Role Purpose:
To lead and oversee the organization's Governance, Risk, and Compliance (GRC) cybersecurity framework by driving the implementation, monitoring, and continuous improvement of cybersecurity initiatives. The role ensures full alignment with Saudi regulatory requirements and internal policies while proactively managing cybersecurity risks, strengthening governance practices, and enhancing the organization's overall security posture.
Key responsibilities:
- Lead the development, implementation, and continuous enhancement of the organization's cybersecurity governance framework in alignment with Saudi cybersecurity regulations and industry best practices.
- Oversee the identification, assessment, and mitigation of cybersecurity risks within the enterprise risk management framework, ensuring effective risk treatment strategies are in place.
- Monitor and enforce compliance with cybersecurity policies, standards, and frameworks, providing regular insights and strategic updates to the Head of GRC and Cybersecurity.
- Manage and coordinate internal and external cybersecurity audits, regulatory assessments, and ensure timely closure of audit findings.
- Conduct and supervise periodic risk assessments, ensuring all gaps are clearly documented, prioritized, and addressed through actionable remediation plans.
- Own and maintain the cybersecurity risk register, ensuring accurate tracking, reporting, and follow-up on mitigation actions.
- Lead the design and delivery of cybersecurity awareness and training programs to enhance organizational security culture.
- Oversee the monitoring of security incidents, ensuring effective coordination with IT and third-party vendors for timely response, escalation, and resolution.
- Supervise third-party cybersecurity risk management activities, ensuring vendors comply with the organization's security requirements and contractual obligations.
- Prepare and present comprehensive reports on cybersecurity risks, compliance status, KPIs, and performance metrics to senior leadership and board-level committees.
- Stay informed on emerging cybersecurity threats, trends, and regulatory changes, and proactively recommend strategic improvements and controls.
- Provide guidance and mentorship to junior team members, ensuring knowledge sharing and capability development within the team.
Qualifications:
- Bachelor's degree in Cybersecurity, Information Security, Information Technology, or a related field.
- Preferred certifications: CISA, CISM, ISO 27001 Lead Implementer/Auditor, CRISC, or equivalent.
- Strong proficiency in Microsoft Office Suite (Word, Excel, PowerPoint, Outlook).
- Excellent written and verbal communication skills in both English and Arabic.
- 5–7 years of experience in cybersecurity governance, risk, and compliance, with demonstrated experience in leading initiatives or supervising teams.