Cybersecurity Governance, Risk & Compliance (GRC) Specialist

Apply Now ↗
📍 Riyadh, Riyadh Province, Saudi ArabiaFull time

About this role

Location: On-site – Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 6+ years

Role Purpose

Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.

Key Responsibilities

·      Review and periodically update cybersecurity policies, procedures, standards, and guidelines.

·      Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.

·      Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite.

·      Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.

·      Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.

·      Operate or support eGRC and cybersecurity risk-management tools.

·      Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.

Technical and Professional Requirements

·      Bachelor’s degree in Computer Science, Information Security, or a related field.

·      At least 6 years of experience in cybersecurity governance, risk, and compliance.

·      Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001.

·      Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools.

Personal Requirements

·      Strong stakeholder-management skills and confidence working with senior leadership.

·      Excellent analytical, writing, presentation, and documentation skills.

·      Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams.

Professional Certifications

Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).

Frequently Asked Questions

Is the salary disclosed for the Cybersecurity Governance, Risk & Compliance (GRC) Specialist position at CCDS?
The salary for this Cybersecurity Governance, Risk & Compliance (GRC) Specialist role at CCDS is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Cybersecurity Governance, Risk & Compliance (GRC) Specialist position at CCDS located?
This Cybersecurity Governance, Risk & Compliance (GRC) Specialist role at CCDS is based in Riyadh, Riyadh Province, Saudi Arabia. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Cybersecurity Governance, Risk & Compliance (GRC) Specialist role at CCDS full-time or part-time?
This is listed as a Full time position. It is posted as a Cybersecurity Governance, Risk & Compliance (GRC) Specialist role at CCDS.
How do I apply for the Cybersecurity Governance, Risk & Compliance (GRC) Specialist position at CCDS?
Click the "Apply Now" button on this page. You will be redirected to CCDS's official application portal hosted on workable where you can submit your application directly.
When was the Cybersecurity Governance, Risk & Compliance (GRC) Specialist job at CCDS posted?
This Cybersecurity Governance, Risk & Compliance (GRC) Specialist position at CCDS was posted on Aug 27, 2026. Apply as soon as possible — early applications are often reviewed first.
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
CCDS
Apply for this role ↗

You'll be redirected to CCDS's official application page on workable.