أبلاي إيدج ابدأ البحث عن عمل

Cybersecurity Governance, Risk Management and Compliance Specialist

Kualitatem Inc. · Riyadh, Saudi Arabia

قدّم وتابع مع أبلاي إيدج
Minimum Qualifications: A bachelor’s degree in computer science, information security, or a related field. Obtaining the following certifications is preferred: CISSP, CISM, CRISC, or ISO 27001 LI. Job Requirements: No less than 6 years of experience in cybersecurity governance, risk and compliance. Advanced knowledge of national and international cybersecurity frameworks and standards. Proven experience in managing cybersecurity risk registers and preparing executive reports. Experience in managing third-party (external party) risks. Experience in implementing and managing eGRC tools. Experience in cybersecurity risk management tools. The ability to carry out compliance activities and self-assessments against national and international frameworks and standards. The ability to communicate and coordinate with senior leadership and business stakeholders. Principal Responsibilities: Reviewing and updating cybersecurity governance documents such as policies, procedures, standards and guidelines on a periodic basis. Conducting cybersecurity risk assessments periodically at the level of assets, systems, projects and third parties. Developing and improving the risk management methodology in line with the best frameworks and standards approved locally and internationally. Updating the risk register and following it up periodically, together with preparing treatment plans and following up their implementation. Aligning treatment decisions with the risk acceptance level approved by the Ministry. Conducting compliance gap assessments against the controls of the National Cybersecurity Authority and related frameworks such as ISO 27001 and any other relevant regulatory requirements. Supporting internal and external audit processes and preparing supporting evidence. Managing cases of non-compliance, developing gap remediation plans, and following up their implementation. Preparing regulatory compliance reports for management and external stakeholders. Preparing periodic reports for senior management on cybersecurity governance, risk and compliance. Preparing executive dashboards covering the level of risk, the status of compliance, and performance indicators, and providing reports directed to the competent committees.