Job Purpose:
Establishing and overseeing the organization's cybersecurity governance, risk, and compliance framework to ensure alignment with regulatory requirements, industry standards, and business objectives
Key responsibilities:
- Develop and maintain cybersecurity policies, procedures, and control documentation
- Drive the organization’s cybersecurity awareness, phishing and training initiatives
- Ensure policies are updated, communicated, and enforced across departments
- Align governance documents with NCA ECC, ISO 27001, and legal obligations
- Conduct risk assessments, maintain risk register, and define treatment plans
- Ensure compliance with NCA ECC, ISO 27001, and Saudi PDPL requirements
- Perform third-party/vendor risk assessments and due diligence reviews
- Track remediation plans and prepare for internal/external audits
- Maintain dashboards for compliance posture and control performance
- Develop, distribute, and track employee security training and awareness programs
- Conduct phishing simulations and evaluate response trends
- Collaborate with HR on onboarding and offboarding security procedures
- Maintain evidence repository for audits and compliance tracking
- Map security controls NCA ECC domains and ensures maturity documentation
- Support the Risk & Compliance Specialist with reporting and updates
.
Qualifications
- Bachelor’s degree in information security, IT Governance, Law, or Business with Security specialization
- 3–5 years of experience in cybersecurity compliance, audit, or GRC
- In-depth experience in implementing and managing ISMS and compliance framework