Information Security Compliance Consultant (Non-Technical)
HRsource · Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجInformation Security Compliance ConsultantImportant: This Is Not a Technical Cybersecurity Role This position is focused on compliance, documentation, governance, regulatory coordination, and audit support.📍 Location: Riyadh, Saudi ArabiaAbout the RoleWe are seeking an Information Security Compliance Consultant to support information security and data protection compliance activities in Saudi Arabia.The role will serve as a key local representative for information security and personal data protection compliance, working closely with Saudi regulatory authorities, senior leadership, IT and security teams, auditors, and internal stakeholders.The successful candidate will be responsible for coordinating regulatory requirements, supporting PDPL compliance, localizing policies and procedures, maintaining compliance documentation, and ensuring the organization remains prepared for regulatory reviews and audits.Key ResponsibilitiesGovernment Liaison & Regulatory ComplianceServe as the local point of contact with relevant Saudi regulatory authorities, including NCA and SDAIA.Monitor, interpret, and communicate regulatory notices, requirements, circulars, and updates to relevant internal stakeholders.Coordinate regulatory communications, submissions, responses, and required documentation through official channels and portals.Support regulatory notifications related to cybersecurity or personal data incidents in line with applicable requirements and internal procedures.Maintain professional and effective communication with government and regulatory stakeholders.Personal Data Protection & PDPL ComplianceSupport compliance with the Saudi Personal Data Protection Law (PDPL).Coordinate the identification and documentation of personal data processing activities with IT and business teams.Support the preparation and maintenance of PDPL-related filings, declarations, policies, procedures, and employee communications.Own and maintain local PDPL compliance documentation and supporting audit evidence.Ensure compliance documentation remains accurate, current, organized, and readily available for regulatory reviews and audits.Information Security Governance & Policy LocalizationSupport the localization of global cybersecurity policies and frameworks into Saudi-compliant policies, SOPs, and procedures.Ensure relevant documentation is aligned with applicable Saudi requirements, including NCA Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC) where applicable.Coordinate with technical teams to collect and organize evidence required to demonstrate compliance.Maintain appropriate version control and documentation standards across policies, procedures, and compliance records.Audit Readiness & Compliance EvidenceDevelop and maintain a structured Compliance Evidence Repository to ensure audit traceability and readiness.Collect, organize, and maintain compliance evidence, including:Policy approvals and acknowledgementsSecurity committee and management meeting minutesAccess approval recordsSecurity and awareness training recordsSystem screenshots and extracts provided by technical teamsOther supporting documentation required for complianceCoordinate with internal stakeholders and auditors to ensure evidence is complete, accurate, and available when required.Track outstanding compliance requirements and ensure timely follow-up and closure.Training & Third-Party ComplianceCoordinate information security and PDPL awareness training for local employees.Support phishing simulation exercises and maintain appropriate training and awareness records.Assist with basic information security compliance checks for local vendors and third parties.Review supporting documentation, including NDAs and information security clauses, where required.What We're Looking ForMinimum 2 years of experience in compliance, IT governance, regulatory affairs, audit support, or information security-related roles.Strong understanding of information security, data protection, and regulatory compliance concepts.Previous experience working with Saudi government entities or regulatory bodies is strongly preferred.Ability to prepare clear and professional government and regulatory correspondence.Professional English proficiency, with the ability to understand security standards and prepare clear written reports.Strong attention to detail and a high level of documentation discipline.Ability to manage compliance requirements, evidence, records, and follow-up activities effectively.Comfortable working with senior stakeholders, auditors, regulators, IT teams, and business functions.Preferred QualificationsThe following would be advantageous:Exposure to ISO/IEC 27001 audits or implementation.Exposure to ISO 22301 or SOC 2 audits.Familiarity with NCA Essential Cybersecurity Controls (ECC).Familiarity with NCA Cloud Cybersecurity Controls (CCC).Knowledge of Saudi PDPL requirements.Certifications such as CompTIA Security+, ISO Internal Auditor, or equivalent.What Success Looks LikeThe successful candidate will be someone who can take regulatory requirements, understand their implications for the organization, coordinate effectively with the relevant internal teams, and ensure that required documentation and evidence are complete, accurate, traceable, and readily available.Strong performance in this role will be demonstrated through regulatory alignment, audit readiness, documentation quality, and effective coordination across stakeholders.