Governance, Risk & Compliance Specialist
Naseej
3–5 years of experience
Job description
This role is responsible for identifying, assessing, and managing cybersecurity risks for a project within the Saudi Ministry of Commerce . It supports the implementation of risk management processes, maintains risk registers, and ensures compliance with applicable regulatory and industry frameworks such as NCA, SAMA, and ISO 27001.
Key Responsibilities:
Conduct cybersecurity risk assessments to identify, evaluate, and document risks, threats, vulnerabilities, and control gaps.
Maintain and update risk registers, ensuring risks are accurately tracked, monitored, and reported.
Support the development, implementation, and monitoring of risk treatment and mitigation plans to reduce project and organizational risk exposure.
Prepare periodic risk reports and dashboards, and coordinate with stakeholders to ensure timely remediation of identified risks.
Ensure alignment with the cybersecurity and regulatory requirements applicable to the Saudi Ministry of Commerce project.
Assist in ensuring compliance with cybersecurity regulatory requirements and standards, including NCA, SAMA, and ISO 27001.
Support internal and external audits, compliance assessments, and risk-related governance activities.
Saudi National
Bachelor's degree in Cybersecurity, Information Security, or a related field
3-5 years of practical experience in cybersecurity compliance or GRC