentation skills. · Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.

Professional Certifications Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).

Responsibilities

1Location: On-site – Riyadh, Saudi Arabia
2Contract/engagement: Project-based managed cybersecurity services (13-month)
3Minimum experience: 6+ years
4Role Purpose
5Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.
6Key Responsibilities
7· Review and periodically update cybersecurity policies, procedures, standards, and guidelines.
8· Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.

Requirements

1Technical and Professional Requirements
2· Bachelor’s degree in Computer Science, Information Security, or a related field.
3· At least 6 years of experience in cybersecurity governance, risk, and compliance.
4· Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.
5· Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.
6Personal Requirements
7· Strong stakeholder-management skills and confidence working with senior leadership.
8· Excellent analytical, writing, presentation, and documentation skills.
9· Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.
10Professional Certifications
11Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).

Skills and tags

SACybersecurityAuditCompliance

Claim your tabbio link
before it's taken