Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
An established industry player is seeking a dynamic leader for Cybersecurity Governance, Risk, and Compliance. This pivotal role involves developing and implementing a robust GRC framework across multiple regions, ensuring adherence to enterprise cybersecurity policies and standards. The ideal candidate will have extensive experience in cybersecurity and GRC leadership, with a strong understanding of regulatory frameworks in GCC and LATAM. You will work closely with executive management to present findings and recommendations, fostering a culture of cybersecurity awareness throughout the organization. If you're passionate about cybersecurity and ready to make a significant impact, this opportunity is for you.
Lead the ongoing development and implementation of the Cybersecurity Governance, Risk, and Compliance (GRC) framework across GCC and LATAM operating companies.
Ensure enterprise cybersecurity policies, standards, and control frameworks (e.g., CRF, ISO/IEC 27001, NIST CSF, CIS Controls) are developed, implemented, and adhered to across regional subsidiaries.
Identify and assess cybersecurity risks related to business objectives and technology operations, and report on them accordingly.
Coordinate and support periodic internal and external cybersecurity audits, regulatory reviews, and assessments.
Maintain and manage the risk register, ensuring risks are documented, assessed, and tracked in alignment with the risk management framework.
Interface with local GRC professionals in each OpCo to harmonize compliance controls and address country-specific regulatory requirements.
Evaluate and monitor the maturity of cybersecurity practices and propose continuous improvement strategies.
Present key findings, risk exposures, and recommendations to the CISO and executive management.
Stay informed on regulatory changes for the countries within GCC and LATAM and assess their impact on the compliance posture.
Foster a strong cybersecurity risk-awareness culture across business lines through training and awareness programs.
We are seeking someone who embodies the following:
Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field (required).
Master's degree in Information Security or Risk Management (preferred).
CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor (highly desirable).
7+ years in cybersecurity, with at least 3 years in a GRC leadership or advisory role.
Experience operating within multinational environments, preferably in telecom, fintech, or critical infrastructure.
Strong familiarity with GCC regulatory frameworks; LATAM experience is a plus.
Proven ability to communicate and influence across executive and regulatory stakeholders.