Consultant - Governance & Compliance

Elm Co

Riyadh

On-site

SAR 180,000 - 300,000

Full time

28 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Elm Co in Riyadh seeks a seasoned Governance, Risk and Compliance (GRC) consultant to develop and enhance governance frameworks, risk assessments, policies, and executive reporting. You will support the Governance & Compliance Department in ensuring adherence to regulations and internal policies while delivering practical recommendations to strengthen controls.

You will collaborate with key stakeholders to monitor compliance, coordinate audits and remediation, and produce insightful reports that

Qualifications

  • Bachelor’s degree in Law or related field required.
  • Professional certifications in governance, risk, compliance preferred.
  • 5–7 years of relevant GRC experience preferred.

Responsibilities

  • Provide specialized GRC advisory to support governance and compliant business practices.
  • Develop, review and enhance governance frameworks, control models and procedures.
  • Conduct risk assessments, identify gaps and coordinate remediation actions.
  • Prepare periodic GRC reports, dashboards, and executive summaries for management.

Skills

GRC Advisory
Governance
Regulatory Compliance

Education

Bachelor’s degree in Law/related field
CGRC/CRISC/ISO 31000/ISO 37301/CIA/CISA certification (preferred)

Job description

Select how often (in days) to receive an alert:

Date: 6 Oct 2026

Custom Field 1: 716933

Location: Riyadh, SA

Facility: Others

Job Description
OVERVIEW
Job Title

Consultant

Job Code

716933

Grade

I3

Group

Legal, Compliance & Governance

Division

-

Department

Governance & Compliance

Unit

-

ROLE PURPOSE

To provide senior Governance, Risk and Compliance (GRC) expertise by developing, reviewing, and enhancing governance frameworks, compliance controls, risk assessments, policies, procedures, and executive reporting. The role supports the Governance & Compliance Department in ensuring organizational adherence to applicable regulations, internal policies, governance requirements, and best practices, while providing practical recommendations that strengthen control maturity, transparency, and decision-making across relevant business activities.

KEY ACCOUNTABILITIES & ACTIVITIES

This section describes the principal outputs required from the job.

Key Accountabilities
Key Activities
GRC Advisory & Governance Support
  • Provide specialized advice on governance, risk, and compliance matters to support consistent and controlled business practices.
  • Interpret regulatory, internal policy, and governance requirements and translate them into practical controls and actions.
  • Support management in identifying governance gaps and recommending improvements aligned with organizational priorities.
Governance Frameworks & Controls
  • Develop, review, and enhance governance frameworks, control models, procedures, and decision-making mechanisms.
  • Assess the effectiveness of existing governance practices and recommend improvements to strengthen accountability and oversight.
  • Coordinate with relevant stakeholders to ensure governance requirements are embedded within operational processes.
Compliance Assessment & Monitoring
  • Conduct compliance reviews and monitoring activities to evaluate adherence to internal policies, applicable regulations, and approved procedures.
  • Identify compliance gaps, control weaknesses, and recurring observations requiring corrective actions.
  • Follow up on agreed actions and track closure status to support timely remediation and management visibility.
Risk Identification & Mitigation
  • Support the identification, assessment, and documentation of governance and compliance risks across relevant activities.
  • Analyze potential risk impacts and propose mitigation actions, controls, or escalation paths as required.
  • Maintain clear risk records and provide updates on risk trends, exposures, and treatment progress.
Policies, Procedures & Regulatory Alignment
  • Review and update policies, procedures, guidelines, and compliance documents to ensure alignment with regulatory and organizational requirements.
  • Coordinate policy and procedure reviews with relevant departments and ensure feedback is reflected accurately.
  • Support awareness and clarification of governance and compliance requirements to promote consistent application.
  • Prepare periodic GRC reports, dashboards, and executive summaries covering compliance status, risks, observations, and action plans.
  • Analyze governance and compliance data to identify trends, priorities, and matters requiring management attention.
  • Ensure reports are accurate, structured, and provide clear insights to support informed decision-making.
Audit, Evidence & Remediation Coordination
  • Coordinate the collection and validation of evidence required for internal reviews, audits, regulatory requests, or compliance assessments.
  • Support the analysis of audit observations and translate findings into clear remediation plans and ownership structures.
  • Track remediation activities and elevate delays or unresolved matters to ensure effective closure.
Stakeholder Engagement & Continuous Improvement
  • Engage with internal stakeholders to understand business needs, clarify GRC expectations, and support practical implementation of requirements.
  • Identify opportunities to improve governance practices, compliance monitoring, documentation quality, and reporting efficiency.
  • Contribute to building a culture of accountability, transparency, and continuous improvement across governance and compliance activities.
  • Follow all relevant departmental policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner.
  • Comply with all relevant safety, quality and environmental management policies, procedures and controls to ensure a healthy and safe work environment.
Information Security
  • Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.
JOB SPECIFICATIONS
Academic and professional qualifications
  • Bachelor’s degree in Law, Business Administration, Governance, Risk Management, Compliance, Internal Audit, Finance, or a related field.
  • Professional certifications in governance, risk, compliance, internal audit, or regulatory compliance are preferred, such as CGRC, CRISC, ISO 31000, ISO 37301, CIA, CISA, or equivalent.
Years and Nature of Experience
  • 5-7 years of relevant experience in governance, risk management, compliance, internal controls, regulatory compliance, audit coordination, or related GRC roles.
Job Segment

Internal Audit, Risk Management, Consulting, Information Security, Finance, Service, Technology

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT GRC Specialist
IT GRC Specialist

Sahm Capital • Riyadh

On-site
SAR 140,000 - 230,000
Senior Specialist - Governance
Senior Specialist - Governance

JASARA PMC • Riyadh

On-site
SAR 360,000 - 540,000
GRC Principal Consultant (RE)
GRC Principal Consultant (RE)

Innovative Solutions • Riyadh

On-site
SAR 240,000 - 420,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

Ninja • Riyadh

On-site
SAR 150,000 - 210,000
Restaurant d'entreprise
Indemnités de stage/alternance
GRC Manager
GRC Manager

MINDFREE Consulting | Insurance Talent Hub • Riyadh

On-site
SAR 167,400 - 279,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

zamil offshore services company • Saudi Arabia

On-site
SAR 180,000 - 260,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 29,000 - 48,000
GRC Specialist (Information Security, Privacy and Business Continuity)
GRC Specialist (Information Security, Privacy and Business Continuity)

KalSoft • Riyadh

On-site
SAR 180,000 - 260,000