عن الدور الوظيفي
تبحث شركة FNRCO عن رئيس قسم الحوكمة والمخاطر والالتزام الرقمي (Digital GRC) لقيادة ممارسات حوكمة تكنولوجيا المعلومات وإدارة المخاطر والامتثال عبر المنصات الرقمية. هذا المنصب بدوام كامل ويقع مقره في مكة المكرمة، مع تغطية العمليات في كل من جدة ومكة المكرمة. يركز الدور على ضمان الرقابة الفعالة على المخاطر، والاستعداد للتدقيق، والالتزام بالسياسات واللوائح ضمن المشهد الرقمي.
الغرض من الدور وسياقه
الغرض الأساسي من هذا الدور هو دمج أطر عمل الحوكمة والمخاطر والالتزام (GRC) في عمليات تكنولوجيا المعلومات، وإدارة مخاطر الطرف الثالث، وتقديم تقارير قابلة للتنفيذ إلى رئيس القسم. سيعمل رئيس قسم الحوكمة والمخاطر والالتزام الرقمي على تمكين العمليات المسؤولة والواعية بالمخاطر من خلال الإشراف على حوكمة تكنولوجيا المعلومات، وإدارة مخاطر المؤسسة، والامتثال عبر المنصات الرقمية للمؤسسة.
المسؤوليات الرئيسية
- تأسيس وتحسين وإنفاذ أطر عمل وسياسات وضوابط حوكمة تكنولوجيا المعلومات عبر مشهد تكنولوجيا المؤسسة، مع ضمان التوافق مع المعايير والمتطلبات التنظيمية.
- قيادة تقييمات مخاطر تكنولوجيا المعلومات على مستوى المؤسسة، والحفاظ على سجل مركزي للمخاطر، وترتيب أولويات الثغرات بناءً على تأثيرها على الأعمال.
- الإشراف على أطر الامتثال (*, ISO, NCA, GDPR)، وضمان جاهزية المنصات الرقمية للتدقيق، وتنسيق الردود على عمليات التدقيق الداخلية والخارجية.
- قيادة تقييمات نضج الحوكمة والمخاطر والالتزام لدى الموردين، وإدراج بنود قائمة على المخاطر، ومراقبة امتثال الطرف الثالث من خلال اتفاقيات مستوى الخدمة، أو الشهادات، أو عمليات التدقيق المستقلة.
- تحديد وصيانة لوحات تحكم الحوكمة والمخاطر والالتزام التي تغطي وضع المخاطر، ونتائج التدقيق، وحالة الامتثال، وتقديم تحديثات منتظمة للجان الحوكمة.
- دعم مراقبة الأنشطة اليومية لضمان الامتثال للسياسات والإجراءات المنصوص عليها.
- المساهمة في تحديد فرص التحسين المستمر للأنظمة والعمليات.
- المشاركة بفعالية في التدريب أثناء العمل، والتوجيه، وتدريب المرؤوسين، وتوفير توجيهات واضحة ومراقبة سير العمل.
المؤهلات والخبرة
- ما لا يقل عن 5 إلى 10 سنوات من الخبرة ذات الصلة في حوكمة تكنولوجيا المعلومات والمخاطر والامتثال.
- خبرة مثبتة في تأسيس وتحسين أطر عمل وسياسات حوكمة تكنولوجيا المعلومات.
- كفاءة في قيادة تقييمات مخاطر تكنولوجيا المعلومات على مستوى المؤسسة وإدارة سجلات المخاطر.
- خبرة في أطر الامتثال مثل ISO وNCA وGDPR.
- القدرة على قيادة اختبار الضوابط، وتقييم الفجوات، وتخطيط المعالجة.
- خبرة في حوكمة مخاطر الطرف الثالث والموردين.
المهارات والسمات
- فهم قوي لأفضل ممارسات الحوكمة والمخاطر والالتزام في تكنولوجيا المعلومات والمتطلبات التنظيمية.
- القدرة على تعزيز تبني ثقافة واعية بالمخاطر عبر فرق تكنولوجيا المعلومات.
- مهارات تحليلية وإعداد تقارير ممتازة، بما في ذلك القدرة على تحديد وصيانة لوحات تحكم الحوكمة والمخاطر والالتزام.
- مهارات تواصل وتفاعل شخصي قوية للتنسيق مع أصحاب المصلحة الداخليين والخارجيين.
- قدرات قيادية لإدارة الأفراد، بما في ذلك التوجيه والتدريب.
بيئة العمل
هذا منصب بدوام كامل مقره مكة المكرمة، المملكة العربية السعودية، مع مسؤوليات تغطي العمليات في جدة ومكة المكرمة. يتضمن الدور العمل ضمن بيئة احترافية تعزز ثقافة الأداء العالي بما يتماشى مع قيم الشركة.
About the Role
FNRCO is seeking a Digital GRC Section Head to lead IT governance, risk, and compliance practices across digital platforms. This full-time position is based in Makkah, with operations spanning Jeddah and Makkah. The role focuses on ensuring effective risk oversight, audit readiness, and adherence to policies and regulations within the digital landscape.
Role Purpose and Context
The primary purpose of this role is to embed GRC frameworks into IT processes, manage third-party risks, and provide actionable reporting to the Section Head. The Digital GRC Section Head will enable accountable and risk-aware operations by overseeing IT governance, enterprise risk management, and compliance across the organization's digital platforms.
Key Responsibilities
- Establish, refine, and enforce IT governance frameworks, policies, and controls across the enterprise technology landscape, ensuring alignment with standards and regulatory requirements.
- Lead enterprise-level IT risk assessments, maintain a centralized risk register, and prioritize vulnerabilities based on business impact.
- Oversee compliance frameworks (*, ISO, NCA, GDPR), ensure digital platforms are audit-ready, and coordinate responses to internal and external audits.
- Lead assessments of vendor GRC maturity, embed risk-based clauses, and monitor third-party compliance through SLAs, certifications, or independent audits.
- Define and maintain GRC dashboards covering risk posture, audit findings, and compliance status, providing regular updates to governance committees.
- Support monitoring of day-to-day activities to ensure compliance with stipulated policies and procedures.
- Contribute to identifying opportunities for continuous improvement of systems and processes.
- Actively participate in on-the-job training, mentoring, and coaching of subordinates, providing clear direction and monitoring workflow.
Qualifications and Experience
- A minimum of 5 to 10 years of relevant experience in IT governance, risk, and compliance.
- Demonstrated experience in establishing and refining IT governance frameworks and policies.
- Proficiency in leading enterprise-level IT risk assessments and managing risk registers.
- Experience with compliance frameworks such as ISO, NCA, and GDPR.
- Ability to lead control testing, gap assessments, and remediation planning.
- Experience in third-party and vendor risk governance.
Skills and Attributes
- Strong understanding of IT GRC best practices and regulatory requirements.
- Ability to drive adoption of a risk-aware culture across IT teams.
- Excellent analytical and reporting skills, including the ability to define and maintain GRC dashboards.
- Strong communication and interpersonal skills for coordinating with internal and external stakeholders.
- Leadership capabilities for people management, including mentoring and coaching.
Work Environment
This is a full-time position based in Makkah, Saudi Arabia, with responsibilities covering operations in Jeddah and Makkah. The role involves working within a professional environment that promotes a high-performance culture aligned with company values.