Cybersecurity GRC Lead

Confidential

Al Khobar

On-site

SAR 220,000 - 320,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Confidential is seeking a cybersecurity compliance professional to develop and maintain policies, procedures, and control documentation. You will drive awareness programs, training, and phishing simulations while aligning governance with standards and legal obligations.

With 6–10 years in cyber risk, audit, or GRC, you will implement ISMS and lead third-party risk assessments and auditable controls across departments in Saudi Arabia.

Qualifications

  • Bachelor's degree or equivalent in security, governance, law, or business with security focus.
  • Experience in cybersecurity compliance, audit, or GRC (6–10 years).
  • Experience implementing and managing ISMS and compliance frameworks.

Responsibilities

  • Develop and maintain cybersecurity policies, procedures, and control documentation.
  • Drive cybersecurity awareness, phishing and training initiatives.

Skills

Cybersecurity compliance
Audit
GRC
ISMS

Education

Bachelor’s degree in information security, IT Governance, Law, or Business with Security specialization

Job description

Key responsibilities
  • Develop and maintain cybersecurity policies, procedures, and control documentation
  • Drive the organization’s cybersecurity awareness, phishing and training initiatives
  • Ensure policies are updated, communicated, and enforced across departments
  • Align governance documents with NCA ECC, ISO 27001, and legal obligations
  • Conduct risk assessments, maintain risk register, and define treatment plans
  • Ensure compliance with NCA ECC, ISO 27001, and Saudi PDPL requirements
  • Perform third-party/vendor risk assessments and due diligence reviews
  • Track remediation plans and prepare for internal/external audits
  • Maintain dashboards for compliance posture and control performance
  • Develop, distribute, and track employee security training and awareness programs
  • Conduct phishing simulations and evaluate response trends
  • Collaborate with HR on onboarding and offboarding security procedures
  • Maintain evidence repository for audits and compliance tracking
  • Map security controls NCA ECC domains and ensures maturity documentation
  • Support the Risk & Compliance Specialist with reporting and updates
Qualifications
  • Bachelor’s degree in information security, IT Governance, Law, or Business with Security specialization
  • 6-10 years of experience in cybersecurity compliance, audit, or GRC
  • In-depth experience in implementing and managing ISMS and compliance framework
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Lead
Cybersecurity GRC Lead

Confidential • Saudi Arabia

On-site
SAR 250,000 - 350,000
Cybersecurity GRC Lead: Policy, Risk & Audit Excellence
Cybersecurity GRC Lead: Policy, Risk & Audit Excellence

Confidential • Al Khobar

On-site
SAR 220,000 - 320,000
Cyber GRC Lead: Policy, Risk & Compliance
Cyber GRC Lead: Policy, Risk & Compliance

Confidential • Saudi Arabia

On-site
SAR 250,000 - 350,000
Cybersecurity Governance & Compliance Coordinator: (SAUDI NATIONALS ONLY)
Cybersecurity Governance & Compliance Coordinator: (SAUDI NATIONALS ONLY)

Digital Pay • Riyadh Region

On-site
SAR 180,000 - 240,000
GRC Specialist
GRC Specialist

Managed.sa • Jeddah

On-site
SAR 70,000 - 100,000
GRC Consultant
GRC Consultant

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 75,000
Cybersecurity GRC & Compliance Coordinator
Cybersecurity GRC & Compliance Coordinator

Digital Pay • Riyadh Region

On-site
SAR 180,000 - 240,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

flint-international • Jeddah

On-site
SAR 180,000 - 300,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000