الشركة السعودية لخدمات الملاحة الجوية تعلن عن وظيفة رئيس قسم الحوكمة والمخاطر والامتثال الرقمية في جدة
تفاصيل الوظيفة
يقوم قائد قسم الحوكمة الرقمية والمخاطر والامتثال (Digital GRC Section Head) بالإشراف على ممارسات الحوكمة والمخاطر والامتثال لتقنية المعلومات في الشركة السعودية لخدمات الملاحة الجوية (SANS) عبر المنصات الرقمية، وضمان فعالية الرقابة على المخاطر والجاهزية للتدقيق والالتزام بالسياسات واللوائح، مع تمكين العمليات الواعية بالمخاطر من خلال دمج أطر GRC في عمليات تقنية المعلومات وإدارة مخاطر الطرف الثالث وتقديم تقارير قابلة للتنفيذ لرئيس القسم (مكة - جدة - السعودية).
المهام والمسؤوليات
- إنشاء وتحسين وتطبيق أطر الحوكمة والسياسات والضوابط لتقنية المعلومات عبر المشهد التقني للمؤسسة، وضمان توافق ممارسات الحوكمة مع المعايير والمتطلبات التنظيمية وأفضل الممارسات الصناعية.
- تقديم تقارير منظمة وتحديثات لرئيس القسم حول مستويات اعتماد السياسات والامتثال.
- قيادة تقييمات مخاطر تقنية المعلومات على مستوى المؤسسة والحفاظ على سجل مركزي للمخاطر مع تحديد ملكية وجداول زمنية للمعالجة.
- ترتيب أولويات الثغرات والمخاطر بناءً على أثر الأعمال، والتكامل مع وظائف البنية التحتية والأمن لمعالجتها.
- تعزيز ثقافة واعية بالمخاطر عبر فرق تقنية المعلومات من خلال التوعية والإرشادات العملية.
- الإشراف على أطر الامتثال (ISO، NCA، GDPR، إلخ) وضمان جاهزية المنصات الرقمية للتدقيق.
- قيادة اختبار الضوابط وتقييم الفجوات وتخطيط المعالجة، والتنسيق للاستجابات في الوقت المحدد للتدقيقات الداخلية والخارجية.
- ضمان صيانة مستودعات الأدلة لاستجابات تدقيق فعالة.
- قيادة تقييم نضج جهات الطرف الثالث في GRC، وإدراج البنود القائمة على المخاطر في العقود، ومراقبة الامتثال من خلال اتفاقيات مستوى الخدمة والشهادات أو التدقيقات المستقلة.
- تعريف وصيانة لوحات معلومات GRC تغطي وضع المخاطر ونتائج التدقيق والجداول الزمنية للمعالجة وحالة الامتثال، مع تقديم تحديثات منتظمة لرئيس القسم ولجان الحوكمة.
- التحسين المستمر لممارسات GRC من خلال المقارنة المرجعية وتقييمات النضج والدروس المستفادة.
- دعم مراقبة الأنشطة اليومية لضمان الامتثال للسياسات والإجراءات المقررة، والمساهمة في تحديد فرص التحسين المستمر مع مراعاة الممارسات الرائدة والتغيرات في بيئة الأعمال وخفض التكاليف وزيادة الإنتاجية.
- المشاركة الفاعلة في التدريب والتوجيه والإرشاد للمرؤوسين، وتوفير توجيه واضح وتحديد الأولويات وتفويض المسؤوليات ومراقبة سير العمل، وتعزيز بيئة عمل عالية الأداء تتماشى مع قيم الشركة.
الشروط والمتطلبات
- خبرة لا تقل عن 6 سنوات في مجال ذي صلة أو ما يعادلها.
- درجة البكالوريوس في الهندسة أو علوم الحاسب أو تقنية المعلومات أو ما يعادلها.
- يفضل الحصول على شهادات في التدقيق والضمان (audit and assurance)، بالإضافة إلى خبرة في إدارة المخاطر ومؤشرات الأداء الرئيسية (KPI-P) والامتثال وأطر الرقابة الداخلية.
عرض النص الأصلي للإعلان
Role Purpose
Lead SANS IT governance, risk and compliance (GRC) practices across digital platforms, ensuring effective risk oversight, audit readiness, and adherence to policies and regulations, enable accountable, risk-aware operations by embedding GRC frameworks into SANS IT processes, managing third-party risks, and providing actionable reporting to the Section Head.
KEY ACCOUNTABILITIES & ACTIVITIES
Governance Framework & Policy Oversight
- Establish, refine, and enforce IT governance frameworks, policies, and controls across the enterprise technology landscape.
- Ensure governance practices align with standards, regulatory requirements, and industry best practices.
- Provide structured reporting and updates to the Section Head on policy adoption and compliance levels.
Enterprise Risk Management & Vulnerability Oversight
- Lead enterprise-level IT risk assessments and maintain a centralized risk register, ensuring ownership and remediation timelines are defined.
- Prioritize vulnerabilities and risks based on business impact, integrating with architecture, infrastructure, and security functions for remediation.
- Drive adoption of a risk-aware culture across IT teams through awareness and practical guidelines.
Compliance Management & Audit Readiness
- Oversee compliance frameworks (ISO, NCA, GDPR, etc.) and ensure digital platforms are audit ready.
- Lead control testing, gap assessments, and remediation planning; coordinate timely responses to internal/external audits.
- Ensure that evidence repositories are well-maintained for efficient audit responses.
Third-party & Vendor Risk Governance
- Lead assessments of vendor GRC maturity, embed risk-based clauses, and monitor compliance.
- Ensure vendors demonstrate compliance through SLAs, certifications, or independent audits.
Performance Reporting, Metrics & Continuous Improvement
- Define and maintain GRC dashboards covering risk posture, audit findings, remediation timelines, and compliance status.
- Provide regular structured updates to the Section Head and governance committees.
- Continuously uplift GRC practices through benchmarking, maturity assessments, and lessons learned.
Policies, Processes and Procedures
- Support in monitoring day-to-day activities to ensure compliance with stipulated policies and procedures
- Contribute to the identification of opportunities for continuous improvement of systems and processes taking into account leading practices, changes in business environment, cost reduction and productivity improvement
People Management
- Actively participate in on-the-job training, mentoring and coaching of subordinates
- Provide clear direction, prioritize tasks, assign and delegate responsibility and monitor the workflow
- Promote a high-performance working environment embracing SANS’s values
QUALIFICATIONS / REQUIREMENTS
Knowledge and Experience
- Minimum 6 years of experience in a related field or equivalent is required.
Education and Certifications
- A bachelor’s degree in Engineering, Computer Science, Information Technology (IT), or equivalent is required.
- Preferrable qualifications include certifications in audit and assurance, as well as expertise in risk management, KPI-P, compliance, and internal control frameworks.
رقم الإعلان لدى المصدر: 4464506922