Digital GRC Section Head

Saudi Air Navigation Services

As Sudiyah

On-site

OMR 35,000 - 46,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Saudi Air Navigation Services seeks a Lead IT governance, risk and compliance (GRC) expert to oversee GRC across digital platforms, embedding risk-aware operations and ensuring audit readiness. You will drive policy adoption, third-party risk management and actionable reporting to the Section Head.

You will lead governance framework development, risk assessments, compliance management, vendor risk governance, and performance reporting, while mentoring team members and promoting SANS values.

Qualifications

  • Minimum 6 years of experience in a related field or equivalent is required.
  • Bachelor’s degree in Engineering, Computer Science, Information Technology (IT), or equivalent is required.
  • Preferrable qualifications include certifications in audit and assurance, as well as expertise in risk management, KPI-P, compliance, and internal control frameworks.

Responsibilities

  • Lead IT governance frameworks, policies, and controls across the enterprise technology landscape.
  • Drive enterprise-level IT risk assessments and maintain a centralized risk register with remediation timelines.
  • Oversee compliance frameworks (ISO, NCA, GDPR, etc.) and ensure digital platforms are audit ready.
  • Lead vendor GRC assessments, embed risk-based clauses, and monitor compliance.
  • Define and maintain GRC dashboards and provide updates to the Section Head and governance committees.

Skills

GRC governance
IT risk management
Policy oversight
Compliance management
Vendor risk
Reporting

Education

Bachelor's degree in Engineering, Computer Science, Information Technology, or equivalent

Tools

ISO standards
NCA
GDPR

Job description

Lead SANS IT governance, risk and compliance (GRC) practices across digital platforms, ensuring effective risk oversight, audit readiness, and adherence to policies and regulations, enable accountable, risk-aware operations by embedding GRC frameworks into SANS IT processes, managing third-party risks, and providing actionable reporting to the Section Head.

KEY ACCOUNTABILITIES & ACTIVITIES
Governance Framework & Policy Oversight
  • Establish, refine, and enforce IT governance frameworks, policies, and controls across the enterprise technology landscape.
  • Ensure governance practices align with standards, regulatory requirements, and industry best practices.
  • Provide structured reporting and updates to the Section Head on policy adoption and compliance levels.
Enterprise Risk Management & Vulnerability Oversight
  • Lead enterprise-level IT risk assessments and maintain a centralized risk register, ensuring ownership and remediation timelines are defined.
  • Prioritize vulnerabilities and risks based on business impact, integrating with architecture, infrastructure, and security functions for remediation.
  • Drive adoption of a risk-aware culture across IT teams through awareness and practical guidelines.
Compliance Management & Audit Readiness
  • Oversee compliance frameworks (ISO, NCA, GDPR, etc.) and ensure digital platforms are audit ready.
  • Lead control testing, gap assessments, and remediation planning; coordinate timely responses to internal/external audits.
  • Ensure that evidence repositories are well-maintained for efficient audit responses.
Third-party & Vendor Risk Governance
  • Lead assessments of vendor GRC maturity, embed risk-based clauses, and monitor compliance.
  • Ensure vendors demonstrate compliance through SLAs, certifications, or independent audits.
Performance Reporting, Metrics & Continuous Improvement
  • Define and maintain GRC dashboards covering risk posture, audit findings, remediation timelines, and compliance status.
  • Provide regular structured updates to the Section Head and governance committees.
  • Continuously uplift GRC practices through benchmarking, maturity assessments, and lessons learned.
Policies, Processes and Procedures
  • Support in monitoring day-to-day activities to ensure compliance with stipulated policies and procedures
  • Contribute to the identification of opportunities for continuous improvement of systems and processes taking into account leading practices, changes in business environment, cost reduction and productivity improvement
People Management
  • Actively participate in on-the-job training, mentoring and coaching of subordinates
  • Provide clear direction, prioritize tasks, assign and delegate responsibility and monitor the workflow
  • Promote a high-performance working environment embracing SANS’s values
QUALIFICATIONS / REQUIREMENTS
Knowledge and Experience
  • Minimum 6 years of experience in a related field or equivalent is required.
Education and Certifications
  • A bachelor’s degree in Engineering, Computer Science, Information Technology (IT), or equivalent is required.
  • Preferrable qualifications include certifications in audit and assurance, as well as expertise in risk management, KPI-P, compliance, and internal control frameworks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

SOHAR • Muscat

On-site
OMR 20,000 - 42,000
IT Governance & Risk Specialist / Manager
IT Governance & Risk Specialist / Manager

astek middle east • As Sudiyah

On-site
OMR 15,000 - 27,000
Strategic GRC Lead – Digital Platforms & Risk Oversight
Strategic GRC Lead – Digital Platforms & Risk Oversight

Saudi Air Navigation Services • As Sudiyah

On-site
OMR 35,000 - 46,000
Senior Director - Governance, Risk & Compliance
Senior Director - Governance, Risk & Compliance

Omanyp • Oman

On-site
OMR 120,000 - 180,000
Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

Oman Investment Authority • Muscat

On-site
OMR 18,000 - 30,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Senior Cyber GRC Specialist: Policy, Risk & Compliance
Senior Cyber GRC Specialist: Policy, Risk & Compliance

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Governance Specialist
Governance Specialist

2P Perfect Presentation • As Sudiyah

On-site
OMR 9,200 - 15,000
GRC Specialist (IT Risk & IT Compliance) - Immediate Joining
GRC Specialist (IT Risk & IT Compliance) - Immediate Joining

muller's solutions • As Sudiyah

On-site
OMR 31,000 - 42,000
Competitive salary
Benefits package
Exciting projects
Data Platform & Management Manager
Data Platform & Management Manager

fnrco • As Sudiyah

On-site
OMR 46,000 - 69,000