Cybersecurity GRC Lead
Nextera Robotics
Job description
About the role
NextEra is seeking a dynamic Cybersecurity GRC Lead to establish and manage the organization’s security governance framework, cyber‑risk management program, and regulatory/compliance posture. The role partners with business leaders, technology teams, and auditors to ensure security controls are designed, implemented, measured, and continuously improved.
Key responsibilities
- Define and maintain the Information Security Governance model, including policies, standards, procedures, and control baselines.
- Own security exception management, documenting compensating controls and approvals.
- Establish security KPIs/KRIs and provide dashboard reporting for leadership.
- Drive security program maturity using frameworks such as ISO 27001/27002, NIST CSF, NIST 800‑53, and CIS Controls.
- Lead enterprise cyber‑risk assessments covering IT, cloud, application, and infrastructure risks; maintain a risk register and track remediation.
- Facilitate risk acceptance decisions with consistent criteria and scoring.
- Manage compliance and assurance activities for standards and regulations including ISO 27001, SOC 2, PCI DSS, GDPR, and local requirements.
- Plan and execute internal audits, coordinate external audits, and manage audit evidence collection.
- Lead creation of Statement of Applicability, control narratives, and audit‑ready documentation.
- Implement and oversee third‑party/vendor risk management, including risk assessments and ongoing monitoring.
Required profile
- Minimum 12 years (144 months) of experience in cybersecurity governance, risk, and compliance.
- Proven ability to lead risk assessments, compliance programs, and third‑party risk initiatives.
- Strong collaboration skills to work with business leaders, technology teams, and auditors.
Required skills
- Identity access logging
- ServiceNow GRC
- NIST CSF
- Endpoint vulnerability management
- CIS Controls
- Cloud governance
- GRC platforms
- SaaS controls
- Secure SDLC governance
- Audit evidence workflows
- NIST 800‑53
- Shared responsibility model
- Risk registers
- Archer
- Encryption
- ISO 27001
- GCP
- Security Controls
- Microsoft Azure
- AWS
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Saudi Arabia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 1 week from now
17 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Nextera Robotics