Cybersecurity GRC Specialist(Saudi National only)

Sifi

Riyadh

On-site

SAR 180,000 - 300,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SiFi in Saudi Arabia seeks a Cybersecurity GRC Specialist to maintain regulatory compliance posture and ensure audit readiness across frameworks. You will manage the full GRC lifecycle including evidence management, policy governance, risk tracking, and KPI/KRI reporting, ensuring controls are measurable and defensible.

Ideal candidates have 1-3 years in a GRC role, experience with SAMA CSF compliance, and strong policy drafting skills; proficiency with Archer, ServiceNow GRC, or OneTrust is

Qualifications

  • 1-3 years of experience in a dedicated Cybersecurity GRC role.
  • Hands-on experience with SAMA CSF compliance within regulated entities.
  • Experience in audit evidence preparation and regulatory assessments.
  • Strong background in drafting cybersecurity policies and procedures.

Responsibilities

  • Regulatory Compliance & Audit Readiness: Manage compliance tracker across SAMA CSF, PDPL, NDMO, PCI-DSS and evidence lifecycle.
  • Governance & Policy Management: Develop and maintain cybersecurity policies, standards and procedures; map to controls.
  • Cyber Risk Management: Maintain risk register; conduct TPRA and vendor due diligence; support risk reviews.
  • KPI & KRI Monitoring & Reporting: Collect and validate KPIs/KRIs; maintain centralized tracker; report trends.

Skills

English
Arabic
Policy drafting

Education

Bachelor's degree in Cybersecurity

Tools

Archer
ServiceNow GRC
OneTrust

Job description

Role Overview

The Cybersecurity GRC Specialist plays a critical role in maintaining SiFiu2019s cybersecurity compliance posture and ensuring audit readiness across all regulatory frameworks

This role is responsible for managing the full Governance Regular and Compliance GRC lifecycle including evidence management policy governance risk tracking and KPI KRI reporting ensuring that all cybersecurity controls are measurable defensible and aligned with regulatory expectations

Key Responsibilities
  1. 1 Regulatory Compliance amp Audit Readiness

    • Maintain and manage the compliance tracker across SAMA CSF PDPL NDMO and PCI-DSS
    • Own the full evidence lifecycle collection validation and documentation
    • Ensure continuous audit readiness with traceable control-aligned evidence
    • Track regulatory findings and remediation plans ensuring timely closure
    • Provide regular compliance status reports to the CISO and relevant committees
  2. 2 Governance amp Policy Management

    • Develop and maintain cybersecurity policies standards and procedures
    • Ensure documentation aligns with SiFi governance structure and regulatory expectations
    • Manage document lifecycle versioning approvals reviews
    • Map all policies and procedures to SAMA CSF controls
  3. 3 Cyber Risk Management

    • Maintain and update the cybersecurity risk register
    • Conduct third‑party risk assessments TPRA and vendor due diligence
    • Support risk reviews and reporting cycles
    • Collaborate with Risk and Compliance teams to align enterprise risk frameworks
  4. 4 KPI KRI Monitoring amp Reporting

    • Collect and validate cybersecurity KPIs KRIs from relevant stakeholders
    • Maintain a centralized KPI KRI tracker
    • Prepare periodic reports with trend analysis to support regulatory maturity Level 3
    • Identify and escalte performance gaps
Requirements
  • 1-3 years of experience in a dedicated Cybersecurity GRC role
  • Hands‑on experience with SAMA CSF compliance within regulated entities
  • Experience in audit evidence preparation and regulatory assessments
  • Strong background in drafting cybersecurity policies and procedures
  • Experience using GRC platforms e g Archer ServiceNow GRC OneTrust etc
  • Bachelor's degree in Cybersecurity Information Security Computer Science or related field
  • Certifications in ISO 27001 Lead Implementer Lead Auditor Security ISC CC CGRC or CISA or CRISC
  • Speaks English and Arabic
Preferred Qualifications
  • Experience with PDPL and NDMO regulations
  • PCI-DSS compliance exposure
  • Knowledge of cloud security AWS Azure GCP OCI
  • Experience in fintech or financial services
  • Familiarity with frameworks like ISO 27001 NIST COBIT
Important Note

Job role open for Saudi Nationals only

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000
Cyber GRC Specialist: Audit-Ready Compliance & Policy
Cyber GRC Specialist: Audit-Ready Compliance & Policy

Sifi • Riyadh

On-site
SAR 180,000 - 300,000
Cybersecurity GRC Specialist: Audit-Ready Policy & Risk Lead
Cybersecurity GRC Specialist: Audit-Ready Policy & Risk Lead

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 201,000 - 312,000
Medical Insurance
Paid Time Off
Training & Development
+1
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

flint-international • Jeddah

On-site
SAR 180,000 - 300,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
GRC Consultant
GRC Consultant

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 75,000
Strategic IT & Cybersecurity GRC Consultant
Strategic IT & Cybersecurity GRC Consultant

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 201,000 - 312,000
Medical Insurance
Paid Time Off
Training & Development
+1
Senior GRC & Cybersecurity Compliance Lead
Senior GRC & Cybersecurity Compliance Lead

مرنة للتمويل • Riyadh

On-site
SAR 246,000 - 379,000