Info Security Governance, Risk, and Compliance
2 weeks ago
**Position: GRC manager - RIYADH**
**Job Summary**
Under the direction of management, the incumbent coordinates and performs PCC’s security assessment functions and control testing reporting and activities in accordance with PCC’s Internal Controls compliance, regulatory and departmental policy and procedures. The Information Security Assessment Specialist updates and maintains control matrices and spreadsheets and provides recommendations for management’s consideration. This position ensures compliance with PCC’s internal controls, regulatory and information security policies and procedures. The incumbent works with internal audit, external audit firms, and regulatory agencies to provide supportive documentation as applicable. The Information Security Assessment Specialist takes a lead role in ensuring the security of all protected information collected, used, maintained, or released by PCC.
**Typical Duties and Responsibilities**
Implements security controls, risk assessment framework, and program that align to regulatory requirements, ensuring documented and sustainable compliance that aligns and advances College business objectives.
Evaluates risks and develops security standards, procedures, and controls to manage risks. Improves PCC’s security positioning through process improvement, policy, automation, and the continuous evolution of capabilities.
Implements processes, such as GRC (governance, risk and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing. Develops reporting metrics, dashboards, and evidence artifacts.
Defines and documents business process responsibilities and ownership of the controls in GRC tool. Schedules regular assessments and testing of effectiveness and efficiency of controls and creates GRC reports.
Updates security controls and provides support to all stakeholders on security controls covering internal assessments, regulations, protecting Personally Identifying Information (PII) data, and Payment Card Industry Data Security Standards (PCI DSS).
Performs and investigates internal and external information security risk and exceptions assessments. Assess incidents, vulnerability management, scans, patching status, secure baselines, penetration test result, phishing, and social engineering tests and attacks.
Documents and reports control failures and gaps to stakeholders. Provides remediation guidance and prepares management reports to track remediation activities.
Assists other staff in the management and oversight of security program functions.
Trains, guides, and acts as a resource on security assessment functions to other departments within the College.
Remains current on best practices and technological advancements and acts as the College’s technical resource for security assessment and regulatory compliance.
Performs other related duties as assigned.
**Work Environment and Physical Requirements**
Work environment includes frequent disruptions and changes in priorities. Work is performed in an office environment or using standard information technology equipment combined with specialized information security products. Working conditions may require various shifts and/or weekends to provide incident response operations, business continuity plans, or disaster recovery operations. There is occasional travel between campuses or to off-site meetings. Position requires routine periods of standing and walking, lifting of equipment (30-50 pounds) and physical agility. Physical skills are required for keyboarding and operating complex network and computing equipment.
**Minimum Qualifications**
High school diploma or equivalent. Associate’s Degree in Computer Information Systems or related discipline. Relevant experience may substitute for the degree requirement on a year-for-year basis. Four Years of applied work experience in cyber security programs, audits, assessments, risk, remediation, or cyber security compliance management.
**Knowledge, Skills, and Abilities**
Knowledge of:
- Applicable information security management, governance, and compliance principles, practices, laws, rules and regulations;
- Information technology systems and processes, network infrastructure, data architecture, data processes, and protocols;
- Cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration;
- Information systems auditing, monitoring, controlling, and assessment process;
- Incident response management;
- Risk assessment and management methodology.
Skills in:
- Developing and implementing enterprise governance, risk, and compliance strategy and solutions;
- Researching and locating information related to internal and external organizations using online and other sources;
- Security project management and planning;
- Maintaining confidentiality;
- Troubleshooting and operating a computer and various software packages;
- D
-
Governing Information Security and Managing Risk
18 hours ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeAbout the Position:We are seeking an experienced Cybersecurity GRC Consultant to join our team at IT Security C&T. As a senior member of our security consulting team, you will be responsible for developing and maintaining cybersecurity governance frameworks, risk management strategies, and compliance practices.Key Responsibilities:Develop and maintain...
-
Governance Risk Compliance
3 weeks ago
Riyadh, Saudi Arabia CCDS Full time**Responsibilities**: - Developing and implementing policies and procedures for governance, risk, and compliance management. - Ensuring the organization maintains complete and accurate records of all identified risks, mitigations, and policy changes. - Overseeing the implementation of security controls to ensure compliance with industry standards and...
-
Cybersecurity Governance and Compliance Expert
18 hours ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeAbout the Role:We are seeking an experienced Cybersecurity Governance, Risk Management (GRC) Consultant to join our team at IT Security C&T. As a senior member of our security consulting team, you will be responsible for developing and maintaining cybersecurity governance frameworks, risk management strategies, and compliance practices across various...
-
Information Security Risk Management Professional
18 hours ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeAbout the Job:As a Cybersecurity GRC Consultant at IT Security C&T, you will play a critical role in helping organizations manage cybersecurity risks and improve their overall security posture.Key Responsibilities:Develop and implement comprehensive cybersecurity governance, risk management, and compliance frameworksCollaborate with cross-functional teams to...
-
Governance, Risk, and Compliance Consultant
3 weeks ago
Riyadh, Ar Riyāḑ, Saudi Arabia RP International Full timeGovernance, Risk, and Compliance ConsultantWe are seeking a GRC Consultant for our client, that advises clients on developing, implementing, and improving cybersecurity GRC frameworks. This role includes assessing risks, ensuring regulatory compliance, and strengthening governance to enhance organizational security and resilience.Roles and...
-
Cybersecurity Governance Specialist
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeGet expert guidance on cybersecurity governance, risk management, and compliance frameworks. As a Cybersecurity GRC Consultant at IT Security C&T, you will work with cross-functional teams to identify and assess cybersecurity risks and vulnerabilities.Job OverviewWe are looking for an experienced Cybersecurity GRC Consultant to join our team of security...
-
Governance, Risk, and Compliance senior officer
3 weeks ago
Riyadh, Ar Riyāḑ, Saudi Arabia Takamol Holding Full timeGovernance, Risk, and Compliance Senior Officer (GRC)Responsibilities:Risk Assessment and Management: Identify, assess, and manage cybersecurity risks across the organization. Develop and implement risk mitigation strategies to address identified vulnerabilities.Policy and Framework Development: Assist in the creation and maintenance of cybersecurity...
-
Compliance Risk Manager
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia RP International Full timeCompliance Risk ManagerRP International is seeking a highly skilled Compliance Risk Manager to join our team. As a key member of our team, you will be responsible for advising clients on developing, implementing, and enhancing cybersecurity GRC frameworks.In this role, you will work closely with clients to assess risks, ensure regulatory compliance, and...
-
IT Security Consultant with GRC Focus
18 hours ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeAbout the Company:IT Security C&T is a leading provider of cybersecurity consulting services in the MENA region. Our team of experts helps organizations protect themselves against cyber threats and improve their overall security posture.Job Description:We are seeking an experienced Cybersecurity GRC Consultant to join our team. As a senior member of our...
-
Cybersecurity Governance Risk and Compliance Expert
17 hours ago
Riyadh, Ar Riyāḑ, Saudi Arabia Riyadh Air Full timeAbout the CompanyRiyadh Air is a new national airline shaping the future of flying. It aims to lead the aviation industry by transforming Saudi Arabia into a global aviation and trade hub, a digitally native airline connecting the kingdom to over 100 destinations.About the RoleThis role requires a driven Cybersecurity GRC professional with excellent...
-
Cybersecurity Governance Professional
17 hours ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeJob Title:Cybersecurity Governance ProfessionalAbout the Role:We are seeking a skilled Cybersecurity Governance Professional to join our team at IT Security C&T. As a Cybersecurity Governance Professional, you will be responsible for developing and maintaining comprehensive cybersecurity governance frameworks, strategies, and practices.You will collaborate...
-
Cybersecurity Governance, Risk Compliance
6 days ago
Riyadh, Saudi Arabia Talent Pal Full time**Cybersecurity GRC (Analyst/Consultant)** **Location: Riyadh, Saudi Arabia** **About Accenture** **Accenture Technology** Through unmatched industry experience, leading technologies from our ecosystem partners and startups, and the largest delivery network in the world, we provide a powerful range of capabilities that can be tailored to our client’s...
-
Security Governance Professional
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia MDS for Computer Systems (MDS CS) Full timeCompliance and Risk Management Specialist:We are seeking a highly skilled Compliance and Risk Management Specialist to join our team. The successful candidate will be responsible for ensuring the effectiveness of our information security governance framework. Key responsibilities include conducting regular security audits, identifying areas for improvement,...
-
Compliance and Cybersecurity Advisor
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeThe role of a Cybersecurity GRC Consultant involves developing and maintaining comprehensive cybersecurity governance, risk management, and compliance frameworks, strategies, and practices. If you have a strong passion for cybersecurity and want to make a difference, this is an exciting opportunity for you.About the JobAs a Cybersecurity GRC Consultant, you...
-
IT Compliance and Risk Manager
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia Adree Full timeAbout AdreeAdree is a leading organization in the field of information technology, committed to delivering exceptional results through our commitment to quality, innovation, and customer satisfaction.Job DescriptionWe are seeking a highly skilled IT Compliance and Risk Manager to join our team. The ideal candidate will have a strong background in IT audit,...
-
Senior Officer Cybersecurity Governance and
3 days ago
Riyadh, Saudi Arabia البنك السعودي الفرنسي Full timeThis level requires Good knowledge of Information Security Governance and compliance. This level also requires good knowledge of information security policies, processes, standards and guidelines. Knowledge of security exceptions, security awareness is also expected, National regulations of Cybersecurity and international standards and practices Knowledge of...
-
Riyadh, Ar Riyāḑ, Saudi Arabia Riyadh Air Full timeAbout the CompanyRiyadh Air (RX), headquartered in the Saudi Capital, is the new national airline that's shaping the future of flying. It seeks to lead the aviation industry by transforming Saudi Arabia into a global aviation and trade hub – a digitally native airline that will connect the kingdom to more than 100 destinations.About the RoleAre you a...
-
IT Security Consultant Expert
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia IT Security C&T Full timeCybersecurity is a rapidly evolving field that requires continuous learning and adaptation. Our team of security experts at IT Security C&T stay up-to-date with emerging cyber threats and vulnerabilities and recommend appropriate mitigation strategies.Job DescriptionDevelop and maintain cybersecurity governance, risk management, and compliance frameworks,...
-
Governance, Risk, and Compliance Officer
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia Riyadh Air Full timeAbout YouWe are looking for a highly motivated and experienced Governance, Risk, and Compliance Officer to join our team. As a key member of our cybersecurity team, you will be responsible for developing and maintaining a comprehensive GRC framework that ensures compliance and drives business excellence.The ideal candidate will have a strong background in...
-
Cloud Security Governance Lead
5 days ago
Riyadh, Ar Riyāḑ, Saudi Arabia Oracle Full timeJob Title: Cloud Security Governance LeadCompany Overview:Oracle Cloud Infrastructure (OCI) is a leading provider of cloud infrastructure services, empowering businesses to innovate and thrive in the digital age.We are seeking a highly skilled Cloud Security Governance Lead to join our team, driving the development and implementation of cloud security...