Enable job alerts via email!

Cybersecurity Compliance Analyst

TIS

Riyadh

On-site

SAR 150,000 - 200,000

Full time

19 days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Start fresh or import an existing resume

Job summary

A leading company in Saudi Arabia seeks a Cybersecurity Compliance Analyst to ensure alignment with SAMA Cyber Security Framework. The role involves conducting gap assessments, developing risk mitigation strategies, and maintaining ongoing regulatory compliance. Candidates should possess strong skills in IT security, compliance, and risk management, particularly within the financial sector.

Qualifications

  • 3 years of relevant experience in GRC or CS Compliance preferred.
  • MUST HAVE practical experience on SAMA Cyber Security Framework.
  • Certifications like ISO 27001, CISSP, CISA, or GRCP are preferred.

Responsibilities

  • Perform comprehensive gap assessments in line with SAMA and NCA.
  • Develop risk mitigation strategies with cross-functional teams.
  • Prepare compliance reports for executive leadership.

Skills

IT Security
Compliance
Risk Management
Cybersecurity Gap Analysis
Data Privacy and Protection

Education

Bachelor’s degree in Computer Science or Information Security

Tools

GRC tools

Job description

Position Overview


The Cybersecurity Compliance Analystwill work on Gap Analysis, evaluating and aligning the organization’s information security
practices with the Saudi Central Bank (SAMA) Cyber Security Framework. This
role involves assessing current security controls, identifying gaps,
recommending risk mitigation strategies, and ensuring ongoing compliance with
SAMA’s regulatory requirements. Candidates with knowledge of the National
Cybersecurity Authority (NCA) regulations in Saudi Arabia will be at an
advantage.


Key Responsibilities


1. Conduct
Comprehensive Gap Assessments


• Perform detailed
reviews of existing security policies, procedures, and technical controls.


• Map current
practices to the SAMA Cyber Security Framework and NCA regulations, documenting
any non-conformities or control gaps.


2. Develop Risk
Mitigation Strategies


• Collaborate with
cross-functional teams (IT, Legal, Compliance, Operations) to prioritize discovered
gaps.


• Propose remediation
plans with clear timelines and action items to address deficiencies.


3. Maintain
Regulatory Compliance


• Stay up to date on
changes and updates in the SAMA Cyber Security Framework and NCA regulations.


• Review and update
internal policies and standards to ensure continuous alignment with regulatory
requirements.


4. Reporting &
Stakeholder Communication


• Prepare compliance
reports and presentations for executive leadership and relevant committees.


• Communicate findings
and recommendations clearly to both technical and non-technical stakeholders.


5. Audit Readiness
& Support


• Coordinate with
internal and external audit teams to validate remedial actions and ensure
readiness for formal SAMA reviews.


• Provide evidence of
compliance, track audit findings, and follow up on corrective actions.


6. Continuous
Improvement


• Evaluate and
improve gap analysis methodologies and tools.


• Advocate best
practices for documentation, risk assessment, and compliance testing across the
organization.



RequirementsEducation

Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent practical knowledge).

Technical Skillset

Hands-on experience in IT Security, Compliance, or Risk Management—preferably in the financial sector.

3 years of relevant experience GRC or CS Compliance is preferred, candidates with a strong understanding of cybersecurity gap analysis and compliance will also be considered.


MUST HAVE Practical Experience on SAMA Cyber Security Framework and its alignment with standards like ISO 27001 or NIST.

• Experience in Data Privacy and Protection, with a focus on Saudi PDPL and GDPR compliance.

Awareness of NCA regulations and their implications for cybersecurity in the Saudi government sector.

• Familiarity with cybersecurity governance, risk, and compliance (GRC) tools or similar frameworks.

Preferred Certification (Has at least one of the following certifications:)
ISO 27001(Lead
Implementer or Lead Auditor)

CISSP (Certified
Information Systems Security Professional)

CISA (Certified
Information Systems Auditor)

GRCP (GRC
Professional)



Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.