Cybersecurity GRC Specialist - Riyadh
Sifi, based in Riyadh, Saudi Arabia, is seeking to hire a qualified and experienced Cybersecurity Governance, Risk, and Compliance (GRC) Specialist. This role emerges at a time when the Kingdom is witnessing a surge in digital transformation and an increased focus on strengthening cybersecurity infrastructure, aligning with Saudi Vision 2030 and its strategic goals of building a secure and resilient digital economy.
Job Description
The selected specialist will be responsible for designing, implementing, and managing the organization's information security governance, risk, and compliance framework. They will act as a vital link between technical and business requirements to ensure security practices align with internal policies and local/international regulatory standards.
Key Expected Responsibilities:
- Governance: Develop and maintain information security policies, standards, procedures, and guidelines. Ensure effective communication of these policies across the organization and monitor compliance.
- Risk Management: Lead and conduct periodic, systematic information security risk assessments. Identify security vulnerabilities, assess threat levels, and estimate potential business impact. Develop risk treatment plans and monitor their implementation.
- Compliance: Ensure the organization's compliance with relevant cybersecurity regulations and policies in Saudi Arabia, such as the (National Cybersecurity Authority Framework) issued by the National Cybersecurity Authority (NCA), as well as global standards like ISO 27001 and PCI-DSS if relevant to the company's operations.
- Audit Oversight: Coordinate with internal and external audit teams to support information security audit activities. Prepare necessary reports, provide evidence of compliance, and follow up on corrective action plans.
- Awareness & Culture: Contribute to employee security awareness programs to foster a security-conscious culture within the organization.
- Reporting: Prepare periodic reports for risk management and stakeholders on the status of information security, risks, and compliance levels.
Requirements and Qualifications
To be a successful candidate for this position, you should meet the following requirements:
Essential Qualifications:
- A Bachelor’s degree in a relevant field such as Information Security, Computer Science, Information Technology, or equivalent.
- Proven practical experience of at least 3 to 5 years in the field of Cybersecurity Governance, Risk, and Compliance (GRC).
- In-depth knowledge of cybersecurity frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, and the Saudi National Cybersecurity Authority Framework.
- Strong understanding of data protection regulations and compliance relevant to the Saudi market.
- Excellent analytical skills and the ability to assess complex risks and provide practical recommendations.
- Outstanding written and verbal communication skills in both Arabic and English, with the ability to explain technical concepts to non-technical stakeholders.
- Ability to work independently and in a team within a dynamic environment.
Preferred Qualifications (Additional):
- Holding recognized professional certifications such as: CRISC, CISM, CISSP, or ISO 27001 Lead Auditor/Implementer.
- Previous experience in vital sectors such as finance, telecommunications, or energy.
- Knowledge of specialized GRC technologies and tools.
Work Location & Benefits
- Location: Riyadh, Kingdom of Saudi Arabia.
- Job Type: Full-time.
- This opportunity offers joining a leading organization in a stimulating work environment, with the potential to contribute directly to enhancing the organization's security posture in a fast-growing market.
How to Apply
Applications for this position are submitted via the Naukrigulf platform. Please search for the job titled "Cybersecurity GRC Specialist" in Riyadh city and company "Sifi" or follow the direct link if available. Ensure your Curriculum Vitae (CV) is updated to highlight your experience and skills relevant to the job requirements mentioned above, including any professional certifications you hold.
Given the competitive nature of such specialized roles, qualified candidates are advised to apply at their earliest convenience.