img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Opportunity

ASAS for Developing & Operating Industrial Cities is seeking an IT Risk & Compliance Officer to join our team in Riyadh, Saudi Arabia. This full-time role is central to overseeing the implementation of IT risk management and compliance operations, ensuring adherence to approved policies, controls, and standards. The officer will play a key role in mitigating technical risks and enhancing governance and business continuity across the organization.

Core Responsibilities

  • Oversee the implementation of IT risk management processes in accordance with approved methodologies and policies, ensuring effective risk identification, assessment, and treatment.
  • Monitor and update the IT risk register, evaluating risk likelihood and impact, and providing necessary recommendations for mitigation.
  • Track the execution of risk treatment plans and corrective actions, measuring progress and ensuring the closure of observations.
  • Ensure compliance with established policies, controls, frameworks, and standards, including COBIT, ISO 27001, ISO 20000, and other relevant regulatory controls.
  • Conduct and monitor compliance self-assessments, analyzing results to identify opportunities for improvement.
  • Coordinate with relevant departments to ensure the implementation of governance and compliance requirements and address non-compliance cases.
  • Support internal, external, and regulatory audits by providing required evidence and documentation, and following up on the implementation of recommendations.
  • Review and evaluate technical and procedural controls, proposing enhancements to strengthen compliance and reduce risks.
  • Prepare and submit comprehensive risk and compliance reports, including key risks and recommendations, to management.
  • Promote awareness of risk management and compliance practices, offering advisory support to departments regarding policies, controls, and standards.
  • Oversee the documentation and periodic update of policies, procedures, risk registers, and compliance records.
  • Participate in developing and improving governance, risk management, and compliance processes in line with best practices.
  • Monitor the preparation of periodic reports and performance indicators related to risks and compliance.
  • Support continuous improvement initiatives to enhance the maturity level of governance and risk management.
  • Perform any other tasks within the scope of specialization and job level.

Qualifications and Experience

  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Computer Engineering, Business Administration, or a related field.
  • A minimum of 4 years of experience in IT Governance, Risk Management, Compliance, Audit, or Cybersecurity.

Preferred Professional Certifications

  • COBIT Foundation
  • ISO/IEC 27001 Foundation or Lead Implementer
  • ISO 31000 Risk Management
  • CRISC
  • CGEIT
  • ITIL® 4 Foundation

Essential Skills

  • IT Governance
  • IT Risk Management
  • Compliance Management
  • Controls and Internal Audit Management
  • Proficiency with COBIT, ISO 27001, ISO 20000, and ISO 31000 standards.
  • Risk Analysis and Reporting
  • Performance Indicator and Dashboard Management (*, Power BI, Excel)
  • Analytical Thinking
  • Risk Assessment and Management
  • Accuracy and Attention to Detail
  • Executive Report Preparation
  • Strong Communication and Coordination Skills
  • Stakeholder Management
  • Problem Solving and Decision Making
  • Planning and Organization
  • Ability to work effectively in a team.

Application Information

We invite qualified candidates to apply for this full-time position. The salary for this role will be discussed during the interview process.


Requirements

  • Requires 5-10 Years experience

Similar Jobs