Digital GRC Section Head

Saudi Air Navigation Services

Ar Rass, Jeddah

On-site

SAR 350,000 - 650,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Saudi Air Navigation Services is seeking a senior IT GRC leader to oversee governance, risk, and compliance across digital platforms and ensure audit readiness. You will establish frameworks, manage risk assessments, and drive remediation and reporting to the Section Head.

The role requires a minimum of 6 years in a related field, with preferred certifications in audit and assurance, and a strong focus on policy adherence and continuous improvement within enterprise IT.

Qualifications

  • Minimum 6 years of experience in a related field or equivalent is required.
  • Preferrable qualifications include certifications in audit and assurance, as well as expertise in risk management, KPI-P, compliance, and internal control frameworks.

Responsibilities

  • Lead IT governance, risk and compliance (GRC) practices across digital platforms, ensuring effective risk oversight, audit readiness, and adherence to policies and regulations.
  • Establish, refine, and enforce IT governance frameworks, policies, and controls across the enterprise technology landscape.
  • Provide structured reporting and updates to the Section Head on policy adoption and compliance levels.
  • Lead enterprise-level IT risk assessments and maintain a centralized risk register, ensuring ownership and remediation timelines are defined.
  • Prioritize vulnerabilities and risks based on business impact, integrating with architecture, infrastructure, and security functions for remediation.
  • Drive adoption of a risk-aware culture across IT teams through awareness and practical guidelines.
  • Oversee compliance frameworks (ISO, NCA, GDPR, etc.) and ensure digital platforms are audit ready.
  • Lead control testing, gap assessments, and remediation planning; coordinate timely responses to internal/external audits.
  • Ensure that evidence repositories are well-maintained for efficient audit responses.
  • Lead assessments of vendor GRC maturity, embed risk-based clauses, and monitor compliance.
  • Ensure vendors demonstrate compliance through SLAs, certifications, or independent audits.
  • Define and maintain GRC dashboards covering risk posture, audit findings, remediation timelines, and compliance status.
  • Provide regular structured updates to the Section Head and governance committees.
  • Continuously uplift GRC practices through benchmarking, maturity assessments, and lessons learned.
  • Support in monitoring day-to-day activities to ensure compliance with stipulated policies and procedures.
  • Contribute to the identification of opportunities for continuous improvement of systems and processes taking into account leading practices, changes in business environment, cost reduction and productivity improvement.
  • Actively participate in on-the-job training, mentoring and coaching of subordinates.
  • Provide clear direction, prioritize tasks, assign and delegate responsibility and monitor the workflow.
  • Promote a high-performance working environment embracing SANS's values.

Education

Bachelor's degree in Engineering, Computer Science, Information Technology (IT), or equivalent

Job description

Role Purpose

Lead SANS IT governance, risk and compliance (GRC) practices across digital platforms, ensuring effective risk oversight, audit readiness, and adherence to policies and regulations, enable accountable, risk-aware operations by embedding GRC frameworks into SANS IT processes, managing third-party risks, and providing actionable reporting to the Section Head.

KEY ACCOUNTABILITIES & ACTIVITIES
Governance Framework & Policy Oversight
  • Establish, refine, and enforce IT governance frameworks, policies, and controls across the enterprise technology landscape.
  • Ensure governance practices align with standards, regulatory requirements, and industry best practices.
  • Provide structured reporting and updates to the Section Head on policy adoption and compliance levels.
Enterprise Risk Management & Vulnerability Oversight
  • Lead enterprise-level IT risk assessments and maintain a centralized risk register, ensuring ownership and remediation timelines are defined.
  • Prioritize vulnerabilities and risks based on business impact, integrating with architecture, infrastructure, and security functions for remediation.
  • Drive adoption of a risk-aware culture across IT teams through awareness and practical guidelines.
Compliance Management & Audit Readiness
  • Oversee compliance frameworks (ISO, NCA, GDPR, etc.) and ensure digital platforms are audit ready.
  • Lead control testing, gap assessments, and remediation planning; coordinate timely responses to internal/external audits.
  • Ensure that evidence repositories are well-maintained for efficient audit responses.
Third-party & Vendor Risk Governance
  • Lead assessments of vendor GRC maturity, embed risk-based clauses, and monitor compliance.
  • Ensure vendors demonstrate compliance through SLAs, certifications, or independent audits.
Performance Reporting, Metrics & Continuous Improvement
  • Define and maintain GRC dashboards covering risk posture, audit findings, remediation timelines, and compliance status.
  • Provide regular structured updates to the Section Head and governance committees.
  • Continuously uplift GRC practices through benchmarking, maturity assessments, and lessons learned.
Policies, Processes and Procedures
  • Support in monitoring day-to-day activities to ensure compliance with stipulated policies and procedures
  • Contribute to the identification of opportunities for continuous improvement of systems and processes taking into account leading practices, changes in business environment, cost reduction and productivity improvement
People Management
  • Actively participate in on-the-job training, mentoring and coaching of subordinates
  • Provide clear direction, prioritize tasks, assign and delegate responsibility and monitor the workflow
  • Promote a high-performance working environment embracing SANS's values
QUALIFICATIONS / REQUIREMENTS
Knowledge and Experience
  • Minimum 6 years of experience in a related field or equivalent is required.
Education and Certifications
  • A bachelor's degree in Engineering, Computer Science, Information Technology (IT), or equivalent is required.
  • Preferrable qualifications include certifications in audit and assurance, as well as expertise in risk management, KPI-P, compliance, and internal control frameworks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital GRC Section Head
Digital GRC Section Head

FNRCO • Jeddah

On-site
SAR 300,000 - 540,000
GRC Senior Specialist
GRC Senior Specialist

مرنة للتمويل • Riyadh

On-site
SAR 246,000 - 379,000
IT Governance Lead
IT Governance Lead

Nabors Industries • Saudi Arabia

On-site
Digital Service Assurance Section Head
Digital Service Assurance Section Head

Saudi Air Navigation Services • Ar Rass, Jeddah

On-site
SAR 180,000 - 240,000
GRC Consultant
GRC Consultant

Help AG • Riyadh

On-site
SAR 120,000 - 180,000
GRC Manager
GRC Manager

The Professionals • Riyadh

On-site
Information Security Specialist
Information Security Specialist

tabby • Saudi Arabia

On-site
SAR 180,000 - 260,000
Digital GRC Lead: Risk, Compliance & Audit
Digital GRC Lead: Risk, Compliance & Audit

FNRCO • Jeddah

On-site
SAR 300,000 - 540,000
GRC Principal Consultant (RE)
GRC Principal Consultant (RE)

Innovative Solutions SA • Riyadh

On-site
SAR 280,000 - 420,000
Digital Enterprise Architecture Section Head
Digital Enterprise Architecture Section Head

Saudi Air Navigation Services • Jeddah

On-site
SAR 260,000 - 380,000