GRC Specialist
Description
Müller's Solutions is seeking an experienced GRC specialist to support a SAMA-aligned IT risk and IT compliance assessment programme. The candidate will be responsible for delivering a structured set of project outputs across governance, risk, compliance, and IT process improvement workstreams.
Key responsibilities:
- Develop and deliver the project charter & project plan
- Conduct current state and maturity assessments and produce formal reports
- Design and implement an IT governance framework aligned to SAMA requirements
- Develop a full set of IT policies and procedures
- Define the IT operating model and RACI matrix
- Build and maintain a control catalog mapped to SAMA
- Establish governance committee charters and dashboards
- Conduct gap assessments and produce a remediation roadmap
- Perform SAMA readiness assessments
- Complete a risk assessment for information assets
- Develop and maintain risk registers and treatment plans
- Support IT teams in closing SAMA and internal audit observations
- Produce cybersecurity compliance reports and IT process performance reports
- Deliver knowledge transfer sessions to internal stakeholders (up to 10 sessions)
Requirements
- Minimum 7–10 years in IT GRC, IT risk, or IT compliance roles
- Strong working knowledge of SAMA cybersecurity framework
- Experience delivering IT governance frameworks and policy suites
- Proven track record in risk assessment and risk register management
- Familiarity with internal audit closure processes and compliance reporting
- Experience in maturity assessments aligned to recognised frameworks (NIST, ISO 27001, SAMA)
- Excellent documentation and stakeholder communication skills
- Prior experience in the Saudi Arabian financial or regulated sector is highly preferred
Benefits
Why join us:
Opportunity to work with a talented and passionate team.
Competitive salary and benefits package.
Exciting projects and innovative work environment.