IT Governance & Risk Specialist / Manager

astek middle east

As Sudiyah

On-site

OMR 15,000 - 27,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Astek Middle East is seeking an experienced IT Governance & Risk professional to drive the development, implementation, and continuous improvement of technology governance, risk, compliance, audit, business processes, and IT continuity practices.

The role requires hands-on work with ISO implementations and certifications, particularly ISO 20000-1, ISO 27001, and ISO 56002, and entails collaboration with IT, Risk, Audit, Cybersecurity to strengthen governance and resilience.

Qualifications

  • Hands-on experience in ISO implementation and certification (ISO 20000-1, ISO 27001, ISO 56002)

Responsibilities

  • Develop and maintain IT governance frameworks, standards, policies, and procedures.
  • Drive compliance with regulatory requirements (SAMA CSFW, NCA, NDMO-PDPL).
  • Lead IT process improvement and transformation initiatives.
  • Oversee IT documentation, policies, procedures, and governance reporting.
  • Manage IT audits, controls, compliance assessments, and remediation of audit findings.
  • Identify and manage technology risks, KRIs, risk registers, and mitigation plans.
  • Develop and maintain IT Business Continuity & Disaster Recovery plans including BIA, TRA, RTO/RPO.
  • Lead ISO implementation and certification activities (ISO 20000-1, ISO 27001, ISO 56002).
  • Collaborate with IT, Risk, Audit, Cybersecurity and other stakeholders to improve governance and resilience.

Skills

IT Governance & GRC
IT risk management
Stakeholder management & communication
Documentation & reporting
ISO implementation experience

Job description

We are looking for an experienced IT Governance & Risk professional to drive the development, implementation, and continuous improvement of technology governance, risk, compliance, audit, business processes, and IT continuity practices.

The role will be responsible for ensuring that IT governance frameworks, policies, processes, controls, and documentation are aligned with organizational objectives and relevant regulatory and international standards.

A key requirement is hands-on experience with ISO implementations and certifications, particularly ISO 20000-1, ISO 27001, and ISO 56002.

Key Responsibilities
  • Develop and maintain IT Governance frameworks, standards, policies, and procedures aligned with business objectives.
  • Drive compliance with SAMA CSFW, NCA, and NDMO-PDPL regulatory requirements.
  • Lead IT process improvement and transformation initiatives to enhance efficiency and service quality.
  • Oversee IT documentation, policies, procedures, and governance reporting.
  • Manage IT audits, controls, compliance assessments, and remediation of audit findings.
  • Identify and manage technology risks, KRIs, risk registers, and mitigation plans.
  • Develop and maintain IT Business Continuity & Disaster Recovery plans, including BIA, TRA, RTO/RPO, and regular testing.
  • Lead ISO implementation and certification activities, particularly ISO 20000-1, ISO 27001, and ISO 56002.
  • Collaborate with IT, Risk, Audit, Cybersecurity, and other stakeholders to continuously improve technology governance and resilience.
Key Requirements
  • Hands-on experience in ISO implementation and certification, specifically:
  • ISO 20000-1
  • ISO 27001
  • ISO 56002
  • Strong experience in IT Governance, Risk & Compliance (GRC).
  • Experience developing and implementing IT governance frameworks, standards, policies, and procedures.
  • Experience with IT audit, controls, audit observations, corrective actions, and compliance monitoring.
  • Strong understanding and practical experience with SAMA Cyber Security Framework (CSFW).
  • Knowledge/experience of NDMO-PDPL and NCA guidelines.
  • Experience in IT risk management, including risk registers, KRIs, risk assessment, and mitigation.
  • Experience with IT Business Continuity and Disaster Recovery, including BIA, TRA, IT BCP, RTO and RPO.
  • Strong IT process management and continuous improvement experience.
  • Excellent stakeholder management, reporting, documentation, and communication skills.
Strongly Preferred

Candidates who have worked in a regulated environment, particularly where SAMA, NCA, NDMO-PDPL, ISO, IT audit, and technology risk requirements are part of the IT governance landscape, should be prioritized.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Governance & Risk Lead | ISO 27001/20000-1, BCP
IT Governance & Risk Lead | ISO 27001/20000-1, BCP

astek middle east • As Sudiyah

On-site
OMR 15,000 - 27,000
Governance Specialist
Governance Specialist

2P Perfect Presentation • As Sudiyah

On-site
OMR 9,200 - 15,000
GRC Specialist (IT Risk & IT Compliance) - Immediate Joining
GRC Specialist (IT Risk & IT Compliance) - Immediate Joining

muller's solutions • As Sudiyah

On-site
OMR 31,000 - 42,000
Competitive salary
Benefits package
Exciting projects
Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

Oman Investment Authority • Muscat

On-site
OMR 18,000 - 30,000
Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

SOHAR • Muscat

On-site
OMR 20,000 - 42,000
Senior Director - Governance, Risk & Compliance
Senior Director - Governance, Risk & Compliance

Omanyp • Oman

On-site
OMR 120,000 - 180,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

SOHAR Port and Freezone • Muscat

On-site
OMR 40,000 - 70,000
Senior Cyber GRC Specialist: Policy, Risk & Compliance
Senior Cyber GRC Specialist: Policy, Risk & Compliance

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
OQ8 - Expert, Cybersecurity & GRC
OQ8 - Expert, Cybersecurity & GRC

oq8.om • Muscat

On-site
OMR 30,000 - 47,000