Apply Edge Start your job search

Cybersecurity GRC Manager

Talent Blueprint FZ LLC · Riyadh, Saudi Arabia

Apply & track with Apply Edge

Position: Cybersecurity GRC Manager

Location: Riyadh / Jeddah, Saudi ArabiaContract Duration: 15-Oct-26 - 28-Feb-27About the RoleWe are seeking an experienced Cybersecurity GRC Manager to lead the organization's cybersecurity Governance, Risk, and Compliance function for a major international football event project in Saudi Arabia.The role will have end-to-end responsibility for cybersecurity governance, risk management, regulatory compliance, third-party risk, audit readiness, policy management, and data protection compliance across the event lifecycle.The successful candidate will work closely with cybersecurity, legal, procurement, technology, vendors, and senior leadership to ensure that cybersecurity risks and compliance requirements are effectively managed.Key ResponsibilitiesOwn and lead the organization's Cybersecurity Governance, Risk, and Compliance (GRC) program end to end.Develop, maintain, review, and secure executive approval for cybersecurity policies, standards, procedures, and governance frameworks.Own and continuously maintain the cybersecurity risk register, ensuring risks are identified, assessed, tracked, and appropriately treated.Lead periodic and event-driven cybersecurity risk assessments across technology, applications, vendors, and event operations.Coordinate cybersecurity compliance self-assessments, third-party audits, and regulator-led audits where applicable.Manage third-party and vendor cybersecurity risk assessments, including security due diligence, risk identification, remediation tracking, and ongoing monitoring.Support cybersecurity risk management across the significant number of vendors, contractors, sponsors, broadcasters, ticketing providers, hospitality partners, and technology suppliers involved in the event.Own the organization's data protection compliance program in coordination with Legal and relevant business stakeholders.Review and manage data protection requirements associated with personal data processed throughout the event lifecycle.Support and coordinate Data Processing Agreements (DPAs) and related security/data protection requirements with sponsors, broadcasters, ticketing vendors, and other third parties.Develop and manage the organization's cybersecurity awareness and training program.Maintain the policy exception and risk acceptance process, ensuring exceptions are documented, risk assessed, approved, and periodically reviewed.Establish and report cybersecurity GRC and compliance KPIs to senior leadership.Support post-incident reviews from a regulatory, compliance, reporting, and disclosure-obligation perspective.Monitor changes in applicable cybersecurity and data protection requirements and assess their impact on the organization.Provide guidance to business and technology teams on cybersecurity governance, risk, compliance, and third-party security requirements.Work closely with the Cybersecurity Architecture Manager and Cybersecurity Defense Manager to ensure governance and risk requirements are incorporated into cybersecurity architecture and defense operations.Maintain appropriate documentation and evidence to demonstrate compliance and audit readiness throughout the project lifecycle.Requirements3+ years of relevant experience in Cybersecurity GRC, Information Security GRC, Cybersecurity Risk, Compliance, or Information Security.Proven experience managing cybersecurity governance, risk, and compliance programs.Strong experience developing and managing cybersecurity policies, standards, procedures, and controls.Experience maintaining cybersecurity risk registers and conducting risk assessments.Experience with third-party/vendor cybersecurity risk management and security due diligence.Experience supporting or coordinating internal, external, third-party, or regulatory audits.Strong understanding of cybersecurity compliance frameworks, standards, and regulatory requirements.Experience with data protection/privacy compliance and third-party data processing arrangements would be an advantage.Experience managing policy exceptions, risk acceptance, and remediation tracking.Experience developing and delivering cybersecurity awareness and training programs.Strong documentation, reporting, communication, and stakeholder management skills.Ability to work effectively with senior leadership, Legal, Procurement, IT, Cybersecurity, vendors, and other business stakeholders.Experience working in a large-scale, multi-vendor, or major event environment would be an advantage.Knowledge of Saudi cybersecurity and data protection requirements would be an advantage.Preferred CertificationsRelevant cybersecurity, GRC, risk, and privacy certifications would be an advantage, including:CISSPCISMCRISCCISAISO 27001 Lead Implementer / Lead AuditorCGRCCDPSECIPM / CIPPOther recognized cybersecurity GRC, risk, audit, or privacy certifications