img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

J-B is seeking a GRC Manager Cybersecurity to lead the daily execution of its cybersecurity governance, risk, and compliance (GRC) program. This full-time position is based in Riyadh, Saudi Arabia, within a SAMA-regulated financing company. The role involves managing a team of GRC analysts/officers, maintaining the risk register, and providing clear reporting on the organization’s risk and compliance posture to senior leadership. The GRC Manager Cybersecurity reports directly to the Chief of Cybersecurity.

Key Responsibilities

  • Ensure the cybersecurity GRC program maintains full compliance with SAMA Cyber Security Framework (CSF) requirements, including periodic self-assessments and regulatory reporting.
  • Execute and continuously enhance the organization’s cybersecurity governance policies, procedures, and standards, aligning with SAMA requirements, industry best practices, and business objectives.
  • Lead enterprise-wide risk assessments and gap analyses, maintain the risk register, and present findings and remediation plans to senior leadership.
  • Oversee the monitoring and continuous improvement of the cybersecurity controls framework across the organization.
  • Collaborate with stakeholders across IT, legal, audit, and business units to integrate cybersecurity risk management into operational decisions.
  • Lead, mentor, and develop a team of GRC analysts/officers, managing workload, performance, and professional growth.
  • Serve as a subject-matter expert on cybersecurity GRC and SAMA compliance, providing risk and compliance reporting to senior leadership.
  • Manage the cybersecurity awareness and training program, driving organization-wide adoption.
  • Coordinate cybersecurity incident response governance, including cross-functional response coordination, post-incident review, and reporting to leadership, with regulatory notification where required by SAMA.
  • Manage day-to-day relationships with SAMA, external auditors, and third-party assessors, overseeing audit readiness and remediation tracking.
  • Monitor the regulatory and threat landscape, translating emerging requirements into program-level recommendations.
  • Support GRC tooling evaluation and vendor coordination for platforms such as GRC, SIEM, and vulnerability management.

Required Qualifications and Experience

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; a Master’s degree is a plus.
  • 5-8 years of cybersecurity GRC experience, preferably within a SAMA-regulated entity (bank, finance company, or insurance), including 2+ years in a team leadership capacity.
  • Certifications such as CISSP, CISM, or CISA are required; CRISC is a plus.
  • Deep expertise in cybersecurity frameworks and regulations, particularly SAMA Cyber Security Framework (CSF), NCA ECC, NIST, and ISO 27001.
  • Proven track record leading risk assessments, compliance audits, and remediation programs, ideally including SAMA self-assessments.
  • Experience managing cross-functional teams and coordinating with vendors and regulators.

Essential Skills and Knowledge

  • Strong, hands-on knowledge of SAMA Cyber Security Framework (CSF) and its practical application in a financing sector context.
  • Solid understanding of GRC principles and enterprise risk management.
  • Familiarity with NCA ECC and other applicable Saudi regulatory requirements.
  • Demonstrated people leadership skills, including coaching, performance management, and capacity planning.
  • Program and project management skills to effectively run multi-stakeholder GRC initiatives.
  • Familiarity with GRC platforms and the broader security tooling landscape.
  • Strong cross-functional collaboration abilities, particularly with IT, legal, compliance, and audit teams.
  • Excellent communication skills, with the ability to translate technical risk into business impact for senior leadership.
  • Strong strategic thinking, people management, and stakeholder influence skills.

Work Environment and Reporting

This full-time role operates within the financing sector, which is regulated by SAMA. The GRC Manager Cybersecurity will lead a dedicated team of GRC analysts/officers and report directly to the Chief of Cybersecurity, contributing to the organization's robust cybersecurity posture in Riyadh.

Application Process

Candidates meeting the specified qualifications and experience are encouraged to apply for this position.


Requirements

  • Requires 5-10 Years experience

Similar Jobs