Job Title: Cybersecurity Specialist (GRC & Risk)
Location: Saudi Arabia, Riyadh
Duration: Outsource with AIQU , Yealy extendable
We are seeking an experienced Cybersecurity Specialist with strong hands-on expertise in Cybersecurity Risk Management and Governance, Risk, and Compliance (GRC). The ideal candidate will have practical experience in cybersecurity risk assessments, governance, compliance, incident handling, and regulatory requirements.
Key Responsibilities
- Conduct hands-on cybersecurity risk assessments for applications, networks, infrastructure, third-party vendors, technology projects, and organizational changes.
- Identify, analyze, and evaluate cybersecurity risks by assessing likelihood and business impact.
- Maintain the cybersecurity risk register and develop, track, and follow up on risk treatment and mitigation plans.
- Develop, review, and maintain cybersecurity governance documentation, including policies, procedures, standards, frameworks, and guidelines.
- Assess compliance with applicable NCA Cybersecurity Controls and review supporting evidence.
- Identify compliance gaps, document findings, and coordinate with stakeholders to ensure timely remediation and closure.
- Support internal and external cybersecurity audits, regulatory assessments, and compliance reviews.
- Investigate cybersecurity incidents and Security Operations Center (SOC) alerts, perform initial analysis, assess impact, escalate when required, and monitor remediation activities.
- Maintain strong technical knowledge of cybersecurity vulnerabilities, security controls, infrastructure configurations, and remediation approaches.
- Collaborate with technical and business teams to strengthen the organization's cybersecurity posture.
Required Qualifications
- Minimum 3 years of hands-on experience in Cybersecurity Risk Management and GRC.
- Strong practical experience conducting cybersecurity risk assessments (not limited to coordinating assessments or project management).
- Experience developing and implementing cybersecurity governance documentation.
- Solid understanding of NCA Cybersecurity Controls and compliance requirements.
- Experience supporting cybersecurity audits and regulatory assessments.
- Knowledge of cybersecurity incident response and SOC operations.
- Good understanding of network, infrastructure, applications, security technologies, vulnerabilities, and security controls.
- Excellent analytical, communication, and stakeholder management skills.