Apply Edge Start your job search

Cybersecurity GRC Lead

Confidential · Al Khobar, Eastern, Saudi Arabia

Apply & track with Apply Edge
Job Purpose: Establishing and overseeing the organization's cybersecurity governance, risk, and compliance framework to ensure alignment with regulatory requirements, industry standards, and business objectivesKey responsibilities:Develop and maintain cybersecurity policies, procedures, and control documentationDrive the organization’s cybersecurity awareness, phishing and training initiativesEnsure policies are updated, communicated, and enforced across departmentsAlign governance documents with NCA ECC, ISO 27001, and legal obligationsConduct risk assessments, maintain risk register, and define treatment plansEnsure compliance with NCA ECC, ISO 27001, and Saudi PDPL requirementsPerform third-party/vendor risk assessments and due diligence reviewsTrack remediation plans and prepare for internal/external auditsMaintain dashboards for compliance posture and control performanceDevelop, distribute, and track employee security training and awareness programsConduct phishing simulations and evaluate response trendsCollaborate with HR on onboarding and offboarding security proceduresMaintain evidence repository for audits and compliance trackingMap security controls NCA ECC domains and ensures maturity documentationSupport the Risk & Compliance Specialist with reporting and updates.QualificationsBachelor’s degree in information security, IT Governance, Law, or Business with Security specialization6–10 years of experience in cybersecurity compliance, audit, or GRCIn-depth experience in implementing and managing ISMS and compliance framework