img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Governance Risk Compliance Specialist Role

NourNet is seeking an experienced Governance Risk Compliance Specialist (GRC) to join its client’s technology team in Riyadh. This is a full-time, on-site position requiring 5-10 years of relevant experience. The role focuses on establishing and maintaining robust cybersecurity governance and risk management frameworks.

Role Overview and Objectives

The primary objective of this role is to develop and sustain comprehensive cybersecurity governance and risk management frameworks for the client project. This includes ensuring strict alignment with both regulatory mandates and established industry standards. The specialist will leverage a strong background in secure-by-design principles, cloud security, and enterprise architecture governance to achieve these objectives.

Key Responsibilities

  • Maintain and update cybersecurity policies, standards, and procedures for the client, ensuring alignment with SAMA, NCA ECC, ISO 27001, NIST CSF, and applicable local regulations.
  • Lead periodic cyber risk assessments across systems, projects, and business processes.
  • Maintain and manage the Cyber Risk Register, including recording risks, assigning owners, documenting mitigation plans, and tracking status.
  • Coordinate risk treatment activities with business and IT owners, encompassing risk acceptance and mitigation tracking.
  • Produce governance reporting and dashboards, including Key Risk Indicators (KRIs), for management and risk committees.
  • Ensure Security Operations Center (SOC) operational activities map to governance requirements and control frameworks.
  • Support regulatory self-assessments, gap analyses, and remediation planning.
  • Manage exceptions and control deficiencies through formal governance processes.
  • Provide stakeholder engagement, training, and awareness to ensure governance adoption.

Candidate Profile and Experience

The ideal candidate will possess 5-10 years of experience and demonstrate a proven track record in conducting risk assessments and maintaining risk registers. Required experience also includes policy governance, control mapping, exception management, and governance reporting within a cybersecurity context.

Technical Acumen and Regulatory Standards

Candidates must have a strong understanding of secure-by-design principles, cloud security, and enterprise architecture governance. Proficiency in aligning cybersecurity practices with key regulatory and industry standards such as SAMA, NCA ECC, ISO 27001, NIST CSF, and other applicable local regulations is essential for this role.

Work Environment

This is a full-time position based entirely on-site in Riyadh. The role involves working closely with the client's technology team to implement and maintain cybersecurity governance frameworks.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة