Cybersecurity Governance, Risk & Compliance (GRC) Specialist

Cloud Consultancy - CCDS

Riyadh

On-site

SAR 180,000 - 240,000

Part time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Cloud Consultancy - CCDS is seeking a seasoned cybersecurity governance, risk and compliance professional to support a government entity in Riyadh. You will oversee policies, risk assessments, and executive reporting for a 13-month project, aligning actions with the organization’s risk appetite and regulatory expectations.

Responsibilities include audits, evidence preparation, third-party risk oversight, and implementation of eGRC tools, with collaboration across senior leadership and multiple

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • At least 6 years of experience in cybersecurity governance, risk, and compliance.
  • Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.
  • Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.

Responsibilities

  • Review and periodically update cybersecurity policies, procedures, standards, and guidelines.
  • Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.
  • Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite.
  • Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.
  • Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.
  • Operate or support eGRC and cybersecurity risk-management tools.
  • Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.

Skills

Stakeholder management
Analytical skills
Presentation skills
Documentation skills

Education

Bachelor's degree in Computer Science or Information Security

Tools

eGRC tools

Job description

Location: On-site - Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 6+ years

Role Purpose

Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

Key Responsibilities
  • Review and periodically update cybersecurity policies, procedures, standards, and guidelines
  • Perform cybersecurity risk assessments covering assets, systems, projects, and third parties
  • Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite
  • Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks
  • Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure
  • Operate or support eGRC and cybersecurity risk-management tools
  • Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations
Requirements
Technical and Professional Requirements
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • At least 6 years of experience in cybersecurity governance, risk, and compliance
  • Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001
  • Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools
Personal Requirements
  • Strong stakeholder-management skills and confidence working with senior leadership
  • Excellent analytical, writing, presentation, and documentation skills
  • Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams
Professional Certifications

Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

CCDS • Riyadh

On-site
SAR 240,000 - 360,000
Cyber Security GRC Specialist
Cyber Security GRC Specialist

CYBER سايبر • Jeddah

On-site
SAR 180,000 - 240,000
GRC Specialist
GRC Specialist

Managed.sa • Jeddah

On-site
SAR 70,000 - 100,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
Senior GRC Specialist: Risk, Compliance & Audit Leadership
Senior GRC Specialist: Risk, Compliance & Audit Leadership

CCDS • Riyadh

On-site
SAR 240,000 - 360,000
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

CCDS • Riyadh

On-site
SAR 240,000 - 360,000
Medical Insurance
Paid Time Off
Training & Development
+1
Cyber GRC Specialist - On-site in Jeddah
Cyber GRC Specialist - On-site in Jeddah

Managed • Jeddah

On-site
SAR 120,000 - 180,000
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 201,000 - 312,000
Medical Insurance
Paid Time Off
Training & Development
+1
Cybersecurity Governance & Compliance Coordinator: (SAUDI NATIONALS ONLY)
Cybersecurity Governance & Compliance Coordinator: (SAUDI NATIONALS ONLY)

Digital Pay • Riyadh Region

On-site
SAR 180,000 - 240,000