Global Cybersecurity GRC Manager

Foodics

Riyadh

On-site

SAR 420,000 - 780,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonuses
Equity/Share options
Learning stipend
Training opportunities

Job summary

Foodics is seeking a Global Cybersecurity GRC Manager to lead governance, risk, and compliance across the Foodics Group under the CISO. Translate regulatory requirements into practical controls, ownership, remediation plans, and reporting.

This high-visibility role collaborates with Cybersecurity, Technology, Product, Legal, Privacy, Internal Audit, and business teams; prepare dashboards, manage risk registers, and drive evidence-based improvements in our GRC program.

Qualifications

  • 10+ years of professional experience in cybersecurity governance, risk, compliance, audit, or closely related field.
  • Strong hands-on knowledge of ISO 27001 and SOC 2 with experience mapping controls and driving remediation.
  • Good working knowledge of Saudi cybersecurity/privacy requirements (NCA ECC, KSA PDPL).
  • Experience owning/managing cybersecurity risk registers, risk assessments, and treatment plans.
  • Experience maintaining cybersecurity policies, standards, procedures, and evidence repositories.
  • Ability to coordinate internal/external audits and support customer security assessments.
  • Strong analytical skills to create dashboards, executive summaries, and management reporting.
  • Stakeholder management to drive accountability and follow-through.

Responsibilities

  • Manage and coordinate group GRC efforts under the CISO for day-to-day activities and improvements.
  • Conduct, coordinate, and track gap assessments against ISO 27001, SOC 2, NCA ECC, SAMA CSF, KSA PDPL, etc.
  • Translate regulatory requirements into practical controls with owners and target dates.
  • Maintain cybersecurity policy framework, standards, and evidence records.
  • Own and maintain the cybersecurity risk register and remediation plans.
  • Monitor control implementation and escalate material risks and overdue actions.
  • Coordinate internal and external audits and readiness activities.
  • Prepare GRC dashboards, KPIs, KRIs, and management reports.
  • Collaborate with cross-functional teams to embed cybersecurity requirements.

Skills

GRC management
Stakeholder management
Policy writing
Executive reporting
Risk assessment
Audits coordination
English communication
Cross-functional collaboration

Education

Bachelor’s degree in Cybersecurity/Information Security/Information Technology/Risk Management

Tools

ISO 27001
SOC 2
NCA ECC
KSA PDPL
GRC platforms
Evidence management

Job description

Who Are We

We Are Foodics!a leading restaurant management ecosystem and payment tech provider. Founded in 2014 with headquarters in Riyadh and offices across 5 countries, including UAE, Egypt, Jordan and Kuwait. We are currently serving customers and partners in over 35 different countries worldwide. Our innovative products have successfully processed over 6 billion (yes, billion with a B) orders so far! making Foodics one of the most rapidly evolving SaaS companies to ever emerge from the MENA region. Also, Foodics has achieved three rounds of funding, with the latest raising $170 million in the largest SaaS funding round in MENA, boosting its innovation capabilities to better serve business owners.

The Job in a Nutshell

We are looking for a Global Cybersecurity GRC Manager to manage and coordinate cybersecurity governance, risk, and compliance activities across the Foodics Group under the direction of the CISO. You will be responsible for the day-to-day operation of the GRC program translating cybersecurity frameworks, regulatory obligations, and business risks into practical controls, clear ownership, measurable remediation plans, and decision-ready reporting. This is a high-visibility, cross-functional role working closely with Cybersecurity, Technology, Product, Legal, Privacy, Internal Audit, and business teams across the group, while supporting Foodics Pay cybersecurity compliance activities where required.

What you will do
  • Manage and coordinate the group cybersecurity governance, risk, and compliance program under the direction of the CISO, including day-to-day GRC activities, priorities, operating cadence, and continuous improvement initiatives.
  • Conduct, coordinate, and track gap assessments against ISO 27001, SOC 2, NCA ECC, SAMA CSF, KSA PDPL, and other applicable cybersecurity, privacy, regulatory, and contractual requirements.
  • Translate regulatory and framework requirements into practical controls, implementation actions, accountable owners, target dates, and measurable evidence requirements.
  • Maintain the cybersecurity policy framework, including policies, standards, procedures, control owners, supporting evidence, review cycles, approved exceptions, and related governance records.
  • Own and maintain the cybersecurity risk register, facilitate risk assessments, and drive follow-up on treatment plans, risk acceptance, and overdue actions with business and technology owners.
  • Monitor control implementation and remediation progress, challenge weak or incomplete responses, and elevate material risks, recurring gaps, and overdue actions when necessary.
  • Coordinate internal audits, external audits, customer cybersecurity due diligence, certification activities, and readiness assessments, ensuring requests and evidence are handled consistently and efficiently.
  • Support Foodics cybersecurity compliance activities where required, including control mapping, evidence coordination, remediation tracking, audit support, and management reporting.
  • Prepare cybersecurity GRC dashboards, KPIs, KRIs, risk summaries, compliance status reports, and materials for management and cybersecurity governance committees.
  • Partner with control owners across Technology, Product, Operations, HR, Legal, Privacy, Procurement, and other functions to embed cybersecurity requirements into business processes and initiatives.
  • Maintain a clear compliance calendar and ensure recurring assessments, reviews, evidence collection, policy updates, risk reviews, and audit commitments are completed within agreed timelines.
  • Improve the efficiency and quality of the GRC program through standardized templates, control libraries, automation, tooling, and stronger evidence-management practices.
What Are We Looking For
Required
  • 10+ years of professional experience in cybersecurity governance, risk, compliance, audit, or a closely related field, with demonstrated experience managing enterprise GRC activities and working with senior cybersecurity leadership.
  • Strong hands-on knowledge of ISO 27001 and SOC 2, with practical experience conducting gap assessments, mapping controls, collecting evidence, and driving remediation to closure.
  • Good working knowledge of Saudi cybersecurity and privacy requirements, particularly NCA ECC and KSA PDPL, with the ability to interpret requirements and translate them into actionable controls.
  • Demonstrated experience owning or managing cybersecurity risk registers, risk assessments, treatment plans, risk acceptance, exceptions, and management escalation.
  • Experience maintaining cybersecurity policies, standards, procedures, control libraries, control ownership, evidence repositories, and compliance documentation.
  • Proven ability to coordinate internal and external audits, manage evidence requests, respond to customer security assessments, and support certification or assurance readiness.
  • Strong analytical skills and the ability to turn complex risk and compliance information into clear dashboards, executive summaries, and decision-ready committee reporting.
  • Stakeholder management skills, with the confidence to challenge control owners constructively, drive accountability, and follow actions through to completion.
  • Strong written and verbal communication in English, including the ability to write clear policies, risk statements, assessment findings, remediation actions, and management reports.
  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, or a related discipline, or equivalent relevant professional experience.
Nice to have
  • Experience working in FinTech, payments, SaaS, or another regulated and technology-driven environment.
  • Experience with SAMA cybersecurity requirements or supporting cybersecurity compliance activities for a regulated payment or financial-services entity.
  • Professional certifications such as ISO 27001 Lead Implementer / Lead Auditor, CISM, CRISC, CISA, CISSP, or equivalent.
  • Experience with PCI DSS, third-party cybersecurity risk management, privacy compliance, or other regional and international security frameworks.
  • Hands-on experience with GRC platforms, evidence automation, compliance tooling, or building structured control and risk reporting workflows.
  • Experience operating across multiple business entities, countries, or regulatory environments.
  • Arabic language skills for engaging with stakeholders, regulators, and documentation.
What We Offer You

We believe you will love working at Foodics!

  • We offer highly competitive compensation packages, including bonuses and the potential for shares.
  • We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment.
  • Join a talented team of over 30 nationalities working in 14 countries, and gain valuable experience in an exciting industry.
  • We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Global Cybersecurity GRC Manager
Global Cybersecurity GRC Manager

Foodics • Riyad Al Khabra

On-site
SAR 300,000 - 520,000
Bonus potential
Learning stipend
Global team exposure
Global Cybersecurity GRC Manager at Foodics
Global Cybersecurity GRC Manager at Foodics

Foodics • Riyadh

On-site
SAR 380,000 - 540,000
Bonus potential and equity
Learning stipend
Global team experience
+1
Global Cybersecurity GRC Strategist
Global Cybersecurity GRC Strategist

Foodics • Riyadh

On-site
SAR 380,000 - 540,000
Bonus potential and equity
Learning stipend
Global team experience
+1
Head of Compliance
Head of Compliance

Foodics • Riyadh

On-site
SAR 350,000 - 520,000
Bonuses
Share options
Learning stipend
+2
Head of Compliance
Head of Compliance

Taco Stars • Riyadh

On-site
SAR 350,000 - 650,000
Bonus potential
Learning stipend
Diverse, multi-national team
+1
Risk Specialist
Risk Specialist

Foodics’ Group • Riyadh

On-site
SAR 149,000 - 225,000
Competitive compensation packages
Annual learning stipend
Inclusive and diverse culture
Senior Global Cybersecurity GRC Leader
Senior Global Cybersecurity GRC Leader

Foodics • Riyadh

On-site
SAR 420,000 - 780,000
Bonuses
Equity/Share options
Learning stipend
+1
Global Cybersecurity GRC Lead
Global Cybersecurity GRC Lead

Foodics • Riyad Al Khabra

On-site
SAR 300,000 - 520,000
Bonus potential
Learning stipend
Global team exposure
Risk Specialist
Risk Specialist

Tacostars • Riyadh

On-site
SAR 180,000 - 300,000
Bonuses
Stock options
Learning stipend
+2
Cybersecurity GRC Specialist(Saudi National only)
Cybersecurity GRC Specialist(Saudi National only)

sifiapp • Riyadh

On-site
SAR 120,000 - 190,000