S
IT GRC Specialist
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 3–5 yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 days ago
- Work mode
- In office
- Education
- Bachelor's degree in IT or related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
We are seeking an IT GRC Specialist to enhance IT governance, risk management, and compliance functions within our financial services organization. This role centers on ensuring adherence to Saudi Arabian regulatory standards, facilitating audits, assessing IT risks, and bolstering cybersecurity and governance frameworks.
Key Responsibilities
- Support compliance efforts aligned with NCA, CMA, PDPL, and other relevant regulations.
- Assist in the implementation and upkeep of IT governance and cybersecurity frameworks, focusing on ISO 27001 and related standards.
- Create, evaluate, and update IT policies, procedures, protocols, and controls.
- Manage and update the IT risk register while tracking remediation efforts.
- Perform risk assessments for IT systems and cybersecurity measures related to vendors and third-party relationships.
- Facilitate internal and external audit processes by organizing evidence collection and addressing follow-up actions.
- Track compliance statuses and develop governance and risk reporting for management review.
- Collaboratively engage with IT, Security, Risk, and Business departments to enhance control effectiveness and readiness for regulatory requirements.
Qualifications and Requirements
- Bachelor's degree in Information Technology, Information Systems, Cybersecurity, or a similar field.
- 3 to 5 years experience in IT Governance, Risk & Compliance (GRC), IT Audit, Information Security, or equivalent roles; experience in the GCC region is advantageous.
- Mandatory certifications: CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), ISO 27001 Lead Implementer or Auditor.
- Familiarity with regulatory frameworks including NCA ECC, ISO 27001, PDPL, and compliance mandates specific to the financial sector is preferred.
- Background in financial services, fintech, banking, or capital markets adds value.
- Deep understanding of IT governance, risk management, and compliance fundamentals.
- Knowledge of IT controls such as access management, change management, vulnerability management, and disaster recovery procedures.
- Strong skills in documentation, reporting, and coordinating audits.
- Analytical mindset coupled with effective stakeholder management skills.
- Proficiency in both Arabic and English languages.
Minimum education
Bachelor's Degree