IT Governance & Risk Specialist / Manager

Astek Middle East

Jeddah

On-site

SAR 180,000 - 300,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Astek Middle East in Jeddah is seeking an experienced IT Governance & Risk professional to drive the development, implementation, and continuous improvement of technology governance, risk, compliance, audit, and IT continuity practices. The role requires hands-on ISO implementation and certification with ISO 20000-1, ISO 27001, and ISO 56002.

You will collaborate with IT, Risk, Audit, Cybersecurity, and other stakeholders to ensure governance aligns with regulatory and international standards,

Qualifications

  • Hands-on experience with ISO implementation and certification.
  • Experience with ISO 20000-1, ISO 27001 and ISO 56002 implementations and certifications.
  • Strong expertise in IT Governance, Risk & Compliance (GRC).
  • Experience developing and implementing IT governance frameworks, standards, policies, and procedures.
  • Experience with IT audit, controls, audit observations, corrective actions, and compliance monitoring.
  • Strong understanding of SAMA CSFW and related regulatory guidelines.

Responsibilities

  • Develop and maintain IT Governance frameworks, standards, policies, and procedures aligned with business objectives.
  • Drive compliance with SAMA CSFW, NCA, and NDMO-PDPL regulatory requirements.
  • Lead IT process improvement and transformation initiatives to enhance efficiency and service quality.
  • Oversee IT documentation, policies, procedures, and governance reporting.
  • Manage IT audits, controls, compliance assessments, and remediation of audit findings.
  • Identify and manage technology risks, KRIs, risk registers, and mitigation plans.
  • Develop and maintain IT Business Continuity & Disaster Recovery plans, including BIA, TRA, RTO/RPO, and testing.
  • Lead ISO implementation and certification activities (ISO 20000-1, ISO 27001, ISO 56002).
  • Collaborate with IT, Risk, Audit, Cybersecurity, and other stakeholders to improve governance and resilience.

Skills

ISO implementation
ISO 20000-1
ISO 27001
ISO 56002
IT Governance, Risk & Compliance
IT audit & controls
SAMA CSFW
NDMO-PDPL & NCA guidelines
IT risk management
IT Continuity & Disaster Recovery
Stakeholder management

Job description

We are looking for an experienced IT Governance & Risk professional to drive the development, implementation, and continuous improvement of technology governance, risk, compliance, audit, business processes, and IT continuity practices.

The role will be responsible for ensuring that IT governance frameworks, policies, processes, controls, and documentation are aligned with organizational objectives and relevant regulatory and international standards.

A key requirement is hands-on experience with ISO implementations and certifications, particularly ISO 20000-1, ISO 27001, and ISO 56002.

Key Responsibilities
  • Develop and maintain IT Governance frameworks, standards, policies, and procedures aligned with business objectives.
  • Drive compliance with SAMA CSFW, NCA, and NDMO-PDPL regulatory requirements.
  • Lead IT process improvement and transformation initiatives to enhance efficiency and service quality.
  • Oversee IT documentation, policies, procedures, and governance reporting.
  • Manage IT audits, controls, compliance assessments, and remediation of audit findings.
  • Identify and manage technology risks, KRIs, risk registers, and mitigation plans.
  • Develop and maintain IT Business Continuity & Disaster Recovery plans, including BIA, TRA, RTO/RPO, and regular testing.
  • Lead ISO implementation and certification activities, particularly ISO 20000-1, ISO 27001, and ISO 56002.
  • Collaborate with IT, Risk, Audit, Cybersecurity, and other stakeholders to continuously improve technology governance and resilience.
Key Requirements
Essential
  • Hands-on experience in ISO implementation and certification, specifically:
  • ISO 20000-1
  • ISO 27001
  • ISO 56002
  • Strong experience in IT Governance, Risk & Compliance (GRC).
  • Experience developing and implementing IT governance frameworks, standards, policies, and procedures.
  • Experience with IT audit, controls, audit observations, corrective actions, and compliance monitoring.
  • Strong understanding and practical experience with SAMA Cyber Security Framework (CSFW).
  • Knowledge/experience of NDMO-PDPL and NCA guidelines.
  • Experience in IT risk management, including risk registers, KRIs, risk assessment, and mitigation.
  • Experience with IT Business Continuity and Disaster Recovery, including BIA, TRA, IT BCP, RTO and RPO.
  • Strong IT process management and continuous improvement experience.
  • Excellent stakeholder management, reporting, documentation, and communication skills.
Strongly Preferred

Candidates who have worked in a regulated environment, particularly where SAMA, NCA, NDMO-PDPL, ISO, IT audit, and technology risk requirements are part of the IT governance landscape, should be prioritized.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Governance Lead
IT Governance Lead

Nabors Industries • Saudi Arabia

On-site
IT Governance Officer
IT Governance Officer

Zamil Offshore Services Company • Al Khobar

On-site
SAR 250,000 - 420,000
GRC Analyst - COBIT Certified
GRC Analyst - COBIT Certified

Eram Talent • Dhahran Compound

On-site
Consultant IT Governance
Consultant IT Governance

Client of AIQU • Saudi Arabia

On-site
SAR 180,000 - 240,000
Digital GRC Section Head
Digital GRC Section Head

FNRCO • Jeddah

On-site
SAR 300,000 - 540,000
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

CCDS • Riyadh

On-site
SAR 240,000 - 360,000
Medical Insurance
Paid Time Off
Training & Development
+1
ServiceNow GRC / IRM Implementation Consultant
ServiceNow GRC / IRM Implementation Consultant

TAWANTECH • Riyadh

On-site
SAR 320,000 - 520,000
IT, Cybersecurity GRC Consultant
IT, Cybersecurity GRC Consultant

Cloud Consultancy - CCDS • Riyadh

On-site
SAR 201,000 - 312,000
Medical Insurance
Paid Time Off
Training & Development
+1
IT Governance & Risk Lead | ISO 27001/20000 Certified
IT Governance & Risk Lead | ISO 27001/20000 Certified

Astek Middle East • Jeddah

On-site
SAR 180,000 - 300,000
Governance, Risk & Compliance (GRC) Specialist
Governance, Risk & Compliance (GRC) Specialist

Saudi Consulting Services Company (SAUDCONSULT) • Riyadh

On-site
SAR 180,000 - 300,000