Apply Edge Start your job search

GRC Manager - Cybersecurity

J-B | جيبي · Riyadh, Saudi Arabia

Apply & track with Apply Edge
Job Description & AccountabilitiesCybersecurity GRC ManagerThe Cybersecurity GRC Manager leads the day-to-day execution of the organization’s cybersecurity governance, risk, and compliance (GRC) program within a SAMA-regulated financing company. This role manages a team of GRC analysts/officers, maintains the risk register, and supports senior leadership with clear reporting on the organization’s risk and compliance posture. The manager drives risk assessments, oversees the cybersecurity controls framework, and ensures full alignment with SAMA Cyber Security Framework (CSF) requirements and other applicable regulations — reporting to the Chief of Cybersecurity.Reports to: Chief of Cybersecurity Sector: Financing / Regulated by SAMAResponsibilitiesEnsure the cybersecurity GRC program remains fully compliant with SAMA Cyber Security Framework (CSF) requirements, including periodic self-assessments and regulatory reporting.Execute and continuously improve the organization’s cybersecurity governance policies, procedures, and standards, aligned with SAMA requirements, industry best practices, and business objectives.Lead enterprise-wide risk assessments and gap analyses; maintain the risk register and present findings/remediation plans to senior leadership.Oversee the monitoring and continuous improvement of the cybersecurity controls framework across the organization.Partner with stakeholders across IT, legal, audit, and business units to embed cybersecurity risk management into operational decisions.Lead, mentor, and develop a team of GRC analysts/officers; manage workload, performance, and professional growth.Serve as a subject-matter expert on cybersecurity GRC and SAMA compliance, providing risk and compliance reporting to senior leadership.Manage the cybersecurity awareness and training program; drive organization-wide adoption.Coordinate cybersecurity incident response governance — cross-functional response coordination, post-incident review, and reporting to leadership, including regulatory notification where required by SAMA.Manage day-to-day relationships with SAMA, external auditors, and third-party assessors; oversee audit readiness and remediation tracking.Monitor the regulatory and threat landscape, translating emerging requirements into program-level recommendations.Support GRC tooling evaluation and vendor coordination (GRC platforms, SIEM, vulnerability management, etc.).Qualifications & ExperienceBachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (Master’s a plus).5-8 years of cybersecurity GRC experience, preferably within a SAMA-regulated entity (bank, finance company, or insurance), including 2+ years in a team leadership capacity.CISSP, CISM, or CISA required (or equivalent); CRISC a plus.Deep expertise in cybersecurity frameworks and regulations, particularly SAMA Cyber Security Framework (CSF), in addition to NCA ECC, NIST, and ISO 27001.Proven track record leading risk assessments, compliance audits, and remediation programs — ideally including SAMA self-assessments.Experience managing cross-functional teams and coordinating with vendors and regulators.Strong communication skills — able to translate technical risk into business impact for senior leadership.Strong strategic thinking, people management, and stakeholder influence skills.Knowledge & SkillsStrong, hands-on knowledge of SAMA Cyber Security Framework (CSF) and its practical application in a financing sector context.Solid understanding of GRC principles and enterprise risk management.Familiarity with NCA ECC and other applicable Saudi regulatory requirements.People leadership: coaching, performance management, capacity planning.Program/project management skills to run multi-stakeholder GRC initiatives.Familiarity with GRC platforms and the security tooling landscape.Strong cross-functional collaboration, especially with IT, legal, compliance, and auditJ-B Values:SimplicityWe make the complex simple, so our customers don’t have to spend more time than necessary understanding their options and credit.ReliabilityTransparent and always there. We mean what we say and do what we say.ProactivenessWe are a true supporter and advisor to our customers, always predicting and anticipating their needs.Proud Created by Saudis for Saudi, we are a proud Saudi brand and we do what’s best for our community.