Cybersecurity GRC Specialist(Saudi National only)

sifiapp

Riyadh

On-site

SAR 120,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

SiFi, a fast-growing B2B FinTech in Riyadh, seeks a Cybersecurity GRC Specialist to oversee regulatory compliance, policy governance, and risk management. You will drive evidence management, audit readiness, and KPI/KRI reporting across frameworks.

Responsibilities include maintaining SAMA CSF, PDPL/NDMO, and PCI-DSS compliance, mapping policies to controls, and supporting risk reviews with the risk and compliance teams. English and Arabic fluency is required.

Qualifications

  • 1-3 years of experience in a dedicated Cybersecurity GRC role.
  • Hands-on with SAMA CSF compliance in regulated entities.
  • Experience in audit evidence preparation and regulatory assessments.
  • Strong background in drafting cybersecurity policies and procedures.
  • Experience using GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust).
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field.
  • Fluency in English and Arabic.

Responsibilities

  • Maintain compliance tracker across SAMA CSF, PDPL/NDMO, and PCI-DSS.
  • Own evidence lifecycle: collection, validation, and documentation.
  • Map policies and procedures to SAMA CSF controls and governance.
  • Maintain cybersecurity risk register and conduct TPRA/vendor due diligence.
  • Support risk reviews and reporting cycles with Risk and Compliance teams.
  • Prepare KPI/KRI reports and track remediation actions.

Skills

GRC
Regulatory compliance
Audit readiness
SAMA CSF
PCI-DSS
Policy drafting
GRC platforms
English
Arabic

Education

Bachelor's degree in Cybersecurity
ISO 27001 Lead Implementer/Lead Auditor
CISA/CRISC

Tools

Archer
ServiceNow GRC
OneTrust

Job description

Job Description
About SiFi

SiFi is a fast-growing B2B FinTech company specializing in spend management and card issuance solutions. We help companies take control of their spending, streamline expense workflows, and operate with greater efficiency.

Role Overview

The Cybersecurity GRC Specialist plays a critical role in maintaining SiFi's cybersecurity compliance posture and ensuring audit readiness across all regulatory frameworks.

This role is responsible for managing the full Governance, Risk, and Compliance (GRC) lifecycle - including evidence management, policy governance, risk tracking, and KPI/KRI reporting - ensuring that all cybersecurity controls are measurable, defensible, and aligned with regulatory expectations.

1. Regulatory Compliance & Audit Readiness
  • Maintain and manage the compliance tracker across SAMA CSF, PDPL/NDMO, and PCI-DSS
  • Own the full evidence lifecycle: collection, validation, and documentation
  • Ensure continuous audit readiness with traceable, control-aligned evidence
  • Track regulatory findings and remediation plans, ensuring timely closure
  • Provide regular compliance status reports to the CISO and relevant committees
2. Governance & Policy Management
  • Develop and maintain cybersecurity policies, standards, and procedures
  • Ensure documentation aligns with SiFi governance structure and regulatory expectations
  • Manage document lifecycle (versioning, approvals, reviews)
  • Map all policies and procedures to SAMA CSF controls
3. Cyber Risk Management
  • Maintain and update the cybersecurity risk register
  • Conduct third-party risk assessments (TPRA) and vendor due diligence
  • Support risk reviews and reporting cycles
  • Collaborate with Risk and Compliance teams to align enterprise risk frameworks
4. KPI / KRI Monitoring & Reporting
  • Collect and validate cybersecurity KPIs/KRIs from relevant stakeholders
  • Maintain a centralized KPI/KRI tracker
  • Prepare periodic reports with trend analysis to support regulatory maturity (Level 3+)
  • Identify and elevate performance gaps
Requirements
  • We are looking for candidates with 1-3 years of experience in a dedicated Cybersecurity GRC role.
  • years in a dedicated Cybersecurity GRC role
  • Hands-on experience with SAMA CSF compliance within regulated entities
  • Experience in audit evidence preparation and regulatory assessments
  • Strong background in drafting cybersecurity policies and procedures
  • Experience using GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust, etc.)
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field
  • Certifications in ISO 27001 Lead Implementer / Lead Auditor, Security+, (ISC)² CC, CGRC or CISA or CRISC
  • Speaks English and Arabic
Preferred Qualifications
  • Experience with PDPL and NDMO regulations
  • PCI-DSS compliance exposure
  • Knowledge of cloud security (AWS, Azure, GCP, OCI)
  • Experience in fintech or financial services\
  • Familiarity with frameworks like ISO 27001, NIST, COBIT

Important Note: Job role open for Saudi Nationals only.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

SiFi - Simplified Financial Solutions Company • Riyadh

On-site
SAR 120,000 - 180,000
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

Sifi • Riyadh

On-site
SAR 180,000 - 300,000
Cybersecurity GRC Specialist: Audit-Ready Policy & Risk Lead
Cybersecurity GRC Specialist: Audit-Ready Policy & Risk Lead

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000
Cyber GRC Specialist: Audit-Ready Compliance & Policy
Cyber GRC Specialist: Audit-Ready Compliance & Policy

Sifi • Riyadh

On-site
SAR 180,000 - 300,000
Saudi Cyber GRC Specialist: Audit & Compliance
Saudi Cyber GRC Specialist: Audit & Compliance

SiFi - Simplified Financial Solutions Company • Riyadh

On-site
SAR 120,000 - 180,000
Cyber Security GRC Specialist
Cyber Security GRC Specialist

CYBER سايبر • Jeddah

On-site
SAR 180,000 - 240,000
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

CCDS • Riyadh

On-site
SAR 240,000 - 360,000
Medical Insurance
Paid Time Off
Training & Development
+1
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 201,000 - 312,000
Medical Insurance
Paid Time Off
Training & Development
+1
Cybersecurity Governance & Compliance Coordinator: (SAUDI NATIONALS ONLY)
Cybersecurity Governance & Compliance Coordinator: (SAUDI NATIONALS ONLY)

Digital Pay • Riyadh Region

On-site
SAR 180,000 - 240,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

CCDS • Riyadh

On-site
SAR 240,000 - 360,000