Cybersecurity Governance, Risk & Compliance (GRC) Specialist

CCDS

Riyadh

On-site

SAR 240,000 - 360,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CCDS in Riyadh, Saudi Arabia, on-site, is seeking an experienced cybersecurity governance professional for a 13‑month project to support governance, risk, regulatory compliance, audit readiness, and executive reporting for a government entity.

The role requires 6+ years of experience, a Bachelor in CS or InfoSec, and familiarity with NCA and ISO/IEC 27001. You will manage policies, risk registers, third‑party risk, and provide dashboards and committee presentations.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field.

Responsibilities

  • Review and update cybersecurity policies, procedures, standards, and guidelines.
  • Perform cybersecurity risk assessments across assets, systems, projects, and third parties.
  • Maintain the cybersecurity risk register, develop treatment plans, track actions, and align with risk appetite.
  • Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other frameworks.
  • Support internal and external audits, prepare evidence, manage non-compliance cases, and close remediation.
  • Operate or support eGRC and cybersecurity risk-management tools.
  • Prepare management reports, executive dashboards, KPIs, and committee‑level presentations.

Skills

Stakeholder management
Governance
Risk management
Compliance
Executive reporting
eGRC tools

Education

Bachelor’s degree in Computer Science or Information Security

Tools

eGRC platforms

Job description

Location: On-site – Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 6+ years

Role Purpose

Support the governmental entity’s cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

Key Responsibilities
  • Review and periodically update cybersecurity policies, procedures, standards, and guidelines.
  • Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.
  • Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity’s approved risk appetite.
  • Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.
  • Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.
  • Operate or support eGRC and cybersecurity risk-management tools.
  • Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.
Technical and Professional Requirements
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • At least 6 years of experience in cybersecurity governance, risk, and compliance.
  • Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.
  • Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.
Personal Requirements
  • Strong stakeholder-management skills and confidence working with senior leadership.
  • Excellent analytical, writing, presentation, and documentation skills.
  • Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.
Professional Certifications

Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security GRC Specialist
Cyber Security GRC Specialist

CYBER سايبر • Jeddah

On-site
SAR 180,000 - 240,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 201,000 - 312,000
Medical Insurance
Paid Time Off
Training & Development
+1
Senior GRC Specialist: Risk, Compliance & Audit Leadership
Senior GRC Specialist: Risk, Compliance & Audit Leadership

CCDS • Riyadh

On-site
SAR 240,000 - 360,000
Cyber GRC Specialist - On-site in Jeddah
Cyber GRC Specialist - On-site in Jeddah

Managed • Jeddah

On-site
SAR 120,000 - 180,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

flint-international • Jeddah

On-site
SAR 180,000 - 300,000
GRC Specialist
GRC Specialist

Managed.sa • Jeddah

On-site
SAR 70,000 - 100,000
GRC & Cybersecurity Risk Specialist — On-Site Jeddah
GRC & Cybersecurity Risk Specialist — On-Site Jeddah

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
Cybersecurity GRC Lead
Cybersecurity GRC Lead

Confidential • Al Khobar

On-site
SAR 220,000 - 320,000