الوصف الوظيفي
Managed.sa تبحث عن اختصاصي حوكمة وامتثال (GRC) متحمس لدعم مشروع الأمن السيبراني القائم في جدة.
يُفَضَّل أن يمتلك المرشح المثالي خبرة عملية في الحوكمة وإدارة المخاطر والامتثال، مع اهتمام قوي بإدارة مخاطر الأمن السيبراني. يتطلب هذا الدور العمل عن كثب مع أصحاب المصلحة من الأعمال والتقنية لتقييم المخاطر، الحفاظ على وثائق الامتثال، ودعم تنفيذ ضوابط الأمن السيبراني.
المسؤوليات الأساسية
- إجراء تقييمات مخاطر الأمن السيبراني وتوثيق المخاطر المحددة.
- الحفاظ على سجلات المخاطر وخطط المعالجة والإجراءات المتابعة.
- دعم تطوير ومراجعة سياسات وإجراءات ومعايير الأمن السيبراني.
- تقييم الامتثال للإطارات التنظيمية ومتطلبات الأمن السيبراني المعمول بها.
- تحديد ثغرات الضوابط وتوصية إجراءات التصحيح المناسبة.
- جمع وتنظيم ومراجعة أدلة الامتثال.
- إعداد تقارير المخاطر والامتثال للإدارة وأصحاب المصلحة في المشروع.
- متابعة أنشطة المعالجة ومتابعة الفرق المعنية.
- دعم التدقيقات والتقييمات الداخلية والخارجية للأمن السيبراني.
- التنسيق مع أصحاب المصلحة من الأعمال وتكنولوجيا المعلومات والأمن السيبراني والمشروع.
ملف المرشح المطلوب
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو تكنولوجيا المعلومات أو علوم الحاسوب أو مجال ذي صلة.
- حوالي 1.5–3 سنوات من الخبرة ذات الصلة في حوكمة وامتثال الأمن السيبراني.
- خبرة عملية في تقييم مخاطر الأمن السيبراني وإدارة المخاطر.
- الإلمام بأطر ومعايير الأمن السيبراني مثل:
- الهيئة العامة للمنشآت الصغيرة والمتوسطة (NCA ECC)
- ISO 27001
- ISO 31000
- إطار عمل الأمن السيبراني NIST
-
- مهارات قوية في التوثيق والتقارير والتواصل مع أصحاب المصلحة.
- القدرة على العمل بشكل مستقل والمتابعة في أنشطة المخاطر والامتثال المتعددة.
- يفضل الحصول على شهادات مهنية في GRC أو الأمن السيبراني أو إدارة المخاطر.
- التوفر للعمل بدوام كامل في الموقع بجدة.
- سيتم إعطاء الأولوية للمرشحين القادمين خلال إطار زمني قصير.
Job Description
Managed.sa is seeking a motivated GRC Specialist to support a cybersecurity project based in Jeddah.
The ideal candidate will have practical experience in Governance, Risk, and Compliance, with a strong interest in cybersecurity risk management. This role requires working closely with business and technical stakeholders to assess risks, maintain compliance documentation, and support the implementation of cybersecurity controls.
Key Responsibilities
- Conduct cybersecurity risk assessments and document identified risks.
- Maintain risk registers, treatment plans, and follow-up actions.
- Support the development and review of cybersecurity policies, procedures, and standards.
- Assess compliance with applicable cybersecurity frameworks and regulatory requirements.
- Identify control gaps and recommend appropriate remediation actions.
- Collect, organize, and review compliance evidence.
- Prepare risk and compliance reports for management and project stakeholders.
- Monitor remediation activities and follow up with relevant teams.
- Support internal and external cybersecurity audits and assessments.
- Coordinate with business, IT, cybersecurity, and project stakeholders.
Desired Candidate Profile
- Bachelor s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field.
- Approximately 1.5 3 years of relevant experience in cybersecurity GRC.
- Practical experience in cybersecurity risk assessment and risk management.
- Familiarity with cybersecurity frameworks and standards such as:
- NCA ECC
- ISO 27001
- ISO 31000
- NIST Cybersecurity Framework
-
- Strong documentation, reporting, and stakeholder communication skills.
- Ability to work independently and follow up on multiple risk and compliance activities.
- Professional certifications in GRC, cybersecurity, or risk management are preferred.
- Availability to work full-time on-site in Jeddah.
- Candidates who can join within a short timeframe will be prioritized.