
CCDS
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
🇸🇦 Riyadh, Saudi Arabia🏢 On-site
CybersecurityGRCISO/IEC 27001NCA ControlsRisk AssessmenteGRC
At a Glance
- Category
- 💻 Technology
- Level
- Mid-Level
- Type
- Full-time
What's Your Score?
- See the score CCDS's ATS gives your resume
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
Location: On-site – Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 6+ years
Role Purpose
Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.
Key Responsibilities
- Review and periodically update cybersecurity policies, procedures, standards, and guidelines.
- Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.
- Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite.
- Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.
- Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.
- Operate or support eGRC and cybersecurity risk-management tools.
- Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.
Technical and Professional Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- At least 6 years of experience in cybersecurity governance, risk, and compliance.
- Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.
- Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.
Personal Requirements
- Strong stakeholder-management skills and confidence working with senior leadership.
- Excellent analytical, writing, presentation, and documentation skills.
- Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.
Professional Certifications
Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).
Requirements
- •Bachelor’s degree in Computer Science, Information Security, or a related field
- •At least 6 years of experience in cybersecurity governance, risk, and compliance
- •Advanced knowledge of Saudi and international cybersecurity frameworks (NCA, ISO/IEC 27001)
- •Proven experience with risk registers, treatment plans, third-party risk, and executive reporting
- •Experience with eGRC and cybersecurity risk-management tools
- •Strong stakeholder-management skills
- •Excellent analytical, writing, presentation, and documentation skills
- •Detail-oriented and able to coordinate remediation across multiple teams
Nice to Have
- •CISSP certification
- •CISM certification
- •CRISC certification
- •ISO/IEC 27001 Lead Implementer (LI)
Responsibilities
- •Review and periodically update cybersecurity policies, procedures, standards, and guidelines
- •Perform cybersecurity risk assessments covering assets, systems, projects, and third parties
- •Maintain the cybersecurity risk register and develop treatment plans
- •Conduct compliance gap assessments against NCA controls and ISO/IEC 27001
- •Support internal and external audits and manage non-compliance cases
- •Operate or support eGRC and cybersecurity risk-management tools
- •Prepare management reports, executive dashboards, KPIs, and committee-level presentations
Related Jobs4 similar jobs
Browse Similar
Apply Now
What's Your Score?
- See the score CCDS's ATS gives your resume
- Get AI-rewritten bullet points
- Download Gulf-ready CV
60 seconds. $5.88 one-time.
GCC Info
Apply Now



