GRC Specialist
- Posted a month ago
- Be among the first 10 applicants
Job Description
Job Description
Managed.sa is seeking a motivated GRC Specialist to support a cybersecurity project based in Jeddah.
The ideal candidate will have practical experience in Governance, Risk, and Compliance, with a strong interest in cybersecurity risk management. This role requires working closely with business and technical stakeholders to assess risks, maintain compliance documentation, and support the implementation of cybersecurity controls.
Key Responsibilities
Managed.sa is seeking a motivated GRC Specialist to support a cybersecurity project based in Jeddah.
The ideal candidate will have practical experience in Governance, Risk, and Compliance, with a strong interest in cybersecurity risk management. This role requires working closely with business and technical stakeholders to assess risks, maintain compliance documentation, and support the implementation of cybersecurity controls.
Key Responsibilities
- Conduct cybersecurity risk assessments and document identified risks.
- Maintain risk registers, treatment plans, and follow-up actions.
- Support the development and review of cybersecurity policies, procedures, and standards.
- Assess compliance with applicable cybersecurity frameworks and regulatory requirements.
- Identify control gaps and recommend appropriate remediation actions.
- Collect, organize, and review compliance evidence.
- Prepare risk and compliance reports for management and project stakeholders.
- Monitor remediation activities and follow up with relevant teams.
- Support internal and external cybersecurity audits and assessments.
- Coordinate with business, IT, cybersecurity, and project stakeholders.
- Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field.
- Approximately 1.5-3 years of relevant experience in cybersecurity GRC.
- Practical experience in cybersecurity risk assessment and risk management.
- Familiarity with cybersecurity frameworks and standards such as:
- NCA ECC
- ISO 27001
- ISO 31000
- NIST Cybersecurity Framework
- Strong documentation, reporting, and stakeholder communication skills.
- Ability to work independently and follow up on multiple risk and compliance activities.
- Professional certifications in GRC, cybersecurity, or risk management are preferred.
- Availability to work full-time on-site in Jeddah.
- Candidates who can join within a short timeframe will be prioritized.
More Info
Key Skills
Cybersecurity risk assessment
ISO 31000
NCA ECC
NIST Cybersecurity Framework
Cybersecurity frameworks



