Cybersecurity Governance, Risk & Compliance (GRC) Specialist
AI Summary
Supports a governmental entity's cybersecurity governance, risk management, and compliance activities, including risk assessments, audit readiness, and executive reporting.
About this role
Location: On-site – Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 6+ years
Role Purpose
Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.
Key Responsibilities
· Review and periodically update cybersecurity policies, procedures, standards, and guidelines.
· Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.
· Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite.
· Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.
· Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.
· Operate or support eGRC and cybersecurity risk-management tools.
· Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.
Requirements
Technical and Professional Requirements
· Bachelor’s degree in Computer Science, Information Security, or a related field.
· At least 6 years of experience in cybersecurity governance, risk, and compliance.
· Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.
· Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.
Personal Requirements
· Strong stakeholder-management skills and confidence working with senior leadership.
· Excellent analytical, writing, presentation, and documentation skills.
· Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.
Professional Certifications
Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).
Skills
Explore related jobs
More jobs at Ccds
- IT Project ManagerCairo, Cairo Governorate
- Network Security Engineer - Sohar, OmanSohar, Al Batinah North Governorate
- Cybersecurity Architecture SpecialistRiyadh, Riyadh Province
- Cybersecurity Assurance SpecialistRiyadh, Riyadh Province
- Cloud Security & Encryption SpecialistRiyadh, Riyadh Province
- Cyber Defense Specialist - Detection & MonitoringRiyadh, Riyadh Province
Similar CISM jobs
Jobs in Riyadh
Field TechnicianATOMS Careers page · Riyadh, KSA- Field TechnicianPronto · Riyadh, KSA
Field EngineerATOMS Careers page · Riyadh, KSA- Field EngineerPronto · Riyadh, KSA
- PAudio Prep Technician (Live Events | Riyadh)Prginternational · Riyadh, Saudi Arabia
- PRigging Prep Technician (Live Events | Riyadh)Prginternational · Riyadh, Saudi Arabia
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.