Senior GRC Specialist

United Arab Emirates University, Department of Family Medicine

Abu Dhabi

On-site

AED 180,000 - 240,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

United Arab Emirates University seeks a GRC Specialist to oversee information security governance, risk management, and compliance. You will support the Information Security Manager, align with ISO/IEC 27001:2022 and UAE standards, and embed governance into IT and business processes.

Responsibilities include risk assessments, audit coordination, policy updates, and reporting to senior management. A 3+ year background in GRC or information security and a Bachelor’s degree in CS/IT/Cybersecurity

Qualifications

  • Bachelor’s degree in computer science, information technology, or cybersecurity.
  • At least 3 years of GRC or information security experience.
  • Knowledge of ISO/IEC 27001:2022, UAE IA Standards, and data protection laws.
  • Ability to coordinate audits and regulatory reporting.

Responsibilities

  • Support the Information Security Manager in implementing UAEU’s GRC framework.
  • Develop, review, and update information security, governance, and compliance policies and procedures.
  • Conduct information security and operational risk assessments; maintain the risk register.

Skills

GRC experience
ISO 27001
Regulatory compliance

Education

Bachelor’s degree in CS/IT/Cybersecurity

Job description

Job Description

The GRC (Governance, Risk, and Compliance) Specialist is responsible for overseeing UAEU’s information security governance, risk management, and compliance activities. Acting as a key enabler for the Information Security Manager, this role ensures adherence to regulatory requirements, institutional policies, and international standards, while supporting risk assessment, mitigation planning, and audit readiness. The position involves identifying, analyzing, and reporting on compliance gaps, coordinating internal and external audits, and providing actionable recommendations to improve the University’s risk posture. The role requires in-depth knowledge of regulatory frameworks, risk management methodologies, and best compliance practices, with a focus on embedding governance into IT and business processes, maintaining operational transparency, and continuously enhancing UAEU’s cybersecurity and compliance posture.

  • Support the Information Security Manager in implementing and maintaining UAEU’s GRC framework aligned with ISO/IEC 27001:2022, UAE IA Standards, and applicable government regulations.
  • Develop, review, and update information security, governance, and compliance policies, standards, procedures, and guidelines.
  • Conduct information security, IT, and operational risk assessments and maintain the risk register.
  • Monitor compliance with internal policies, UAE cybersecurity regulations, UAE Data Protection Law, and international standards.
  • Coordinate and support internal and external audits, ensuring evidence and documentation meet regulatory and standard requirements.
  • Track and follow up on audit findings, risk mitigation plans, and corrective actions to ensure timely closure.
  • Conduct third-party and vendor risk assessments, review contracts, and monitor ongoing compliance.
  • Provide actionable recommendations to management on risk treatment, compliance gaps, and governance improvements.
  • Facilitate GRC awareness, education, and training programs for staff and stakeholders.
  • Conduct control gap assessments and recommend practical remediation plans
  • Prepare periodic compliance, risk, and governance reports for the Information Security Manager, senior management, and regulatory bodies.
  • Collaborate with IT, security, and business units to embed governance, risk management, and compliance practices into processes.
  • Perform continuous monitoring of regulatory and standards changes to update policies and processes accordingly.
  • Ensure that UAEU’s operations maintain alignment with legal, contractual, and regulatory requirements.
  • Promote continuous improvement of UAEU’s governance, risk management, and compliance posture.
  • Perform any additional duties or responsibilities related to GRC as assigned by the Information Security Manager or management.
Job Description

The GRC (Governance, Risk, and Compliance) Specialist is responsible for overseeing UAEU’s information security governance, risk management, and compliance activities. Acting as a key enabler for the Information Security Manager, this role ensures adherence to regulatory requirements, institutional policies, and international standards, while supporting risk assessment, mitigation planning, and audit readiness. The position involves identifying, analyzing, and reporting on compliance gaps, coordinating internal and external audits, and providing actionable recommendations to improve the University’s risk posture. The role requires in-depth knowledge of regulatory frameworks, risk management methodologies, and best compliance practices, with a focus on embedding governance into IT and business processes, maintaining operational transparency, and continuously enhancing UAEU’s cybersecurity and compliance posture.

  • Support the Information Security Manager in implementing and maintaining UAEU’s GRC framework aligned with ISO/IEC 27001:2022, UAE IA Standards, and applicable government regulations.
  • Develop, review, and update information security, governance, and compliance policies, standards, procedures, and guidelines.
  • Conduct information security, IT, and operational risk assessments and maintain the risk register.
  • Monitor compliance with internal policies, UAE cybersecurity regulations, UAE Data Protection Law, and international standards.
  • Coordinate and support internal and external audits, ensuring evidence and documentation meet regulatory and standard requirements.
  • Track and follow up on audit findings, risk mitigation plans, and corrective actions to ensure timely closure.
  • Conduct third-party and vendor risk assessments, review contracts, and monitor ongoing compliance.
  • Provide actionable recommendations to management on risk treatment, compliance gaps, and governance improvements.
  • Facilitate GRC awareness, education, and training programs for staff and stakeholders.
  • Conduct control gap assessments and recommend practical remediation plans
  • Prepare periodic compliance, risk, and governance reports for the Information Security Manager, senior management, and regulatory bodies.
  • Collaborate with IT, security, and business units to embed governance, risk management, and compliance practices into processes.
  • Perform continuous monitoring of regulatory and standards changes to update policies and processes accordingly.
  • Ensure that UAEU’s operations maintain alignment with legal, contractual, and regulatory requirements.
  • Promote continuous improvement of UAEU’s governance, risk management, and compliance posture.
  • Perform any additional duties or responsibilities related to GRC as assigned by the Information Security Manager or management.
Minimum Qualification

Bachelor’s degree in computer science, Information Technology, Cybersecurity

Preferred Qualification

Bachelor’s degree in computer science, Information Technology, Cybersecurity

Expected Skills

3+ years in a similar role

30/09/2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC & Compliance Strategist
Senior GRC & Compliance Strategist

United Arab Emirates University, Department of Family Medicine • Abu Dhabi

On-site
AED 180,000 - 240,000
Senior Consultant Information Security GRC
Senior Consultant Information Security GRC

Paramount Computer Systems • Dubai

On-site
AED 300,000 - 600,000
Assistant Manager, Security Governance & Compliance (UAE National)
Assistant Manager, Security Governance & Compliance (UAE National)

Commercial Bank of Dubai • Dubai

On-site
AED 240,000 - 420,000
Senior Associate Information Security- Emirati
Senior Associate Information Security- Emirati

Fisher Human Resource Consultancy • Dubai

On-site
AED 180,000 - 300,000
Senior Consultant – Information Security (GRC)
Senior Consultant – Information Security (GRC)

Paramount Computer System • Dubai

On-site
AED 350,000 - 500,000
Senior Consultant – Information Security (GRC)
Senior Consultant – Information Security (GRC)

Paramount Computer Systems • Dubai

On-site
AED 300,000 - 420,000
GRC Analyst (Governance, Risk & Compliance)
GRC Analyst (Governance, Risk & Compliance)

APPIT Software Inc. • Dubai

On-site
AED 150,000 - 200,000
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services

Jobsatdubai • Dubai

On-site
AED 334,800 - 502,200
Cybersecurity Consultant
Cybersecurity Consultant

Dubai Careers - A Smart Dubai Initiative • Dubai

On-site
AED 300,000 - 420,000
Cybersecurity Consultant
Cybersecurity Consultant

Mada Media • Dubai

On-site
AED 300,000 - 600,000