IT GRC Specialist

Sahm Capital

Riyadh

On-site

SAR 140,000 - 230,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Sahm Capital is seeking an IT GRC Specialist to support governance, risk, and compliance across the organization. The role focuses on regulatory compliance for Saudi requirements and improving cybersecurity posture within a financial services context.

Responsibilities include supporting NCA, CMA, and PDPL initiatives, implementing ISO 27001 frameworks, maintaining policies, and coordinating audits and remediation with IT and risk teams. GCC region experience is a plus.

Qualifications

  • Bachelor's degree in information technology, Information Systems, Cybersecurity or equivalent degree.
  • 3–5 years of experience in IT GRC, IT Audit, Information Security or related role; GCC region is a plus.
  • Certifications CRISC and CISA are must-have.
  • Experience with regulatory frameworks such as NCA ECC, ISO 27001, PDPL or financial-sector compliance preferred.
  • Experience in financial services, fintech, banking or capital markets is advantageous.

Responsibilities

  • Support compliance initiatives related to NCA, CMA, PDPL and other regulatory requirements.
  • Assist in implementing IT governance and cybersecurity frameworks such as ISO 27001.
  • Develop, review and maintain IT policies, procedures, standards and controls.
  • Maintain the IT risk register and track remediation activities.
  • Conduct IT and cybersecurity risk assessments for vendors and third parties.
  • Support audits by coordinating evidence collection and remediation activities.
  • Monitor compliance status and prepare governance and risk reports for management.
  • Collaborate with IT, Security, Risk and Business teams to improve control effectiveness.

Skills

GRC
IT governance
Risk assessment
Auditing
Documentation
Stakeholder management

Education

CRISC
CISA
Bachelor's degree in IT/IS/Cybersecurity

Job description

The IT GRC Specialist to support IT governance, risk management, and compliance activities across the organization. The role is responsible for maintaining compliance with relevant Saudi regulatory requirements, supporting audits, managing IT risks and helping improve cybersecurity and governance practices within a financial services environment.

The IT GRC Specialist’s tasks will include but are not limited to:

  • Support compliance initiatives related to NCA, CMA, PDPL and other applicable regulatory requirements.
  • Assist in implementing and maintaining IT governance and cybersecurity frameworks such as ISO 27001 and related standards.
  • Develop, review and maintain IT policies, procedures, standards and controls.
  • Maintain the IT risk register and track remediation activities.
  • Conduct IT and cybersecurity risk assessments for vendors and third parties.
  • Support internal and external audits by coordinating evidence collection and remediation activities.
  • Monitor compliance status and prepare governance and risk reports for management.
  • Work closely with IT, Security, Risk and Business teams to improve control effectiveness and regulatory readiness.

Bachelor's degree in information technology, Information Systems, Cybersecurity or equivalent degree

3–5 years of experience in IT Governance, Risk & Compliance (GRC), IT Audit, Information Security or a related role, and the GCC region is a plus.

  • Certifications (Must have)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Auditor (CISA)
  • Experience working with regulatory frameworks such as NCA ECC, ISO 27001, PDPL or financial-sector compliance requirements is preferred.
  • Experience within financial services, fintech, banking or capital markets is an advantage.
  • Understanding of IT governance, risk management and compliance principles.
  • Familiarity with IT controls including access management, change management, vulnerability management and disaster recovery.
  • Strong documentation, reporting and audit coordination skills.
  • Good analytical and stakeholder management abilities.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

Ninja • Riyadh

On-site
SAR 150,000 - 210,000
Restaurant d'entreprise
Indemnités de stage/alternance
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

zamil offshore services company • Saudi Arabia

On-site
SAR 180,000 - 260,000
Strategic IT GRC & Compliance Specialist
Strategic IT GRC & Compliance Specialist

Sahm Capital • Riyadh

On-site
SAR 140,000 - 230,000
GRC Specialist
GRC Specialist

Managed • Jeddah

On-site
SAR 120,000 - 180,000
GRC Specialist
GRC Specialist

Managed Services • Jeddah

On-site
SAR 120,000 - 180,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 29,000 - 48,000
Cybersecurity GRC & Compliance Specialist
Cybersecurity GRC & Compliance Specialist

Ninja • Riyadh

On-site
SAR 150,000 - 210,000
Restaurant d'entreprise
Indemnités de stage/alternance
GRC Consultant
GRC Consultant

Catalyic Security • Saudi Arabia

On-site
SAR 50,000 - 75,000
GRC Principal Consultant (RE)
GRC Principal Consultant (RE)

Innovative Solutions • Riyadh

On-site
SAR 240,000 - 420,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

flint-international • Jeddah

On-site
SAR 180,000 - 300,000