# Cybersecurity Governance, Risk & Compliance (GRC) Specialist

**Company:** [CCDS](null/companies/jW2GU1cjjZDfo4R2Wur6uh.md)
**Location:** Riyadh, Saudi Arabia
**Workplace:** on site
**Employment type:** Full-time

[Apply for this job](null/view/759f6d45-f72e-42b9-8802-27cc850e0645)

## Description

**Location:** On-site – Riyadh, Saudi Arabia

**Contract/engagement:** Project-based managed cybersecurity services (13-month)

**Minimum experience:** 6+ years

### Role Purpose

Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

### Key Responsibilities

·      Review and periodically update cybersecurity policies, procedures, standards, and guidelines.

·      Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.

·      Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite.

·      Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.

·      Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.

·      Operate or support eGRC and cybersecurity risk-management tools.

·      Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.

## Requirements

### Technical and Professional Requirements

·      Bachelor’s degree in Computer Science, Information Security, or a related field.

·      At least 6 years of experience in cybersecurity governance, risk, and compliance.

·      Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.

·      Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.

### Personal Requirements

·      Strong stakeholder-management skills and confidence working with senior leadership.

·      Excellent analytical, writing, presentation, and documentation skills.

·      Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.

### Professional Certifications

Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).
