Search Jobs

Search by job, company or skills

IT GRC Specialist

IT GRC Specialist

sahm capital
  • Posted 8 hours ago
  • Be among the first 10 applicants

Job Description

The IT GRC Specialist to support IT governance, risk management, and compliance activities across the organization. The role is responsible for maintaining compliance with relevant Saudi regulatory requirements, supporting audits, managing IT risks and helping improve cybersecurity and governance practices within a financial services environment.

The IT GRC Specialist's tasks will include but are not limited to:

  • Support compliance initiatives related to NCA, CMA, PDPL and other applicable regulatory requirements.
  • Assist in implementing and maintaining IT governance and cybersecurity frameworks such as ISO 27001 and related standards.
  • Develop, review and maintain IT policies, procedures, standards and controls.
  • Maintain the IT risk register and track remediation activities.
  • Conduct IT and cybersecurity risk assessments for vendors and third parties.
  • Support internal and external audits by coordinating evidence collection and remediation activities.
  • Monitor compliance status and prepare governance and risk reports for management.
  • • Work closely with IT, Security, Risk and Business teams to improve control effectiveness and regulatory readiness.

Bachelor's degree in information technology, Information Systems, Cybersecurity or equivalent degree

3–5 years of experience in IT Governance, Risk & Compliance (GRC), IT Audit, Information Security or a related role, and the GCC region is a plus.

  • Certifications (Must have)
  1. Certified in Risk and Information Systems Control (CRISC)
  2. Certified Information Systems Auditor (CISA)
  3. ISO 27001 Lead Implementer/Auditor

  • Experience working with regulatory frameworks such as NCA ECC, ISO 27001, PDPL or financial-sector compliance requirements is preferred.
  • Experience within financial services, fintech, banking or capital markets is an advantage.
  • Understanding of IT governance, risk management and compliance principles.
  • Familiarity with IT controls including access management, change management, vulnerability management and disaster recovery.
  • Strong documentation, reporting and audit coordination skills.
  • Good analytical and stakeholder management abilities.
  • Fluency in Arabic and English

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Risk and Information Systems Control (CRISC)

PDPL

IT and cybersecurity risk assessments

ISO 27001 Lead Implementer Auditor

NCA

Certified Information Systems Auditor (CISA)

Cybersecurity frameworks

About Company

Similar Jobs

7-10 yrs
Saudi Arabia, Riyadh
Skills:
maturity assessments , Iso 27001, SAMA Cybersecurity Framework, Compliance Reporting, Risk Assessment, IT governance frameworks, risk register management, nist, policy suites, Internal Audit closure processes