This job is no longer available
This job expired on 24/09/2026. It no longer accepts applications.
Governance Risk Compliance Specialist (GRC)
NourNet · Riyad
Job description
About the role
We are looking for an experienced Cybersecurity Governance Risk Compliance (GRC) Specialist to join our client’s technology team in Riyadh. The role is fully on‑site and focuses on establishing and maintaining robust governance and risk management frameworks aligned with regulatory and industry standards.
Key responsibilities
- Maintain and update cybersecurity policies, standards and procedures, ensuring alignment with SAMA, NCA ECC, ISO 27001, NIST CSF and local regulations.
- Lead periodic cyber risk assessments across systems, projects and business processes.
- Manage the Cyber Risk Register: record risks, assign owners, document mitigation plans and track status.
- Coordinate risk treatment activities with business and IT owners, including risk acceptance and mitigation tracking.
- Produce governance reporting and dashboards, including KRIs, for management and risk committees.
- Ensure SOC operational activities map to governance requirements and control frameworks.
- Support regulatory self‑assessments, gap analyses and remediation planning.
- Manage exceptions and control deficiencies through formal governance processes.
- Provide stakeholder engagement, training and awareness to drive governance adoption.
Required profile
- 5+ years of experience in GRC or cyber‑risk roles, preferably in banking or financial services.
- Strong knowledge of ISO 27001, NIST CSF and regional banking regulations (SAMA, NCA ECC).
- Proven experience conducting risk assessments and maintaining risk registers.
- Demonstrated experience in policy governance, control mapping, exception management and governance reporting.
- Excellent stakeholder management and communication skills.
- Relevant certifications such as CISA, CRISC or ISO 27001 Lead Implementer/Auditor (preferred).
- Bachelor’s degree in Computer Science, Information Security, Risk Management or a related field.
Required skills
- Secure‑by‑design principles
- Cloud security
- Enterprise architecture governance
- ISO 27001 framework
- NIST Cybersecurity Framework (CSF)
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Saudi Arabia.
Salaries by job title
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
NourNet
Riyad
Related job offers
-
Master & Reference Data Management Consultant
EJADA Riyad -
Data Privacy Consultant
Protiviti Middle East Member Firm Riyad -
Information Technology Internal Auditor
Trivers Riyad -
Expert Generative AI Engineer (n8n) – 12‑Month Contract
Nextwo Co. Gouvernorat d'Amman -
Game Developer & AR/VR Developer
AZCO CONSULTING & CAREER SERVICES Gouvernorat Tunis