GRC Specialist
Job Description
Managed.sa is seeking a motivated GRC Specialist to support a cybersecurity project based in Jeddah.
The ideal candidate will have practical experience in Governance, Risk, and Compliance, with a strong interest in cybersecurity risk management. This role requires working closely with business and technical stakeholders to assess risks, maintain compliance documentation, and support the implementation of cybersecurity controls.
Key Responsibilities
- Conduct cybersecurity risk assessments and document identified risks.
- Maintain risk registers, treatment plans, and follow-up actions.
- Support the development and review of cybersecurity policies, procedures, and standards.
- Assess compliance with applicable cybersecurity frameworks and regulatory requirements.
- Identify control gaps and recommend appropriate remediation actions.
- Collect, organize, and review compliance evidence.
- Prepare risk and compliance reports for management and project stakeholders.
- Monitor remediation activities and follow up with relevant teams.
- Support internal and external cybersecurity audits and assessments.
- Coordinate with business, IT, cybersecurity, and project stakeholders.
Requirements
- Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field.
- Approximately 1.5–3 years of relevant experience in cybersecurity GRC.
- Practical experience in cybersecurity risk assessment and risk management.
- Familiarity with cybersecurity frameworks and standards such as:
- NCA ECC
- ISO 27001
- ISO 31000
- NIST Cybersecurity Framework
- Strong documentation, reporting, and stakeholder communication skills.
- Ability to work independently and follow up on multiple risk and compliance activities.
- Professional certifications in GRC, cybersecurity, or risk management are preferred.
- Availability to work full-time on-site in Jeddah.
- Candidates who can join within a short timeframe will be prioritized.
Skills
As published by workable · 10 questions · 1 written answer
Basics
First name, Last name, Email, Phone, Address, Resume, Cover letter
Short answers (2)
- What is your current monthly salary in SAR?
- What is your expected monthly salary in SAR?
Pick from a list (7)
- How many years of professional experience do you have in cybersecurity GRC?
- How would you rate your practical experience in cybersecurity risk assessments?
- Have you previously maintained cybersecurity risk registers and risk treatment plans?
- Are you currently based in Jeddah or Makkah, or able to work on-site in Jeddah?
- What is your nationality?
- What is your notice period?
- Are you comfortable joining a renewable client-based cybersecurity project?
Written answers (1)
- Do you hold any relevant professional certifications?