Cybersecurity GRC Specialist(Saudi National only)
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
The Cybersecurity GRC Specialist maintains SiFi’s cybersecurity compliance posture and audit readiness across regulatory frameworks.
The role manages the full GRC lifecycle, including evidence management, policy governance, risk tracking, and KPI/KRI reporting.
Key Skills for This Role
Full Job Posting
About SiFi
SiFi is a B2B FinTech company specializing in spend management and card issuance solutions.
The company helps businesses control spending, streamline expense workflows, and improve operational efficiency.
Role overview
The Cybersecurity GRC Specialist maintains SiFi’s cybersecurity compliance posture and audit readiness across regulatory frameworks.
The role manages the full GRC lifecycle, including evidence management, policy governance, risk tracking, and KPI/KRI reporting.
Regulatory compliance and audit readiness
- Maintain the compliance tracker across SAMA CSF, PDPL/NDMO, and PCI-DSS.
- Own evidence collection, validation, documentation, and control-aligned traceability.
- Track regulatory findings and remediation plans through timely closure.
- Provide compliance status reports to the CISO and relevant committees.
Governance and policy management
- Develop and maintain cybersecurity policies, standards, and procedures.
- Ensure documentation aligns with the governance structure and regulatory expectations.
- Manage document versioning, approvals, and reviews.
- Map policies and procedures to SAMA CSF controls.
Cyber risk management
- Maintain and update the cybersecurity risk register.
- Conduct third-party risk assessments and vendor due diligence.
- Support risk reviews and reporting cycles.
- Collaborate with Risk and Compliance teams to align enterprise risk frameworks.
KPI and KRI reporting
- Collect and validate cybersecurity KPIs and KRIs from relevant stakeholders.
- Maintain a centralized KPI/KRI tracker.
- Prepare periodic reports with trend analysis to support regulatory maturity.
- Identify and escalate performance gaps.
Required qualifications
- 1–3 years of experience in a dedicated Cybersecurity GRC role.
- Hands-on experience with SAMA CSF compliance within regulated entities.
- Experience in audit evidence preparation and regulatory assessments.
- Strong background in drafting cybersecurity policies and procedures.
- Experience using GRC platforms such as Archer, ServiceNow GRC, or OneTrust.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or a related field.
- Certification in ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, Security+, (ISC)² CC, CGRC, CISA, or CRISC.
- Ability to speak English and Arabic.
Preferred qualifications
- Experience with PDPL and NDMO regulations is preferred.
- PCI-DSS compliance exposure is preferred.
- Knowledge of cloud security across AWS, Azure, GCP, or OCI is preferred.
- Experience in fintech or financial services is preferred.
- Familiarity with ISO 27001, NIST, or COBIT is preferred.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at SiFi
Senior Cloud & Security Infrastructure Engineer
Riyadh, KSA
Growth Product Manager
, KSA
Product Manager — Platform
Riyadh, KSA
Senior Data Engineer (Data & AI)
Riyadh, KSA
Onboarding Agent
, KSA
Senior Cloud & Security Infrastructure Engineer
Riyadh, KSA
Internal Audit Manager
Riyadh, KSA
Product Manager
, KSA
AI Engineer
Riyadh, KSA