Cybersecurity Compliance Specialist
flynas · Riyadh, Saudi Arabia
Apply & track with Apply EdgeJob Purpose Responsible for supporting and conducting cybersecurity compliance activities to ensure the organization’s adherence to applicable cybersecurity laws, regulations, policies, standards, and internal requirements. The role supports compliance assessments, evidence collection and validation, identification and tracking of compliance gaps and corrective actions, regulatory reporting, and maintaining organizational readiness for cybersecurity audits and regulatory assessments. Key Accountabilities
- Monitor and assess the organization’s compliance with applicable cybersecurity laws, regulations, and regulatory frameworks, including National Cybersecurity Authority (NCA) requirements such as and not limited to the Essential Cybersecurity Controls (ECC), Critical Systems Cybersecurity Controls (CSCC), Cloud Cybersecurity Controls (CCC), Data Cybersecurity Controls (DCC), and other applicable NCA requirements.
- Identify cybersecurity compliance gaps and coordinate the tracking and timely remediation of identified findings and corrective actions with relevant control owners.
- Monitor and maintain applicable cybersecurity compliance obligations and requirements, including changes to relevant regulatory and organizational requirements.
- Maintain accurate, complete, and traceable records of cybersecurity compliance assessments, findings, corrective actions, and supporting evidence.
- Support cybersecurity regulatory assessments, internal and external audits, and other compliance reviews by coordinating required information, evidence, responses, and follow-up actions.
- Provide cybersecurity compliance guidance and support to relevant internal stakeholders regarding applicable requirements, controls, policies, and standards. Operational Responsibilities
- Coordinate the preparation and collection of evidence and documentation required for regulatory assessments and internal and external audits.
- Track cybersecurity-related audit, regulatory, and assessment findings through remediation and closure.
- Support the review and update of cybersecurity policies, standards, procedures, and control requirements to maintain alignment with applicable regulatory requirements.
- Support cybersecurity compliance assessments of vendors and third parties, including preparation and review of compliance questionnaires and supporting evidence.
- Maintain and track approved cybersecurity exceptions and waivers, including conditions, compensating controls, owners, approvals, and expiry dates.
- Prepare periodic cybersecurity compliance reports and provide inputs to dashboards and management reporting.
- Coordinate with IT, business units, control owners, and other relevant stakeholders to obtain information and evidence required for cybersecurity compliance assessments.
- Participate in cybersecurity compliance awareness and communication activities to promote understanding of applicable requirements and responsibilities.
- Track remediation actions with responsible control and process owners, monitor agreed target dates, and escalate overdue or unresolved actions as appropriate.
- Conduct periodic compliance assessments and checks against applicable cybersecurity regulations, frameworks, policies, standards, procedures, and control requirements.
- Collect, review, validate, and maintain supporting evidence to assess the implementation and effectiveness of applicable cybersecurity controls.