JOB DETAILS

Refine your listings

Senior GRC Consultant - Cybersecurity

Saudi Arabia

Job ID SNS-1043

Posted On
08-Feb-2026
(180 days ago)

Job type
Permanent

Sector
Technology

  • Lead and deliver enterprise-wide Cybersecurity Governance, Risk, and Compliance (GRC) engagements.
  • Provide advisory and hands-on support across regulatory compliance, cyber risk management, and security governance initiatives.
  • Design, implement, and maintain cybersecurity governance frameworks, policies, standards, and procedures.
  • Perform cyber risk assessments, control gap analyses, and risk treatment planning.
  • Lead and support regulatory, internal, and external audits, including remediation tracking and closure.
  • Ensure compliance with applicable regulatory and industry standards (e.g., NCA, SAMA, ISO 27001, NIST, CIS, PCI DSS, GDPR where applicable).
  • Develop and maintain risk registers, compliance dashboards, and executive-level reporting.
  • Conduct third-party and vendor risk assessments and ongoing compliance monitoring.
  • Define, monitor, and report on security controls, KRIs, and KPIs.
  • Support incident response governance, post-incident reviews, and corrective action plans.
  • Work closely with SOC, infrastructure, application, and cloud security teams to ensure control effectiveness.
  • Lead and contribute to RFP, RFQ, and RFI responses related to cybersecurity and GRC services.
  • Develop technical and compliance responses, solution approaches, and governance models for client proposals.
  • Support bid management activities, including scope definition, assumptions, risk identification, and pricing inputs.
  • Participate in client presentations, clarifications, and proposal defenses.
  • Hands-on implementation and testing of security controls across on-prem, cloud, and hybrid environments.
  • Practical experience with ISO 27001 ISMS implementation, risk assessments, and certification readiness.
  • Working knowledge of GRC platforms/tools (e.g., ServiceNow GRC, Archer, or equivalent).
  • Ability to translate regulatory requirements into practical, implementable security controls.
  • Engage with senior management and executives to articulate cyber risk posture and compliance status.
  • Act as a liaison with regulators, auditors, and external assessors.
  • Provide advisory input during digital transformation and cybersecurity initiatives.
  • 8+ years of experience in Cybersecurity, GRC, Risk, or Compliance.
  • Strong exposure to regulated sectors (banking, government, critical infrastructure, large enterprises).
  • Professional certifications preferred: CISSP, CISM, CRISC, ISO 27001 LA/LI, CGRC.
  • Bachelor’s degree in Information Security, Computer Science, or a related field.
Back to list