وظيفة أخصائي حوكمة ومخاطر وامتثال الأمن السيبراني شاغرة لدى CYBER سايبر في جدة
تفاصيل الوظيفة
شركة CYBER سايبر تعلن عن وظيفة متخصص في حوكمة أمن المعلومات وإدارة المخاطر والامتثال (Cyber Security GRC Specialist) في مدينة جدة، السعودية، بنظام الدوام الكامل.
المهام والمسؤوليات
- تطوير وتنفيذ وصيانة سياسات وأطر ومعايير حوكمة الأمن السيبراني.
- مراقبة الالتزام المؤسسي بسياسات وضوابط الأمن السيبراني وإعداد تقارير دورية للمدير التنفيذي لأمن المعلومات.
- إجراء تقييمات شاملة لمخاطر الأمن السيبراني عبر الوحدات والبيئات السحابية، وتحديث سجل المخاطر باستمرار، ومتابعة إغلاق المخاطر ونتائج التدقيق.
- ضمان الامتثال للأطر التنظيمية السعودية (NCA ECC، SAMA CSF) والمعايير الدولية مثل ISO 27001، ودعم أنشطة التدقيق الداخلي والخارجي.
- المساهمة في تطوير خطط استمرارية الأعمال والتعافي من الكوارث، ودعم اختبار الإجراءات، والمشاركة في الاستجابة للحوادث لتقليل الاضطرابات التشغيلية.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو مجال ذي صلة.
- خبرة من 2 إلى 4 سنوات في مجالات حوكمة أمن المعلومات وإدارة المخاطر والامتثال (GRC) أو أدوار مشابهة.
- فهم قوي لأطر الحوكمة ومنهجيات إدارة المخاطر وممارسات الامتثال.
- معرفة بالمتطلبات التنظيمية السعودية (NCA، SAMA) ومعايير ISO 27001.
- خبرة عملية في أدوات GRC (يفضل).
- الشهادات المهنية المفضلة: ISO 27001 Lead Implementer، CompTIA Security+، أو أي شهادات GRC أخرى ذات صلة.
عرض النص الأصلي للإعلان
Cybersecurity GRC Specialist
📍 Saudi Arabia | 🏢 Cyber | 🕒 Full-time Location: Jeddah
About CyberAt Cyber, we are committed to strengthening organizational resilience through robust cybersecurity governance, risk management, and regulatory compliance. We operate in alignment with the Kingdom of Saudi Arabia’s regulatory landscape, ensuring adherence to NCA, SAMA, and international best practices.
We are seeking a Cybersecurity GRC Specialist to support and enhance our Governance, Risk, Compliance, and Security Awareness programs. This role plays a critical part in protecting our information assets, cloud environments, and data by ensuring effective governance structures, regulatory compliance, and risk mitigation strategies.
Key Responsibilities🔹 Cybersecurity Governance- Develop, implement, and maintain cybersecurity governance policies, frameworks, and standards.
- Monitor organizational adherence to established cybersecurity policies and controls.
- Provide periodic governance and risk posture reports to the CISO and executive leadership.
- Maintain cybersecurity documentation aligned with regulatory and industry standards.
- Conduct comprehensive cybersecurity risk assessments across business units and cloud environments.
- Identify, evaluate, and prioritize cybersecurity risks.
- Maintain and continuously update the organizational risk register.
- Drive remediation efforts and ensure timely closure of identified risks and audit findings.
- Ensure compliance with KSA regulatory frameworks (e.g., NCA ECC, SAMA CSF) and international standards such as ISO 27001.
- Support internal and external audit activities.
- Evaluate the effectiveness of implemented technical and administrative security controls.
- Prepare and submit regulatory compliance reports as required.
- Assist in the development and maintenance of Business Continuity and Disaster Recovery plans.
- Support Business Impact Analysis (BIA) activities.
- Participate in testing and validation of continuity and recovery procedures.
- Contribute to incident response efforts to ensure minimal operational disruption.
- Support and promote cybersecurity awareness initiatives across the organization.
- Assist in managing awareness tools and programs.
- Foster a strong cybersecurity culture and ensure employee understanding of risks and responsibilities.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field.
- 2-4 years of experience in Cybersecurity GRC or related roles.
- Strong understanding of governance frameworks, risk management methodologies, and compliance practices.
- Knowledge of KSA regulatory requirements (NCA, SAMA) and ISO 27001 standards.
- Hands-on experience with GRC tools is preferred.
- ISO 27001 Lead Implementer
- CompTIA Security+
- Other relevant GRC certifications are a plus
رقم الإعلان لدى المصدر: 4461284377