img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role

HRsource is seeking an Information Security Compliance Consultant for a full-time position in Riyadh, Saudi Arabia. This role is dedicated to supporting information security and data protection compliance activities within the region. It is not a technical cybersecurity role; instead, it focuses on compliance, documentation, governance, regulatory coordination, and audit support, requiring 5-10 years of relevant experience.

Key Responsibilities

The consultant will serve as a key local representative for information security and personal data protection compliance. Responsibilities include:

  • Acting as the local point of contact with Saudi regulatory authorities, including NCA and SDAIA, and monitoring regulatory updates and requirements.
  • Coordinating regulatory communications, submissions, responses, and required documentation through official channels.
  • Supporting compliance with the Saudi Personal Data Protection Law (PDPL), including identifying and documenting personal data processing activities.
  • Preparing and maintaining PDPL-related filings, declarations, policies, procedures, and employee communications.
  • Supporting the localization of global cybersecurity policies and frameworks to align with applicable Saudi requirements, such as NCA Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC).
  • Developing and maintaining a structured Compliance Evidence Repository to ensure audit traceability and readiness.
  • Collecting, organizing, and maintaining comprehensive compliance evidence, coordinating with internal stakeholders and auditors.
  • Coordinating information security and PDPL awareness training for local employees and assisting with basic compliance checks for local vendors and third parties.

Required Qualifications and Experience

Candidates should demonstrate a strong foundation in compliance and information security, supported by:

  • Minimum 5-10 years of experience in compliance, IT governance, regulatory affairs, audit support, or information security-related roles.
  • Strong understanding of information security, data protection, and regulatory compliance concepts.
  • Professional English proficiency, including the ability to understand security standards and prepare clear written reports.
  • Demonstrated ability to prepare clear and professional government and regulatory correspondence.
  • Strong attention to detail and a high level of documentation discipline.
  • Ability to effectively manage compliance requirements, evidence, records, and follow-up activities.
  • Comfort working collaboratively with senior stakeholders, auditors, regulators, IT teams, and business functions.

Preferred Skills and Certifications

The following qualifications and experiences are considered advantageous for this position:

  • Previous experience working with Saudi government entities or regulatory bodies.
  • Exposure to ISO/IEC 27001 audits or implementation.
  • Exposure to ISO 22301 or SOC 2 audits.
  • Familiarity with NCA Essential Cybersecurity Controls (ECC) and NCA Cloud Cybersecurity Controls (CCC).
  • Knowledge of Saudi PDPL requirements.
  • Relevant certifications such as CompTIA Security+, ISO Internal Auditor, or equivalent.

Success Factors

Success in this role is demonstrated by the ability to interpret regulatory requirements, understand their organizational implications, and coordinate effectively with internal teams. A successful candidate will ensure that all required documentation and evidence are complete, accurate, traceable, and readily available for regulatory reviews and audits. Strong performance will be evident through consistent regulatory alignment, audit readiness, high-quality documentation, and effective coordination across all stakeholders.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة