Ninja

Cybersecurity GRC Specialist

Ninja Riyadh, Riyadh Region, Saudi Arabia

Internet Marketplace Platforms · 201-500 employees

9 h ago
security Mid (2-5 yrs) Full-time Saudi Arabia
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Cybersecurity GRC Specialist will manage cybersecurity policies, risk assessments, and compliance evidence to support internal and regulatory audits. They are responsible for tracking remediation actions, maintaining risk registers, and preparing GRC reports for management.

What they look for

Cybersecurity Governance Risk Assessment Compliance Policy Development Control Testing Audit Support Regulatory Compliance Documentation Analytical Skills Stakeholder Coordination Information Security Risk Management Third-party Risk Management Reporting Dashboarding

Requirements

Candidates must hold a bachelor's degree in a relevant field and possess 2–4 years of experience in cybersecurity GRC or risk management. Proficiency in English and Arabic is required, along with familiarity with cybersecurity frameworks and regulatory requirements.

Full description

The Cybersecurity GRC Specialist will support cybersecurity governance, risk, and compliance activities across the Group. The role will focus on maintaining cybersecurity policies and controls, coordinating risk assessments and compliance evidence, tracking remediation actions, and supporting regulatory, audit, and assurance activities.

  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field.
  • 2–4 years of experience in cybersecurity GRC, information security, risk, compliance, or a related function.
  • Good understanding of cybersecurity governance, risk assessment, control testing, and compliance.
  • Familiarity with Saudi cybersecurity requirements and information security frameworks.
  • Strong documentation, analytical, and stakeholder coordination skills.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Professional proficiency in Arabic and English.
  • Certifications such as ISO 27001, CRISC, CISA, CGRC, or equivalent are preferred.

Key Responsibilities

  • Support the development and maintenance of cybersecurity policies, standards, procedures, and governance records.
  • Coordinate cybersecurity risk assessments for systems, projects, suppliers, and business initiatives.
  • Maintain risk registers, track treatment plans, and follow up on overdue actions.
  • Support cybersecurity compliance assessments against regulatory and internal requirements.
  • Coordinate the collection, validation, and organization of compliance and audit evidence.
  • Support Internal Audit, external assessments, and regulatory reviews by preparing required cybersecurity evidence.
  • Track audit findings, remediation actions, and closure evidence.
  • Support cybersecurity due diligence and risk reviews for third parties and service providers.
  • Maintain security exceptions, risk acceptance records, and required follow-ups.
  • Prepare GRC reports, dashboards, and management updates.
  • Identify control gaps and opportunities to improve cybersecurity governance processes.

Similar roles