Jobless Developer
Ccds logo

Posted 29 days ago

Open

Cybersecurity Governance, Risk & Compliance (GRC) Specialist

RiyadhOn-siteFull-time

AI Summary

Supports a governmental entity's cybersecurity governance, risk management, and compliance activities, including risk assessments, audit readiness, and executive reporting.

About this role

Location: On-site – Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 6+ years

Role Purpose

Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

Key Responsibilities

· Review and periodically update cybersecurity policies, procedures, standards, and guidelines.

· Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.

· Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite.

· Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.

· Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.

· Operate or support eGRC and cybersecurity risk-management tools.

· Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.

Requirements

Technical and Professional Requirements

· Bachelor’s degree in Computer Science, Information Security, or a related field.

· At least 6 years of experience in cybersecurity governance, risk, and compliance.

· Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.

· Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.

Personal Requirements

· Strong stakeholder-management skills and confidence working with senior leadership.

· Excellent analytical, writing, presentation, and documentation skills.

· Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.

Professional Certifications

Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).

Skills

CISMCISSPCRISCCybersecurity Risk RegisterEGRC ToolsISO/IEC 27001ISO/IEC 27001 Lead ImplementerNCA ControlsThird-Party Risk Management

Explore related jobs

Browse these categories

Market data for this role

All reports →