Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds

As Sudiyah

On-site

OMR 29,000 - 48,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

cloud consultancy - ccds in Riyadh is seeking an experienced cybersecurity governance professional to support government entity's governance, risk and compliance, with 6+ years in the field and a focus on policy, risk registers, and executive reporting.

You will review policies, conduct risk assessments, manage evidence for audits, and coordinate remediation across teams using eGRC tools and ISO/IEC 27001 standards.

Qualifications

  • Bachelor's degree in a related field required.
  • 6+ years of experience in cybersecurity governance, risk and compliance.
  • Advanced knowledge of Saudi and international cybersecurity frameworks (NCA controls, ISO/IEC 27001).
  • Experience with risk registers, treatment plans, third‑party risk and executive reporting.

Responsibilities

  • Review and update cybersecurity policies, procedures, standards and guidelines.
  • Perform cybersecurity risk assessments across assets, systems, projects and third parties.
  • Maintain the cybersecurity risk register, develop treatment plans, track actions and align with risk appetite.
  • Conduct compliance gap assessments against NCA controls, ISO/IEC 27001 and other frameworks.
  • Support internal and external audits, prepare evidence, manage non‑compliance and remediation.
  • Operate or support eGRC and cybersecurity risk-management tools.
  • Prepare management reports, dashboards, KPIs and committee presentations.

Skills

Cybersecurity governance
Risk management
Policy development
Executive reporting
Stakeholder management

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

eGRC tools

Job description

Location: On-site - Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 6+ years

Role Purpose

Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

Key Responsibilities
  • Review and periodically update cybersecurity policies, procedures, standards, and guidelines
  • Perform cybersecurity risk assessments covering assets, systems, projects, and third parties
  • Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite
  • Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks
  • Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure
  • Operate or support eGRC and cybersecurity risk-management tools
  • Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations
Requirements
Technical and Professional Requirements
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • At least 6 years of experience in cybersecurity governance, risk, and compliance
  • Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001
  • Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools
Personal Requirements
  • Strong stakeholder-management skills and confidence working with senior leadership
  • Excellent analytical, writing, presentation, and documentation skills
  • Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams
Professional Certifications

Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber GRC Specialist: Policy, Risk & Compliance
Senior Cyber GRC Specialist: Policy, Risk & Compliance

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Cloud Security & Encryption Specialist
Cloud Security & Encryption Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 25,000 - 37,000
Cyber Defense Specialist - Detection & Monitoring
Cyber Defense Specialist - Detection & Monitoring

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 62,000
Cybersecurity Architecture Specialist
Cybersecurity Architecture Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 33,000 - 53,000
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 43,000
GRC Specialist (IT Risk & IT Compliance) - Immediate Joining
GRC Specialist (IT Risk & IT Compliance) - Immediate Joining

muller's solutions • As Sudiyah

On-site
OMR 31,000 - 42,000
Competitive salary
Benefits package
Exciting projects
Governance Specialist
Governance Specialist

2P Perfect Presentation • As Sudiyah

On-site
OMR 9,200 - 15,000
Identity & Access Management (IAM/PAM) Specialist
Identity & Access Management (IAM/PAM) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 18,000 - 29,000
Cybersecurity Architect
Cybersecurity Architect

Your ITeams Sp. z o.o. • As Sudiyah

Hybrid
OMR 34,000 - 47,000
Luxmed Gold Extended medical care
Multisport Plus benefit
Outstanding integration trips to Europe
OQ8 - Expert, Cybersecurity & GRC
OQ8 - Expert, Cybersecurity & GRC

oq8.om • Muscat

On-site
OMR 30,000 - 47,000