Apply Edge Start your job search

IT Governance & Risk Specialist / Manager

Astek Middle East · Jeddah, Makkah, Saudi Arabia

Apply & track with Apply Edge
We are looking for an experienced IT Governance & Risk professional to drive the development, implementation, and continuous improvement of technology governance, risk, compliance, audit, business processes, and IT continuity practices.The role will be responsible for ensuring that IT governance frameworks, policies, processes, controls, and documentation are aligned with organizational objectives and relevant regulatory and international standards.A key requirement is hands-on experience with ISO implementations and certifications, particularly ISO 20000-1, ISO 27001, and ISO 56002.Key ResponsibilitiesDevelop and maintain IT Governance frameworks, standards, policies, and procedures aligned with business objectives.Drive compliance with SAMA CSFW, NCA, and NDMO-PDPL regulatory requirements.Lead IT process improvement and transformation initiatives to enhance efficiency and service quality.Oversee IT documentation, policies, procedures, and governance reporting.Manage IT audits, controls, compliance assessments, and remediation of audit findings.Identify and manage technology risks, KRIs, risk registers, and mitigation plans.Develop and maintain IT Business Continuity & Disaster Recovery plans, including BIA, TRA, RTO/RPO, and regular testing.Lead ISO implementation and certification activities, particularly ISO 20000-1, ISO 27001, and ISO 56002.Collaborate with IT, Risk, Audit, Cybersecurity, and other stakeholders to continuously improve technology governance and resilience.Key RequirementsEssentialHands-on experience in ISO implementation and certification, specifically:ISO 20000-1ISO 27001ISO 56002Strong experience in IT Governance, Risk & Compliance (GRC).Experience developing and implementing IT governance frameworks, standards, policies, and procedures.Experience with IT audit, controls, audit observations, corrective actions, and compliance monitoring.Strong understanding and practical experience with SAMA Cyber Security Framework (CSFW).Knowledge/experience of NDMO-PDPL and NCA guidelines.Experience in IT risk management, including risk registers, KRIs, risk assessment, and mitigation.Experience with IT Business Continuity and Disaster Recovery, including BIA, TRA, IT BCP, RTO and RPO.Strong IT process management and continuous improvement experience.Excellent stakeholder management, reporting, documentation, and communication skills.Strongly PreferredCandidates who have worked in a regulated environment, particularly where SAMA, NCA, NDMO-PDPL, ISO, IT audit, and technology risk requirements are part of the IT governance landscape, should be prioritized.