Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Indexed description
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 6+ years
Role Purpose
Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.
Key Responsibilities
- Review and periodically update cybersecurity policies, procedures, standards, and guidelines
- Perform cybersecurity risk assessments covering assets, systems, projects, and third parties
- Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite
- Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks
- Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure
- Operate or support eGRC and cybersecurity risk-management tools
- Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations
- Bachelor's degree in Computer Science, Information Security, or a related field
- At least 6 years of experience in cybersecurity governance, risk, and compliance
- Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001
- Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools
- Strong stakeholder-management skills and confidence working with senior leadership
- Excellent analytical, writing, presentation, and documentation skills
- Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search