About ******* and the Role
******* is seeking a GRC Specialist to join their team for a cybersecurity project based in Jeddah, Makkah. This is a full-time, on-site position where the specialist will contribute to strengthening the organization's cybersecurity posture.
Role Overview
The GRC Specialist will support the cybersecurity project by applying practical experience in Governance, Risk, and Compliance, with a focus on cybersecurity risk management. The role involves close collaboration with business and technical stakeholders to conduct risk assessments, maintain compliance documentation, and facilitate the implementation of cybersecurity controls.
Key Responsibilities
- Conduct cybersecurity risk assessments and document identified risks.
- Maintain risk registers, treatment plans, and follow-up actions.
- Support the development and review of cybersecurity policies, procedures, and standards.
- Assess compliance with applicable cybersecurity frameworks and regulatory requirements.
- Identify control gaps and recommend appropriate remediation actions.
- Collect, organize, and review compliance evidence.
- Prepare risk and compliance reports for management and project stakeholders.
- Monitor remediation activities and follow up with relevant teams.
- Support internal and external cybersecurity audits and assessments.
- Coordinate with business, IT, cybersecurity, and project stakeholders.
Required Qualifications and Experience
- Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field.
- Approximately ** years of relevant experience in cybersecurity GRC.
- Practical experience in cybersecurity risk assessment and risk management.
Essential Skills and Attributes
- Familiarity with cybersecurity frameworks and standards.
- Strong documentation, reporting, and stakeholder communication skills.
- Ability to work independently and manage multiple risk and compliance activities.
- Professional certifications in GRC, cybersecurity, or risk management are preferred.
Work Environment and Availability
This role requires full-time, on-site work in Jeddah. Candidates who are available to join within a short timeframe will be given priority.
حول ******* والدور
يسعى ******* لتعيين أخصائي GRC للانضمام إلى فريقهم من أجل مشروع أمني سيبراني مقره جدة، مكة. هذا هو موقف دوام كامل وموجود في الموقع حيث سيساهم الأخصائي في تعزيز موقف الأمن السيبراني للمؤسسة.
نظرة عامة على الدور
سيقوم أخصائي GRC بدعم مشروع الأمن السيبراني من خلال تطبيق خبرة عملية في الحوكمة والمخاطر والامتثال، مع تركيز على إدارة مخاطر الأمن السيبراني. يتضمن الدور التعاون عن كثب مع أصحاب المصلحة من الأعمال والتقنية لإجراء تقييمات المخاطر، والحفاظ على وثائق الامتثال، وتسهيل تنفيذ ضوابط الأمن السيبراني.
المسؤوليات الرئيسية
- إجراء تقييمات مخاطر الأمن السيبراني وتوثيق المخاطر المحددة.
- الحفاظ على سجلات المخاطر وخطط المعالجة والإجراءات المتابعة.
- دعم تطوير ومراجعة سياسات وإجراءات ومعايير الأمن السيبراني.
- تقييم الامتثال لإطارات وأطر الأمن السيبراني والتنظيمية المعمول بها.
- تحديد فجوات الضوابط والتوصية بخطوات الإصلاح المناسبة.
- جمع وتنظيم ومراجعة أدلة الامتثال.
- إعداد تقارير المخاطر والامتثال للإدارة وأصحاب المصلحة في المشروع.
- مراقبة أنشطة الإصلاح والمتابعة مع الفرق المعنية.
- دعم عمليات التدقيق والتقييمات الأمنية السيبرانية الداخلية والخارجية.
- التنسيق مع الأعمال وتكنولوجيا المعلومات والأمن السيبراني وأصحاب المصلحة في المشروع.
الخبرة والمؤهلات الأساسية
- درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، تكنولوجيا المعلومات، علوم الحاسوب، أو مجال ذي صلة.
- حوالي ** سنوات من الخبرة ذات الصلة في GRC الأمن السيبراني.
- خبرة عملية في تقييم المخاطر وإدارة مخاطر الأمن السيبراني.
المهارات والصفات الأساسية
- إلمام بإطارات ومعايير الأمن السيبراني.
- مهارات قوية في التوثيق والتقارير والتواصل مع أصحاب المصلحة.
- القدرة على العمل بشكل مستقل وإدارة أنشطة متعددة للمخاطر والامتثال.
- الشهادات المهنية في GRC أو الأمن السيبراني أو إدارة المخاطر مطلوبة مفضَّلة.
بيئة العمل والتوافر
هذا الدور يتطلب عملاً بدوام كامل في الموقع بجدة. ستعطى الأولوية للمرشحين المتاحين للانضمام خلال فترة زمنية قصيرة.