GRC Specialist – Cybersecurity Governance, Risk & Compliance
Managed.sa · Riyad
Job description
About the role
We are seeking a motivated and detail‑oriented GRC Specialist to join our cybersecurity team. You will support governance, risk, and compliance activities for our customers, focusing on security audits, compliance assessments, gap analysis, and remediation planning.
Key responsibilities
- Support execution of GRC activities, including governance, risk management, compliance, and audit tasks.
- Conduct and support security audits and compliance assessments against Saudi and international cybersecurity frameworks.
- Assess cybersecurity controls, identify gaps, and develop remediation plans.
- Build cybersecurity strategies and roadmaps aligned with business needs and regulatory requirements.
- Develop, review, and maintain policies, procedures, standards, and related documentation.
- Perform risk assessments and track mitigation actions.
- Gather audit evidence and coordinate with internal and external stakeholders.
- Prepare reports, findings, gap‑analysis summaries, and status updates for management.
- Support customers in improving governance and compliance maturity.
- Contribute to continuous improvement of GRC processes, templates, and methodologies.
Required profile
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, IT or related field.
- Minimum 3 years of experience in GRC, cybersecurity, compliance, risk management or audit.
- Hands‑on experience with security audits, compliance assessments, gap analysis or control reviews.
- Good knowledge of Saudi cybersecurity frameworks (Aramco CCCCST, NCA ECC/OTCC/DCC/CCCS) and SAMA requirements (CSF, MVC, CRFR).
- Understanding of ISO 27001, NIST, CIS Controls or similar standards.
- Strong analytical, reporting and communication skills.
- Ability to work collaboratively with cross‑functional teams and manage multiple tasks.
Required skills
- Security audits
- Compliance assessments
- Gap analysis
- Risk assessments
- Knowledge of Saudi frameworks: Aramco CCCCST, NCA ECC/OTCC/DCC/CCCS, SAMA CSF/MVC/CRFR
- ISO 27001
- NIST
- CIS Controls
Questions fréquentes
Why are you reporting this job?
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 week ago
Expires 1 month from now
9 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Managed.sa
Riyad
Related job offers
-
Network Security Engineer – Level 3
sirar by stc Riyad -
Senior Innovation Consultant
Elm Company Riyad -
Scrum Master / Project Manager (Arabic Speaker) – Riyadh
Capco Riyad -
Intern - HQ Science, Technology & Innovation
Islamic Development Bank (IsDB) Djeddah -
Technology & Innovation Intern – IsDB HQ
SDGs @ IsDB Group Djeddah