📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

Managed.sa تعلن عن وظيفة أخصائي GRC في الرياض

GRC Specialist
🏢 Managed.sa
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة Managed.sa عن توفر وظيفة أخصائي الحوكمة والمخاطر والامتثال (GRC Specialist) للانضمام إلى فريق الأمن السيبراني في الرياض. في هذا الدور، ستتولى دعم أنشطة الحوكمة والمخاطر والامتثال، مع التركيز على إجراء تدقيقات أمنية وتقييمات امتثال وتحليل فجوات وخطط معالجة للعملاء، وضمان التوافق مع الأطر السعودية والدولية.

المهام والمسؤوليات

  • دعم تنفيذ أنشطة GRC، بما في ذلك مهام الحوكمة وإدارة المخاطر والامتثال والتدقيق.
  • إجراء ودعم التدقيقات الأمنية وتقييمات الامتثال وفق الأطر السعودية والدولية للأمن السيبراني.
  • تقييم ضوابط الأمن السيبراني، وتحديد فجوات الامتثال، ودعم تطوير خطط المعالجة.
  • بناء استراتيجيات وخرائط طريق للأمن السيبراني تتماشى مع احتياجات العملاء والمتطلبات التنظيمية.
  • تطوير ومراجعة وصيانة سياسات وإجراءات ومعايير ووثائق الأمن السيبراني ذات الصلة.
  • إجراء تقييمات المخاطر ودعم تتبع إجراءات تخفيف المخاطر.
  • جمع أدلة التدقيق والتنسيق مع أصحاب المصلحة الداخليين والخارجيين أثناء أنشطة التقييم.
  • إعداد التقارير والنتائج وملخصات تحليل الفجوات وتحديثات الحالة للإدارة وأصحاب المصلحة.
  • دعم العملاء في تحسين نضج حوكمة الأمن السيبراني والامتثال لديهم.
  • المساهمة في التحسين المستمر لعمليات GRC والقوالب والمنهجيات.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة.
  • خبرة لا تقل عن 3 سنوات في GRC أو الأمن السيبراني أو الامتثال أو إدارة المخاطر أو التدقيق أو مجال ذي صلة.
  • خبرة عملية في التدقيقات الأمنية أو تقييمات الامتثال أو تحليل الفجوات أو مراجعة الضوابط.
  • معرفة جيدة بالأطر السعودية للأمن السيبراني والمتطلبات التنظيمية، خاصة: أرامكو CCC، متطلبات هيئة الاتصالات والفضاء والتقنية (CST)، أطر الهيئة الوطنية للأمن السيبراني (NCA) مثل ECC وOTCC وDCC وCCC، ومتطلبات البنك المركزي السعودي (SAMA) تشمل CSF وMVC وCRFR.
  • فهم معايير أمن المعلومات وأطر الرقابة مثل ISO 27001 وNIST وCIS Controls أو ما يماثلها.
  • مهارات تحليلية قوية مع الاهتمام بالتفاصيل.
  • مهارات جيدة في كتابة التقارير والتوثيق والتواصل.
  • القدرة على العمل بشكل تعاوني مع فرق متعددة التخصصات وأصحاب المصلحة من العملاء.
  • القدرة على إدارة مهام متعددة ودعم المشاريع ضمن الجداول الزمنية المتفق عليها.

المهارات المطلوبة

  • شهادة ISO 27001 Lead Implementer و/أو Lead Auditor (مفضلة).
  • شهادات مهنية مثل CISSP أو CISM أو CISA أو CRISC أو ما يماثلها (مفضلة).
  • خبرة في العمل مع شركات استشارات الأمن السيبراني أو الصناعات الخاضعة للتنظيم (مفضلة).
  • خبرة في إعداد تقارير تنفيذية أو لوحات بيانات أو عروض امتثال (مفضلة).
  • الإلمام بسجلات المخاطر وأدوات تتبع الامتثال وجمع أدلة التدقيق ومتابعة المعالجة (مفضلة).
عرض النص الأصلي للإعلان
We are looking for a motivated and detail-oriented GRC Specialist to join our cybersecurity team.

In this role, you will support governance, risk, and compliance activities, with a strong focus on conducting security audits, compliance assessments, gap analysis, and remediation planning for our customers. You will work closely with internal teams, clients, and stakeholders to assess cybersecurity controls, identify compliance gaps, support the development of cybersecurity strategies and roadmaps, and help ensure alignment with Saudi cybersecurity frameworks and international standards.

Key Responsibilities

  • Support the execution of GRC activities, including governance, risk management, compliance, and audit-related tasks
  • Conduct and support security audits and compliance assessments against Saudi and international cybersecurity frameworks
  • Assess cybersecurity controls, identify compliance gaps, and support the development of remediation plans
  • Build cybersecurity strategies and roadmaps aligned with customers' business needs and regulatory requirements
  • Develop, review, and maintain cybersecurity policies, procedures, standards, and related documentation
  • Conduct risk assessments and support the tracking of risk mitigation actions
  • Gather audit evidence and coordinate with internal and external stakeholders during assessment activities
  • Prepare reports, findings, gap analysis summaries, and status updates for management and stakeholders
  • Support customers in improving their cybersecurity governance and compliance maturity
  • Contribute to the continuous improvement of GRC processes, templates, and methodologies

Requirements

Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.

Minimum of 3 years of experience in GRC, cybersecurity, compliance, risk management, audit, or a related area.

Hands-on experience in security audits, compliance assessments, gap analysis, or control reviews.

Good knowledge of Saudi cybersecurity frameworks and regulatory requirements, especially:

  • Aramco CCC
  • CST cybersecurity requirements
  • NCA frameworks such as ECC, OTCC, DCC, and CCC
  • SAMA cybersecurity requirements, including CSF, MVC, and CRFR

Understanding of information security standards and control frameworks such as ISO 27001, NIST, CIS Controls, or similar.

Strong analytical skills and attention to detail.

Good report writing, documentation, and communication skills.

Ability to work collaboratively with cross-functional teams and customer stakeholders.

Ability to manage multiple tasks and support projects within agreed timelines.

Preferred Qualifications

  • ISO 27001 Lead Implementer and/or Lead Auditor certification
  • Professional certifications such as CISSP, CISM, CISA, CRISC, or similar
  • Experience working with cybersecurity consulting firms or regulated industries
  • Experience preparing executive-level reports, dashboards, or compliance presentations
  • Familiarity with risk registers, compliance trackers, audit evidence collection, and remediation follow-up
المصدر: LinkedIn - أُضيفت للموقع في 19 يوليو 2026

وظائف أخرى لدى Managed.sa