Specialist, Cybersecurity Grc Iii
7 days ago
**1. JOB DETAILS**:
**Position Title**:Specialist: Cyber Security GRC**
**Broad Band**:M09: Professional**
**Department & Function**:Ma’aden Cyber Security**
**Talent Pipeline Layer**:Manage Self: Expert/Consultant (MS)**
**2. OVERALL JOB PURPOSE**:
**The Specialist: Cyber Security GRC works across the entire Cyber Security division across Ma’aden Corporate and Affiliates in Saudi Arabia, India, Malawi, Zimbabwe, Mozambique, South Africa and Mauritius. This position is responsible for conducting technology risk assessments, control self assessments, and vendor risk assessments are carried out on a regular basis. This position is also responsible for Cyber security awareness, security performance monitoring, and status reporting as well as developing and setting up required policies and SOPs. Performs compliance and aduit activities.**
**3. QUALIFICATIONS, EXPERIENCE & SKILLS**:
**Qualification**:
**1. Bachelor degree in Computer Science or Management Information Systems with an advanced degree desirable**
**Experience**:
**1. At least 2-4 Years' relevant experience**
**Skills**:
**1. Good understanding of Cyber Security standards (ISO27001, 22301, 9001, NIST)**
**2. Good understanding of IT / OT technologies.**
**3. Information Security Certification (CISM / CISSP / ISO27001 / ISMS Lead Auditor / ISA/IEC 62443)**
**4. KEY ACCOUNTABILITIES**:
**Focus Area**
**Get results through individual expert contributions, influence & efforts**
**Operational / Functional**
**1. Risk Management**:
- **Develop a deep understanding of IT/OT Cyber Security risks and drive the response process in order to minimize the impact of these risks**:
- **Understand and explain risks and exposure to IT/OT environments.**:
- **Identify the critical assets for overall Ma'aden in the seven countries and maitain & mitigate the risk associated.**:
- **Conduct risk and threat research, keeping current with the evolving Cyber threat landscape.**:
- **Understand and incorporates Cyber risk assessments reports into Cyber risk registers for IT and OT.**:
- **Actively participate in IT/OT Cyber Security risk assessments across Ma’aden**:
- **Govern Cybersecurity risks across Ma’aden**:
- **Conduct third party and vendor risk assessment / audit programs**:
- **Support the Manager: Cyber Security GRC by contributing to the development of a comprehensive Risk Management Framework that sets the tone for assessments and threat management across Ma’aden**:
- **Support the Manager: Cyber Security GRC by contributing to the establishment of a Data Security Governance Framework, Data Risk Governance, Data privacy compliance Framework, Data privacy assessment, Cloud data privacy management**:
- **Support the Manager: Cyber Security GRC by contributing to the establishment of a Risk Intelligence center (RIC) covering Common control framework, cloud risk**
**2. Strategy, Governance & Compliance**:
- **Facilitate the execution of the Ma’aden Cyber Security Strategy across the organization**:
- **Execute governance, risk and compliance (GRC) initiatives and activities across Ma’aden**:
- **Provide input on Cyber Security policies, standards, procedures and the Unified Control Frameworks (UCF)**:
- **Ensure continous and peridical review of all governance related in terms of policies, processes, frameworks and controls.**:
- **Communicate GRC objectives to ensure appropriate compliance and risk aware culture**:
- **Provides IT/OT Cyber Security consultation to stakeholders across Ma'aden in Saudi Arabia, India, Malawi, Zimbabwe, Mozambique, South Africa and Mauritius**
**1. Consistently deliver solutions which contribute to business results and improved competitiveness (consulting advice, business options)**
**2. Deliver quality solutions/ service cost effectively on time and within risk parameters**
**3. Provide advice that are generally accepted and implemented on programmes and systems, creating a competitive advantage for organization, leading to quality results**
**5. Deliver Cost effective results**
**6. Risk results**
**7. HSE targets**
**8. Conduct Research & Development that leads to new solutions being implemented in the organization**
**Leadership**
**1. Capability building**:
- **Builds awareness of IT/OT Cyber Security governance areas through Training & awareness**:
- **Subject Matter Expert in IT/OT Cyber Security Coaching, Problem solving, and Risk Management tools and techniques**
**2. Quality Assurance**:
- **Develop a Cyber Security awareness, training program and related strategy for users across Ma’aden**:
- **Provide Quality Assurance & Compliance advice and services to improve service delivery performance and enhance customer satisfaction**:
- **Conduct internal audits to check compliance of IT/OT Cyber Security standards, and propose plans to close gaps as part of the Internal & External Audit “Non-Conformance (NC)” and Observations closure process**:
- **Coordinate with IA to
-
Cybersecurity GRC Specialist
1 week ago
Riyadh, Ar Riyāḑ, Saudi Arabia Lendo | ليندو Full time 120,000 - 240,000 per yearAbout Us:At Lendo, we are a fast-growing FinTech company on a mission to revolutionize the financial landscape in Saudi Arabia. With our innovative digital lending platform, we empower businesses by providing fast, secure, and transparent access to finance. As we continue to expand, we are seeking a detail-oriented and knowledgeable GRC Specialist to enhance...
-
Cybersecurity GRC Consultant
2 weeks ago
Riyadh, Ar Riyāḑ, Saudi Arabia Hays Full timeResponsible for delivering professional GRC services, developing and implementing cybersecurity strategies, and ensuring compliance with industry standards and frameworks. This role requires strong technical knowledge, excellent communication skills, and the ability to manage client relationships effectively.Key Responsibilities:Deliver GRC professional...
-
Cybersecurity Grc Specialist
21 hours ago
Riyadh, Saudi Arabia Qureos Inc Full time**About Employer**: Information Technology **Job Title**: Cybersecurity GRC Specialist **Years of Experience**: 6 years **Location**: Riyadh, Saudi Arabia **Salary Range**: 30000 SAR **Industry**: IT **Role Summary**: **Education**: - Bachelor's degree in Computer Science, Information Technology, or a related field. **Qualification Summary**: -...
-
Senior Cybersecurity GRC Specialist
2 weeks ago
Riyadh, Ar Riyāḑ, Saudi Arabia Mozn Full time 120,000 - 240,000 per yearAbout the roleWe are seeking a highly skilled and motivated Cybersecurity GRC Specialist to join our Governance, Risk, and Compliance (GRC) team. This role is pivotal in ensuring our cybersecurity practices align with both Saudi regulatory frameworks and international standards. The ideal candidate will possess hands-on experience in conducting risk...
-
Cybersecurity GRC Analyst
3 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia American Express Saudi Arabia Full timeCompany DescriptionAmerican Express Saudi Arabia, established in 1999, is a leading financial company in the Kingdom, renowned for delivering excellence and innovative payment solutions. Our mission is to empower individuals and businesses to progress through advanced payment solutions like Credit Cards, Charge Cards, and other services tailored to fit...
-
Grc Team Lead
5 days ago
Riyadh, Saudi Arabia Innovative Solutions Full time**Company Description**: Innovative Solutions (IS) is a leading pure-player Cybersecurity company in the GCC established in 2003, headquartered in Riyadh with presence in Al Khobar, Jeddah, Dubai, and Abu Dhabi. Our Cybersecurity Solutions and Services encompass Advisory Services, Technical Assurance, Solution Deployment, Professional Services, and Managed...
-
GRC Specialist
2 weeks ago
Riyadh, Ar Riyad, , Saudi Arabia TIS Full time 80,000 - 120,000 per yearDefines, reviews and updates the Information Security governance, including architecture, policies, processes, procedures and standards in alignment with regulatory requirements, business needs and best practices in the market. Define, implement, monitor and enhance information security risk management program.Define, manage and implement Information...
-
GRC Specialist
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia VaporVM Full timePosition Overview:We are seeking an experiencedGRC Specialistto support the implementation, documentation, and enhancement of our Information Security Management System (ISMS) in alignment withISO 27001standards. The ideal candidate will have a strong technical background in cybersecurity, governance, and risk management, with a proven ability to ensure...
-
GRC Consultant
7 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia Security Matterz Full time 60,000 - 120,000 per yearAbout Security MatterzSecurity Matterz is a Saudi company Riyadh-based cybersecurity and Managed Security Services provider, helping organizations across government, financial, and private sectors to strengthen their security posture and comply with local and international regulations.We are looking for GRC Consultantsto support and lead cybersecurity...
-
Grc Consultant
5 days ago
Riyadh, Saudi Arabia Innovative Solutions Full time**Company Description**: Innovative Solutions (IS) is a leading pure-player Cyber security company in the GCC established in 2003, headquartered in Riyadh with presence in Al Khobar, Jeddah, Dubai, and Abu Dhabi. Our Cybersecurity Solutions and Services encompass Advisory Services, Technical Assurance, Solution Deployment, Professional Services, and Managed...