Cloud Consultancy - CCDS تعلن عن وظيفة أخصائي حوكمة ومخاطر والامتثال في الأمن السيبراني في الرياض
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
تفاصيل الوظيفة
تقدم شركة Cloud Consultancy - CCDS وظيفة أخصائي حوكمة ومخاطر والامتثال في الأمن السيبراني (GRC) للعمل في الموقع لدى إحدى الجهات الحكومية في الرياض، بعقد مشروع خدمات أمن سيبراني مُدارة (13 شهرًا).
المهام والمسؤوليات
- مراجعة وتحديث سياسات وإجراءات ومعايير وإرشادات الأمن السيبراني بشكل دوري.
- إجراء تقييمات مخاطر الأمن السيبراني تغطي الأصول والأنظمة والمشاريع والأطراف الثالثة.
- الحفاظ على سجل مخاطر الأمن السيبراني، وتطوير خطط المعالجة، وتتبع الإجراءات، ومواءمة القرارات مع مستوى الرغبة في المخاطرة المعتمد للجهة.
- إجراء تقييمات فجوة الامتثال مقابل ضوابط الهيئة الوطنية للأمن السيبراني (NCA) ومعيار ISO/IEC 27001 والأطر الوطنية أو الدولية الأخرى ذات الصلة.
- دعم عمليات التدقيق الداخلي والخارجي، وإعداد الأدلة، وإدارة حالات عدم الامتثال، ومتابعة العلاج حتى الإغلاق.
- تشغيل أو دعم أدوات إدارة الحوكمة والمخاطر والامتثال الإلكترونية (eGRC) وأدوات إدارة مخاطر الأمن السيبراني.
- إعداد تقارير الإدارة ولوحات المعلومات التنفيذية ومؤشرات الأداء الرئيسية وتقارير حالة الامتثال والعروض التقديمية على مستوى اللجان.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو أمن المعلومات أو مجال ذي صلة.
- خبرة لا تقل عن 6 سنوات في مجال حوكمة ومخاطر والامتثال في الأمن السيبراني.
- معرفة متقدمة بأطر ومعايير الأمن السيبراني السعودية والدولية، بما في ذلك ضوابط الهيئة الوطنية للأمن السيبراني (NCA) ومعيار ISO/IEC 27001.
- خبرة مثبتة في سجلات مخاطر الأمن السيبراني وخطط المعالجة ومخاطر الطرف الثالث والتقارير التنفيذية وأدوات eGRC.
- الشهادات المهنية المفضلة: CISSP، CISM، CRISC، أو ISO/IEC 27001 Lead Implementer (LI).
المهارات المطلوبة
- مهارات قوية في إدارة أصحاب المصلحة والثقة في العمل مع القيادة العليا.
- مهارات ممتازة في التحليل والكتابة والعرض والتوثيق.
- منظم وموجه نحو التفاصيل ومسؤول وقادر على تنسيق العلاج عبر فرق متعددة.
عرض النص الأصلي للإعلان
Location: On-site - Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 6+ years
Role Purpose
Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.
Key Responsibilities
Technical and Professional Requirements
Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 6+ years
Role Purpose
Support the governmental entity's cybersecurity governance, enterprise risk, regulatory compliance, audit readiness, and executive reporting activities.
Key Responsibilities
- Review and periodically update cybersecurity policies, procedures, standards, and guidelines
- Perform cybersecurity risk assessments covering assets, systems, projects, and third parties
- Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity's approved risk appetite
- Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks
- Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure
- Operate or support eGRC and cybersecurity risk-management tools
- Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations
Technical and Professional Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field
- At least 6 years of experience in cybersecurity governance, risk, and compliance
- Advanced knowledge of Saudi and international cybersecurity frameworks and standards, including NCA controls and ISO/IEC 27001
- Proven experience with cybersecurity risk registers, treatment plans, third-party risk, executive reporting, and eGRC tools
- Strong stakeholder-management skills and confidence working with senior leadership
- Excellent analytical, writing, presentation, and documentation skills
- Structured, detail-oriented, accountable, and able to coordinate remediation across multiple teams
Preferred: CISSP, CISM, CRISC, or ISO/IEC 27001 Lead Implementer (LI).
المصدر: LinkedIn - أُضيفت للموقع في 27 أغسطس 2026
رقم الإعلان لدى المصدر: 4459674873
رقم الإعلان لدى المصدر: 4459674873