Cybersecurity GRC Specialist

Zamil Offshore Services Company

Al Khobar

On-site

SAR 180,000 - 240,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Zamil Offshore Services Company is seeking an experienced Cybersecurity Compliance Lead based in Saudi Arabia to establish and oversee governance, risk, and compliance frameworks aligned with regulatory requirements, industry standards, and business objectives.

The role will drive policy development, risk assessments, audits, training, and third-party reviews across departments, ensuring ongoing adherence to NCA ECC, ISO 27001, and Saudi PDPL obligations.

Qualifications

  • Bachelor's degree in information security, IT Governance, Law, or Business with Security specialization.
  • 3-5 years of experience in cybersecurity compliance, audit, or GRC.
  • In-depth experience in implementing and managing ISMS and compliance framework.

Responsibilities

  • Develop and maintain cybersecurity policies, procedures, and control documentation.
  • Drive cybersecurity awareness, phishing and training initiatives.
  • Ensure policies are updated, communicated, and enforced across departments.
  • Align governance documents with NCA ECC, ISO 27001, and legal obligations.
  • Conduct risk assessments, maintain risk register, and define treatment plans.
  • Ensure compliance with NCA ECC, ISO 27001, and Saudi PDPL requirements.
  • Perform third-party/vendor risk assessments and due diligence reviews.
  • Track remediation plans and prepare for internal/external audits.
  • Maintain dashboards for compliance posture and control performance.
  • Develop, distribute, and track employee security training and awareness programs.
  • Conduct phishing simulations and evaluate response trends.
  • Collaborate with HR on onboarding and offboarding security procedures.
  • Maintain evidence repository for audits and compliance tracking.
  • Map security controls NCA ECC domains and ensures maturity documentation.

Skills

GRC
Policy development
Risk assessment
Auditing
ISMS management

Education

Bachelor's degree in information security, IT Governance, Law, or Business with Security specialization

Job description

Job Purpose:

Establishing and overseeing the organization's cybersecurity governance, risk, and compliance framework to ensure alignment with regulatory requirements, industry standards, and business objectives

Key responsibilities:
  • Develop and maintain cybersecurity policies, procedures, and control documentation
  • Drive the organization's cybersecurity awareness, phishing and training initiatives
  • Ensure policies are updated, communicated, and enforced across departments
  • Align governance documents with NCA ECC, ISO 27001, and legal obligations
  • Conduct risk assessments, maintain risk register, and define treatment plans
  • Ensure compliance with NCA ECC, ISO 27001, and Saudi PDPL requirements
  • Perform third-party/vendor risk assessments and due diligence reviews
  • Track remediation plans and prepare for internal/external auditsMaintain dashboards for compliance posture and control performance
  • Develop, distribute, and track employee security training and awareness programs
  • Conduct phishing simulations and evaluate response trends
  • Collaborate with HR on onboarding and offboarding security procedures
  • Maintain evidence repository for audits and compliance tracking
  • Map security controls NCA ECC domains and ensures maturity documentation
Qualifications
  • Bachelor's degree in information security, IT Governance, Law, or Business with Security specialization
  • 3-5 years of experience in cybersecurity compliance, audit, or GRC
  • In-depth experience in implementing and managing ISMS and compliance framework
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 29,000 - 48,000
GRC Consultant (saudi only)
GRC Consultant (saudi only)

HCLTech • Riyadh

On-site
SAR 180,000 - 280,000
Cybersecurity GRC Consultant
Cybersecurity GRC Consultant

NOZOM • Riyadh

On-site
SAR 180,000 - 260,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

flint-international • Jeddah

On-site
SAR 180,000 - 300,000
GRC Consultant
GRC Consultant

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 75,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
GRC Principal Consultant (RE)
GRC Principal Consultant (RE)

Innovative Solutions • Riyadh

On-site
SAR 240,000 - 420,000
Cyber GRC Leader: Governance, Risk & Compliance
Cyber GRC Leader: Governance, Risk & Compliance

Confidential • Dhahran Compound

On-site
SAR 300,000 - 520,000
GRC Senior Specialist
GRC Senior Specialist

مرنة للتمويل • Riyadh

On-site
SAR 246,000 - 379,000