img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the GRC Specialist Role

Mina Excellence is seeking a GRC (Governance, Risk & Compliance) Specialist to join our team in Riyadh, Saudi Arabia. This is a full-time position focused on supporting our cybersecurity consulting and compliance services. The specialist will play a key role in helping organizations establish effective governance frameworks, assess cybersecurity risks, ensure compliance with local and international standards, and strengthen their overall security posture. This role requires a strong understanding of cybersecurity frameworks, risk management principles, and regulatory requirements specific to Saudi Arabia.

Key Responsibilities

  • Develop and maintain cybersecurity policies, standards, and procedures.
  • Conduct cybersecurity risk assessments and manage risk registers.
  • Perform compliance and gap assessments against frameworks such as NCA ECC, SAMA CSF, ISO 27001, and NIST CSF.
  • Support clients in implementing governance and compliance programs.
  • Prepare audit documentation and coordinate internal and external cybersecurity audits.
  • Track remediation plans and ensure timely closure of compliance findings.
  • Conduct third-party and vendor security assessments.
  • Prepare governance reports, risk dashboards, and executive presentations.
  • Support awareness initiatives related to cybersecurity governance and compliance.
  • Stay current with cybersecurity regulations and emerging best practices.

Educational and Experience Requirements

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or a related field.
  • 2โ€“5 years of experience in Governance, Risk & Compliance.

Technical Knowledge and Frameworks

  • Demonstrated knowledge of Saudi cybersecurity regulations, including NCA ECC and SAMA CSF.
  • Experience with industry frameworks such as ISO 27001, NIST CSF, COBIT, or CIS Controls.
  • Proven experience supporting cybersecurity audits and risk management activities.

Professional Skills and Attributes

  • Strong analytical and problem-solving skills.
  • Excellent documentation and report-writing abilities.
  • Strong communication and stakeholder management skills.
  • High attention to detail and organizational skills.
  • Ability to manage multiple projects and deadlines effectively.
  • A proactive mindset with a passion for governance and continuous improvement.

Preferred Certifications

Candidates with professional certifications are preferred. These include, but are not limited to:

  • ISO 27001 Lead Auditor/Implementer
  • CISA (Certified Information Systems Auditor)
  • CRISC (Certified in Risk and Information Systems Control)
  • CGRC (Certified in Governance, Risk and Compliance)

Requirements

  • Requires 2-5 Years experience

Similar Jobs