C
Cyber Security GRC Specialist
Jeddah, Makkah Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 2–4 yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 weeks ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Cyber
At Cyber, we are dedicated to enhancing organizational resilience by implementing strong cybersecurity governance, risk management, and compliance measures. Our operations align with the regulatory requirements of Saudi Arabia including NCA and SAMA, as well as international standards.
Key Responsibilities
- Design, uphold, and revise cybersecurity governance frameworks, policies, and standards.
- Track compliance with cybersecurity policies and controls across the company.
- Deliver periodic governance and risk assessment reports to the CISO and senior leadership.
- Keep cybersecurity documentation updated in accordance with regulations and industry norms.
- Perform thorough cybersecurity risk evaluations across departments and cloud infrastructures.
- Assess, rank, and prioritize cybersecurity risks effectively.
- Maintain and refresh the risk register regularly.
- Manage remediation processes and ensure prompt resolution of risks and audit issues.
- Ensure compliance with Saudi regulatory bodies such as NCA ECC and SAMA CSF and international standards like ISO 27001.
- Assist with internal and external audits.
- Assess the performance of security controls implemented.
- Compile and deliver regulatory compliance documentation as needed.
- Help develop and update Business Continuity and Disaster Recovery strategies.
- Support Business Impact Analysis (BIA) activities and participate in continuity and recovery tests.
- Take part in incident response to reduce operational impacts.
- Promote cybersecurity awareness and culture within the company.
- Manage cybersecurity awareness programs and tools.
Qualifications & Requirements
- A Bachelor's degree in Cybersecurity, Information Security, Computer Science, or a related discipline.
- 2 to 4 years’ direct experience in Cybersecurity GRC or equivalent roles.
- Proficient knowledge of governance frameworks, risk management strategies, and compliance procedures.
- Familiarity with Saudi Arabian regulations (NCA, SAMA) and international standards like ISO 27001.
- Practical experience with GRC-related software is advantageous.
Preferred Certifications
- ISO 27001 Lead Implementer certification.
- CompTIA Security+ certification.
- Additional relevant GRC certifications are considered a plus.
Minimum education
Bachelor's Degree
Industry
CybersecurityHow they work
Organisation
required