Cybersecurity GRC Specialist(Saudi National only
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-08-19
Listing for:
Sifi
Full Time
position Listed on 2026-08-19
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Role Overview
The Cybersecurity GRC Specialist plays a critical role in maintaining Si Fiu
2019s cybersecurity compliance posture and ensuring audit readiness across all regulatory frameworks
This role is responsible for managing the full Governance Regular and Compliance GRC lifecycle including evidence management policy governance risk tracking and KPI KRI reporting ensuring that all cybersecurity controls are measurable defensible and aligned with regulatory expectations
Key Responsibilities1 Regulatory Compliance amp Audit Readiness
- Maintain and manage the compliance tracker across SAMA CSF PDPL NDMO and PCI-DSS
- Own the full evidence lifecycle collection validation and documentation
- Ensure continuous audit readiness with traceable control-aligned evidence
- Track regulatory findings and remediation plans ensuring timely closure
- Provide regular compliance status reports to the CISO and relevant committees
2 Governance amp Policy Management
- Develop and maintain cybersecurity policies standards and procedures
- Ensure documentation aligns with SiFi governance structure and regulatory expectations
- Manage document lifecycle versioning approvals reviews
- Map all policies and procedures to SAMA CSF controls
3 Cyber Risk Management
- Maintain and update the cybersecurity risk register
- Conduct third‑party risk assessments TPRA and vendor due diligence
- Support risk reviews and reporting cycles
- Collaborate with Risk and Compliance teams to align enterprise risk frameworks
4 KPI KRI Monitoring amp Reporting
- Collect and validate cybersecurity KPIs KRIs from relevant stakeholders
- Maintain a centralized KPI KRI tracker
- Prepare periodic reports with trend analysis to support regulatory maturity Level 3
- Identify and escalte performance gaps
- 1-3 years of experience in a dedicated Cybersecurity GRC role
- Hands‑on experience with SAMA CSF compliance within regulated entities
- Experience in audit evidence preparation and regulatory assessments
- Strong background in drafting cybersecurity policies and procedures
- Experience using GRC platforms e g Archer Service Now GRC One Trust etc
- Bachelor's degree in Cybersecurity Information Security Computer Science or related field
- Certifications in ISO 27001 Lead Implementer Lead Auditor Security ISC CC CGRC or CISA or CRISC
- Speaks English and Arabic
- Experience with PDPL and NDMO regulations
- PCI-DSS compliance exposure
- Knowledge of cloud security AWS Azure GCP OCI
- Experience in fintech or financial services
- Familiarity with frameworks like ISO 27001 NIST COBIT
Job role open for Saudi Nationals only
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×