{bc}
indeed

Cybersecurity Governance, Risk & Compliance (GRC) Specialist

CCDS
Riyadh, KSA
Full-time
Senior
Onsite
Discovered 2 weeks ago
Cybersecurity governanceCybersecurity risk assessmentRegulatory complianceNCA controlsISO/IEC 27001Cybersecurity risk registers
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Cybersecurity governanceCybersecurity risk assessmentRegulatory compliance
Smart Apply

Full Job Posting

Location

  • The role is on-site in Riyadh, Saudi Arabia.

Contract and Engagement

  • The engagement is for project-based managed cybersecurity services lasting 13 months.

Minimum Experience

  • The role requires a minimum of 6 years of experience.

Role Purpose

Support a governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

Key Responsibilities

  • Review and periodically update cybersecurity policies, procedures, standards, and guidelines.
  • Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.
  • Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with approved risk appetite.
  • Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable frameworks.
  • Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.
  • Operate or support eGRC and cybersecurity risk-management tools.
  • Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.

Technical and Professional Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • At least 6 years of experience in cybersecurity governance, risk, and compliance.
  • Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.
  • Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.

Personal Requirements

  • Strong stakeholder-management skills and confidence working with senior leadership.
  • Excellent analytical, writing, presentation, and documentation skills.
  • Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.

Professional Certifications

  • CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer certification is preferred.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at CCDS