Cybersecurity GRC Manager

Talent Blueprint FZ LLC

Riyadh

On-site

SAR 420,000 - 660,000

Full time

28 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Talent Blueprint FZ LLC is seeking an experienced Cybersecurity GRC Manager to lead the organization's governance, risk and compliance for a major international football event in Saudi Arabia.

The role covers policy management, data protection, risk assessments, third‑party risk, audits readiness, and collaboration with legal, procurement, IT and senior leadership to ensure regulatory compliance throughout the event lifecycle.

Qualifications

  • 3+ years of experience in Cybersecurity GRC, information security GRC, or related fields.
  • Proven track record leading governance, risk, and compliance programs.
  • Strong knowledge of cybersecurity frameworks, standards, and regulatory requirements.
  • Experience with data protection/privacy compliance and DPAs is a plus.
  • Excellent documentation and stakeholder management skills.

Responsibilities

  • Own and lead the organization's Cybersecurity GRC program end to end.
  • Develop, maintain, review, and secure executive approval for policies, standards, procedures, and governance frameworks.
  • Maintain the cybersecurity risk register and ensure risks are identified, assessed, tracked and treated.
  • Lead periodic and event-driven cybersecurity risk assessments across technology, applications, vendors, and operations.
  • Coordinate cybersecurity compliance self-assessments, audits, and regulator-led audits where applicable.
  • Manage third-party and vendor cybersecurity risk assessments, due diligence, remediation tracking, and monitoring.
  • Support data protection compliance across the event lifecycle in coordination with Legal and stakeholders.
  • Develop and manage cybersecurity awareness and training programs.

Skills

Cybersecurity GRC
Policy management
Regulatory compliance
Audit readiness
Vendor risk management
Data protection
Risk assessments
Stakeholder management
Documentation
Communication

Job description

Contract Duration: 15-Oct-26 - 28-Feb-27

About the Role

We are seeking an experienced Cybersecurity GRC Manager to lead the organization's cybersecurity Governance, Risk, and Compliance function for a major international football event project in Saudi Arabia.

The role will have end-to-end responsibility for cybersecurity governance, risk management, regulatory compliance, third-party risk, audit readiness, policy management, and data protection compliance across the event lifecycle.

The successful candidate will work closely with cybersecurity, legal, procurement, technology, vendors, and senior leadership to ensure that cybersecurity risks and compliance requirements are effectively managed.

Key Responsibilities
  • Own and lead the organization's Cybersecurity Governance, Risk, and Compliance (GRC) program end to end.
  • Develop, maintain, review, and secure executive approval for cybersecurity policies, standards, procedures, and governance frameworks.
  • Own and continuously maintain the cybersecurity risk register, ensuring risks are identified, assessed, tracked, and appropriately treated.
  • Lead periodic and event-driven cybersecurity risk assessments across technology, applications, vendors, and event operations.
  • Coordinate cybersecurity compliance self-assessments, third-party audits, and regulator-led audits where applicable.
  • Manage third-party and vendor cybersecurity risk assessments, including security due diligence, risk identification, remediation tracking, and ongoing monitoring.
  • Support cyber risk management across the significant number of vendors, contractors, sponsors, broadcasters, ticketing providers, hospitality partners, and technology suppliers involved in the event.
  • Own the organization's data protection compliance program in coordination with Legal and relevant business stakeholders.
  • Review and manage data protection requirements associated with personal data processed throughout the event lifecycle.
  • Support and coordinate Data Processing Agreements (DPAs) and related security/data protection requirements with sponsors, broadcasters, ticketing vendors, and other third parties.
  • Develop and manage the organization's cybersecurity awareness and training program.
  • Maintain the policy exception and risk acceptance process, ensuring exceptions are documented, risk assessed, approved, and periodically reviewed.
  • Establish and report cybersecurity GRC and compliance KPIs to senior leadership.
  • Support post-incident reviews from a regulatory, compliance, reporting, and disclosure-obligation perspective.
  • Monitor changes in applicable cybersecurity and data protection requirements and assess their impact on the organization.
  • Provide guidance to business and technology teams on cybersecurity governance, risk, compliance, and third-party security requirements.
  • Work closely with the Cybersecurity Architecture Manager and Cybersecurity Defense Manager to ensure governance and risk requirements are incorporated into cybersecurity architecture and defense operations.
  • Maintain appropriate documentation and evidence to demonstrate compliance and audit readiness throughout the project lifecycle.
Requirements
  • 3+ years of relevant experience in Cybersecurity GRC, Information Security GRC, Cybersecurity Risk, Compliance, or Information Security.
  • Proven experience managing cybersecurity governance, risk, and compliance programs.
  • Strong experience developing and managing cybersecurity policies, standards, procedures, and controls.
  • Experience maintaining cybersecurity risk registers and conducting risk assessments.
  • Experience with third-party/vendor cybersecurity risk management and security due diligence.
  • Experience supporting or coordinating internal, external, third-party, or regulatory audits.
  • Strong understanding of cybersecurity compliance frameworks, standards, and regulatory requirements.
  • Experience with data protection/privacy compliance and third-party data processing arrangements would be an advantage.
  • Experience managing policy exceptions, risk acceptance, and remediation tracking.
  • Experience developing and delivering cybersecurity awareness and training programs.
  • Strong documentation, reporting, communication, and stakeholder management skills.
  • Ability to work effectively with senior leadership, Legal, Procurement, IT, Cybersecurity, vendors, and other business stakeholders.
  • Experience working in a large-scale, multi-vendor, or major event environment would be an advantage.
  • Knowledge of Saudi cybersecurity and data protection requirements would be an advantage.
Preferred Certifications

Relevant cybersecurity, GRC, risk, and privacy certifications would be an advantage, including:

  • CISSP
  • CISM
  • CRISC
  • CISA
  • CGRC
  • CDPSE
  • CIPM / CIPP
  • Other recognized cybersecurity GRC, risk, audit, or privacy certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
GRC Consultant (saudi only)
GRC Consultant (saudi only)

HCLTech • Riyadh

On-site
SAR 180,000 - 280,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

flint-international • Jeddah

On-site
SAR 180,000 - 300,000
GRC Consultant
GRC Consultant

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 75,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

Zamil Offshore Services Company • Al Khobar

On-site
SAR 180,000 - 240,000
GRC Principal Consultant (RE)
GRC Principal Consultant (RE)

Innovative Solutions • Riyadh

On-site
SAR 240,000 - 420,000
Information Security Manager (KSA National)
Information Security Manager (KSA National)

Maximus KSA | ماكسيموس السعودية • Riyadh

On-site
SAR 320,000 - 460,000
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

Sifi • Riyadh

On-site
SAR 180,000 - 300,000