وظيفة مدير حوكمة ومخاطر وامتثال الأمن السيبراني شاغرة لدى Talent Blueprint FZ LLC بالرياض
تفاصيل الوظيفة
تعلن شركة Talent Blueprint FZ LLC عن توفر فرصة وظيفية للعمل كمدير للحوكمة والمخاطر والامتثال في الأمن السيبراني (Cybersecurity GRC Manager) في الرياض أو جدة بالمملكة العربية السعودية، ضمن مشروع دولي كبير لأحداث كرة القدم، وذلك بعقد محدد المدة من 15 أكتوبر 2026 حتى 28 فبراير 2027.
المهام والمسؤوليات
- قيادة برنامج الحوكمة والمخاطر والامتثال للأمن السيبراني (GRC) بالكامل في المؤسسة.
- تطوير وصيانة ومراجعة واعتماد سياسات الأمن السيبراني ومعاييره وإجراءاته وأُطر الحوكمة.
- إدارة سجل المخاطر السيبرانية باستمرار من خلال تحديد وتقييم وتتبع ومعالجة المخاطر.
- قيادة تقييمات المخاطر السيبرانية الدورية والطارئة عبر التقنيات والتطبيقات والموردين وعمليات الفعاليات.
- تنسيق تقييمات الامتثال الذاتي للأمن السيبراني والمراجعات الخارجية والتدقيق التنظيمي حسب الحاجة.
- إدارة تقييمات مخاطر الموردين والأطراف الثالثة بما في ذلك العناية الواجبة الأمنية وتتبع المعالجة والمراقبة المستمرة.
- دعم إدارة المخاطر السيبرانية عبر عدد كبير من الموردين والمقاولين والرعاة والناقلين ومقدمي التذاكر وشركاء الضيافة وموردي التكنولوجيا المشاركين في الفعالية.
- الإشراف على برنامج الامتثال لحماية البيانات في المؤسسة بالتنسيق مع الإدارة القانونية وأصحاب المصلحة.
- مراجعة وإدارة متطلبات حماية البيانات المرتبطة بالبيانات الشخصية طوال دورة حياة الفعالية.
- دعم وتنسيق اتفاقيات معالجة البيانات (DPAs) ومتطلبات الأمن/حماية البيانات ذات الصلة مع الرعاة والناقلين وموردي التذاكر والأطراف الثالثة الأخرى.
- تطوير وإدارة برنامج التوعية والتدريب في الأمن السيبراني.
- إدارة عملية استثناءات السياسات وقبول المخاطر مع ضمان التوثيق والتقييم والموافقة والمراجعة الدورية.
- إنشاء مؤشرات أداء رئيسية (KPIs) للحوكمة والمخاطر والامتثال ورفعها إلى الإدارة العليا.
- دعم مراجعات ما بعد الحوادث من منظور الامتثال والإبلاغ والإفصاح التنظيمي.
- مراقبة التغييرات في متطلبات الأمن السيبراني وحماية البيانات المطبقة وتقييم أثرها على المؤسسة.
- تقديم التوجيه لفِرق الأعمال والتقنية بشأن الحوكمة والمخاطر والامتثال ومتطلبات أمن الطرف الثالث.
- العمل بشكل وثيق مع مدير معمارية الأمن السيبراني ومدير الدفاع السيبراني لدمج متطلبات الحوكمة والمخاطر في البنية الدفاعية.
- الحفاظ على الوثائق والأدلة اللازمة لإثبات الامتثال والجاهزية للتدقيق طوال دورة حياة المشروع.
الشروط والمتطلبات
- خبرة لا تقل عن 3 سنوات في مجال الحوكمة والمخاطر والامتثال للأمن السيبراني أو أمن المعلومات أو مخاطر الأمن السيبراني أو الامتثال.
- خبرة مثبتة في إدارة برامج الحوكمة والمخاطر والامتثال للأمن السيبراني.
- خبرة قوية في تطوير وإدارة سياسات الأمن السيبراني ومعاييره وإجراءاته وضوابطه.
- خبرة في صيانة سجلات المخاطر السيبرانية وإجراء تقييمات المخاطر.
- خبرة في إدارة مخاطر الموردين والأطراف الثالثة والعناية الواجبة الأمنية.
- خبرة في دعم أو تنسيق المراجعات الداخلية والخارجية والتنظيمية.
- فهم قوي لأطر الامتثال للأمن السيبراني والمعايير والمتطلبات التنظيمية.
- خبرة في الامتثال لحماية البيانات والخصوصية وترتيبات معالجة بيانات الطرف الثالث (ميزة إضافية).
- خبرة في إدارة استثناءات السياسات وقبول المخاطر وتتبع المعالجة.
- خبرة في تطوير وتقديم برامج التوعية والتدريب في الأمن السيبراني.
- مهارات قوية في التوثيق وإعداد التقارير والتواصل وإدارة أصحاب المصلحة.
- القدرة على العمل بفعالية مع الإدارة العليا والإدارة القانونية والمشتريات وتقنية المعلومات والأمن السيبراني والموردين وأصحاب المصلحة الآخرين.
- خبرة في بيئة واسعة النطاق ومتعددة الموردين أو في مجال الفعاليات الكبرى (ميزة إضافية).
- معرفة بمتطلبات الأمن السيبراني وحماية البيانات في المملكة العربية السعودية (ميزة إضافية).
عرض النص الأصلي للإعلان
Position: Cybersecurity GRC Manager
Location: Riyadh / Jeddah, Saudi Arabia
Contract Duration: 15-Oct-26 - 28-Feb-27
About the Role
We are seeking an experienced Cybersecurity GRC Manager to lead the organization's cybersecurity Governance, Risk, and Compliance function for a major international football event project in Saudi Arabia.
The role will have end-to-end responsibility for cybersecurity governance, risk management, regulatory compliance, third-party risk, audit readiness, policy management, and data protection compliance across the event lifecycle.
The successful candidate will work closely with cybersecurity, legal, procurement, technology, vendors, and senior leadership to ensure that cybersecurity risks and compliance requirements are effectively managed.
Key Responsibilities
- Own and lead the organization's Cybersecurity Governance, Risk, and Compliance (GRC) program end to end.
- Develop, maintain, review, and secure executive approval for cybersecurity policies, standards, procedures, and governance frameworks.
- Own and continuously maintain the cybersecurity risk register, ensuring risks are identified, assessed, tracked, and appropriately treated.
- Lead periodic and event-driven cybersecurity risk assessments across technology, applications, vendors, and event operations.
- Coordinate cybersecurity compliance self-assessments, third-party audits, and regulator-led audits where applicable.
- Manage third-party and vendor cybersecurity risk assessments, including security due diligence, risk identification, remediation tracking, and ongoing monitoring.
- Support cybersecurity risk management across the significant number of vendors, contractors, sponsors, broadcasters, ticketing providers, hospitality partners, and technology suppliers involved in the event.
- Own the organization's data protection compliance program in coordination with Legal and relevant business stakeholders.
- Review and manage data protection requirements associated with personal data processed throughout the event lifecycle.
- Support and coordinate Data Processing Agreements (DPAs) and related security/data protection requirements with sponsors, broadcasters, ticketing vendors, and other third parties.
- Develop and manage the organization's cybersecurity awareness and training program.
- Maintain the policy exception and risk acceptance process, ensuring exceptions are documented, risk assessed, approved, and periodically reviewed.
- Establish and report cybersecurity GRC and compliance KPIs to senior leadership.
- Support post-incident reviews from a regulatory, compliance, reporting, and disclosure-obligation perspective.
- Monitor changes in applicable cybersecurity and data protection requirements and assess their impact on the organization.
- Provide guidance to business and technology teams on cybersecurity governance, risk, compliance, and third-party security requirements.
- Work closely with the Cybersecurity Architecture Manager and Cybersecurity Defense Manager to ensure governance and risk requirements are incorporated into cybersecurity architecture and defense operations.
- Maintain appropriate documentation and evidence to demonstrate compliance and audit readiness throughout the project lifecycle.
Requirements
- 3+ years of relevant experience in Cybersecurity GRC, Information Security GRC, Cybersecurity Risk, Compliance, or Information Security.
- Proven experience managing cybersecurity governance, risk, and compliance programs.
- Strong experience developing and managing cybersecurity policies, standards, procedures, and controls.
- Experience maintaining cybersecurity risk registers and conducting risk assessments.
- Experience with third-party/vendor cybersecurity risk management and security due diligence.
- Experience supporting or coordinating internal, external, third-party, or regulatory audits.
- Strong understanding of cybersecurity compliance frameworks, standards, and regulatory requirements.
- Experience with data protection/privacy compliance and third-party data processing arrangements would be an advantage.
- Experience managing policy exceptions, risk acceptance, and remediation tracking.
- Experience developing and delivering cybersecurity awareness and training programs.
- Strong documentation, reporting, communication, and stakeholder management skills.
- Ability to work effectively with senior leadership, Legal, Procurement, IT, Cybersecurity, vendors, and other business stakeholders.
- Experience working in a large-scale, multi-vendor, or major event environment would be an advantage.
- Knowledge of Saudi cybersecurity and data protection requirements would be an advantage.
Preferred Certifications
Relevant cybersecurity, GRC, risk, and privacy certifications would be an advantage, including:
- CISSP
- CISM
- CRISC
- CISA
- ISO 27001 Lead Implementer / Lead Auditor
- CGRC
- CDPSE
- CIPM / CIPP
- Other recognized cybersecurity GRC, risk, audit, or privacy certifications
رقم الإعلان لدى المصدر: 4468218346