Search by job, company or skills

General Manager Governance, Risk & Compliance

  • Posted an hour ago
  • Be among the first 10 applicants

Job Description

Position Title

General Manager, Governance, Risk & Compliance (GRC)

Function / Department

Governance, Risk & Compliance

Reports to

Chief Executive Officer | Functional access to the Board Risk / Audit Committee on risk & compliance matters

Direct Reports

Risk Manager, Compliance Manager, Governance / Policy Lead, Data Privacy Officer (as applicable)

Grade / Band

General Manager

Location

Jeddah, Saudi Arabia

JOB PURPOSE

Design, implement, and maintain integrated governance, enterprise risk management, and compliance frameworks, enabling the organization to identify, assess, and manage its principal risks and to comply with applicable laws, regulations, and governance requirements — including corporate governance regulations (e.g., CMA) and listing readiness where applicable. The role strengthens the second line of defense and embeds a risk-aware, ethical culture that supports sustainable value creation.

KEY RESPONSIBILITIES

  • Corporate governance. Develop and maintain the corporate governance framework, governance manual, Delegation of Authority (DoA), Code of Conduct, and committee charters (management support), aligned to applicable corporate governance regulations (e.g., CMA) and the Companies Law.
  • Enterprise Risk Management (ERM). Establish and operate the ERM framework (aligned to ISO 31000 / COSO ERM); define and maintain risk appetite and tolerances, the enterprise risk register, and key risk indicators; facilitate risk assessments and report to executive management and the Board Risk Committee.
  • Compliance program. Build and run the compliance program; maintain the regulatory obligations / compliance universe; monitor regulatory change; perform compliance monitoring and testing; and manage the whistleblowing / speak-up channel.
  • Internal control framework. Own the design and coordination of the internal control framework and control self-assessments (second line), and coordinate remediation.
  • Policy governance. Govern the full policy lifecycle — development, approval, publication, and periodic review — and maintain the central policy repository.
  • IPO readiness. Lead governance, risk, and compliance workstreams supporting listing requirements and post-listing obligations, where [Vertical Name] is preparing for or subject to public listing.
  • Data privacy. Oversee compliance with the Saudi Personal Data Protection Law (PDPL) and related data-governance obligations.
  • Ethics & culture. Championing a risk-aware and ethical culture across the organization, including awareness and training programs.
  • Business continuity. Oversee (or coordinate) business continuity and crisis-management frameworks, as mandated.
  • Reporting & analytics. Produce consolidated GRC reporting and dashboards for executive management and Board committees.
  • People leadership. Lead, develop, and retain the GRC team across governance, risk, and compliance disciplines.
  • Technology. Implement and optimize GRC platforms and tooling to integrate risk, control, and compliance data.

KEY PERFORMANCE INDICATORS

  • Residual risk maintained within approved risk appetite.
  • Number and severity of compliance breaches / regulatory findings.
  • Policy currency (percentage of policies within review cycle).
  • Control effectiveness from second-line testing and self-assessment.
  • Completion of governance and compliance milestones, including listing readiness where applicable.
  • Timeliness and accuracy of regulatory reporting and submissions.

QUALIFICATIONS & EXPERIENCE

  • Bachelor's degree in law, Finance, Business, or a related discipline.
  • 10+ years in governance, risk, and/or compliance; listed-company or IPO-track experience is advantageous.
  • Proven track record establishing or leading ERM, compliance, and governance frameworks at group level.
  • Strong working knowledge of applicable regulations (e.g., CMA), Companies Law, PDPL, and the COSO / ISO 31000 frameworks.

PROFESSIONAL CERTIFICATIONS

  • One or more of CRMA, CRISC, CGEIT, GRCP, CCEP, CFE, or ISO 31000 Lead — advantageous.

CORE COMPETENCIES

  • Integrity and an enterprise-wide risk mindset.
  • Regulatory and governance acumen.
  • Ability to influence and drive changes without direct authority.
  • Strategic thinking is balanced with pragmatic execution.
  • Strong stakeholder management across the first line, executive, and Board.

More Info

Job Type:
Industry:
Employment Type:

Job ID: 151900149

Similar Jobs

Saudi Arabia, Jeddah

Skills:

business continuity management Cybersecurity policiesTechnical know-howRisk management frameworksCybersecurity GRC strategyDisaster recovery plans

Beware of Scammers

We don’t charge money for job offers