GRC Consultant (saudi only)

HCLTech

Riyadh

On-site

SAR 180,000 - 280,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

HCLTech in Saudi Arabia is seeking a GRC Consultant to support governance, risk and compliance engagements, working with senior team members to deliver client projects. You will gather and analyze data for GRC assessments, prepare reports, and lead audits for ISO 27001 and SOC 2 while ensuring compliance with NCA ECC and SAMA frameworks.

The ideal candidate has a bachelor's degree in cybersecurity or IT, 5–6 years of relevant experience, and certifications such as CISM/CISSP; GRC/ITSM experience

Qualifications

  • Bachelor's degree in cybersecurity, information technology, or related fields.
  • 5–6 years of relevant experience.
  • Certifications such as CISM/CISSP, CompTIA Security+, ISO 27001 Lead Implementor, SSCP & ITIL or equivalent are a plus.
  • Experience with GRC platforms & ITSM knowledge is a plus.

Responsibilities

  • Assist in gathering and analyzing data for GRC assessments.
  • Support the preparation of assessment reports, governance documentation, and client presentations.
  • Lead the preparation and execution of external audits for ISO 27001 and SOC 2 (Type 1 & 2).
  • Manage compliance with local Saudi regulations (NCA ECC and SAMA cybersecurity frameworks) and assess other frameworks (ISO 27001, NDI Controls, ECC, CSCC, DCC, TCC & OSMACC).
  • Collaborate with senior consultants on policies, procedures, frameworks, and controls.
  • Participate in client workshops and project meetings.
  • Liaise with cross-functional teams to support secure and compliant operations.
  • Assist in selecting and implementing GRC software to automate processes and improve reporting.

Skills

Analytical thinking
Communication
Attention to detail
Team oriented

Education

Bachelor's degree in Cybersecurity or IT

Tools

GRC platforms
ITSM

Job description

SAUDI ONLY

Job Description:

The GRC Consultant supports the delivery of Governance, Risk, and Compliance (GRC) services, assisting senior team members in executing client projects.


Responsibilities:


  • Assist in gathering and analyzing data for GRC assessments.

  • Support the preparation of assessment reports, governance documentation, and client presentations.

  • Lead the preparation and execution of external audits for ISO 27001 and SOC 2 (Type 1 & 2) certifications.

  • Manage compliance with local Saudi regulations, specifically NCA ECC and SAMA cybersecurity frameworks, also perform assessments for different frameworks (e.g., ISO 27001, NDI Controls, NCA-Frameworks- ECC, CSCC, DCC, TCC & OSMACC, and other best practices.

  • Collaborate with senior consultants on the development and implementation of policies, procedures, frameworks, etc.

  • Develop and implement policies, procedures, and controls that ensure compliance with laws, regulations, and industry standards.

  • Participate in client workshops and project meetings.

  • Liaise with cross-functional teams (GRC, IT, legal, audit, operations) to support secure and compliant business operations.

  • Assist in the selection and implementation of GRC software solutions to automate processes and improve reporting capabilities.

  • Stay informed about industry trends, regulatory changes, and emerging risks to provide proactive advice to clients.

  • Evaluate third-party vendors for compliance with security standards and risk management requirements.

  • Provide input into enterprise risk management processes from a cybersecurity perspective.

  • Track and report key GRC metrics and issues to stakeholders and executive leadership.


Minimum Requirements

Bachelor's degree in Cybersecurity, Information Technology, or related fields.



  • Basic understanding of cybersecurity concepts, Internal Audit, Risk management, and compliance standards along with 5-6 years of relevant experience

  • Certifications such as CISM /CISSP, CompTIA Security+, ISO 27001 Lead Implementor, SSCP & ITIL or equivalent are a plus.

  • Experience with GRC platforms & ITSM knowledge is plus


Competencies


  • Strong analytical and problem-solving skills.

  • Effective communication skills (verbal and written).

  • Attention to detail in documentation and reporting.

  • Team-oriented mindset with a proactive attitude.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Consultant
GRC Consultant

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 75,000
GRC Consultant — ISO 27001 & SOC 2 Audits (Saudi)
GRC Consultant — ISO 27001 & SOC 2 Audits (Saudi)

HCLTech • Riyadh

On-site
SAR 180,000 - 280,000
GRC & ISO 27001 Specialist: Risk & Compliance
GRC & ISO 27001 Specialist: Risk & Compliance

Help AG • Riyadh

On-site
SAR 120,000 - 200,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
GRC Principal Consultant (RE)
GRC Principal Consultant (RE)

Innovative Solutions • Riyadh

On-site
SAR 240,000 - 420,000
GRC Manager
GRC Manager

MINDFREE Consulting | Insurance Talent Hub • Riyadh

On-site
GRC Consultant
GRC Consultant

EhsanLab • Saudi Arabia

Hybrid
Competitive compensation aligned with market standards
Opportunity to work on high-impact regulatory projects in KSA and GCC
Exposure to leading financial institutions and fintech clients
+2
Senior GRC Specialist
Senior GRC Specialist

Jasara Program Management Company • Riyadh

On-site
SAR 120,000 - 150,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

Zamil Offshore Services Company • Al Khobar

On-site
SAR 180,000 - 240,000