img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

TawanTech is seeking a Senior Governance, Risk & Compliance (GRC) Specialist to join our team in Riyadh, Riyadh Province. This full-time role is central to leading and strengthening the organization's GRC framework. The successful candidate will ensure compliance with regulatory requirements, industry standards, and internal governance policies, while also driving enterprise risk management initiatives.

Key Responsibilities

  • Develop, implement, and maintain Governance, Risk & Compliance (GRC) policies, standards, frameworks, and procedures.
  • Lead enterprise-wide risk assessments and manage the organization's risk register.
  • Identify, assess, monitor, and report on operational, technology, cybersecurity, and compliance risks.
  • Ensure adherence to banking regulations, regulatory requirements, and internal governance policies.
  • Perform control assessments and gap analyses to evaluate the effectiveness of security and compliance controls.
  • Coordinate internal audits, external audits, and regulatory examinations, ensuring timely remediation of findings.
  • Track audit observations, compliance issues, and risk mitigation plans through to closure.
  • Prepare governance reports, compliance dashboards, and executive-level risk reports.

Specialized Compliance and Risk Management

  • Ensure compliance with PCI DSS (Payment Card Industry Data Security Standard) requirements and support PCI DSS assessments, audits, evidence collection, and remediation activities.
  • Collaborate with business and IT teams to implement and maintain PCI DSS security controls across payment environments.
  • Support compliance initiatives related to ISO 27001, NIST CSF, COBIT, and other applicable regulatory and security frameworks.
  • Conduct third-party and vendor risk assessments.
  • Review new projects, systems, and technology initiatives from governance, risk, and compliance perspectives.

Collaboration and Awareness

This role requires close collaboration with business, IT, Information Security, Internal Audit, Compliance, and regulatory authorities to maintain a strong control environment. The Senior GRC Specialist will also promote risk awareness by delivering GRC and compliance training across the organization.

Required Experience and Qualifications

  • A minimum of 9 years of experience in Governance, Risk, and Compliance.
  • Demonstrated experience in developing and implementing GRC frameworks and policies.
  • Proven ability to manage enterprise risk assessments and maintain risk registers.
  • Strong understanding of banking regulations, industry standards, and internal governance policies.
  • Familiarity with PCI DSS, ISO 27001, NIST CSF, COBIT, and other relevant security frameworks.

Professional Development

The specialist is expected to stay current with emerging regulatory requirements and recommend improvements to governance and compliance processes, contributing to the continuous enhancement of the organization's control environment.


Requirements

  • Requires 5-10 Years experience

Similar Jobs