Overview
Cybersecurity Strategy and Governance Sr. Specialist || Jobs in Riyadh, Saudi Arabia at NHC
Title: Cybersecurity Strategy and Governance Sr. Specialist ||
Company: NHC
Location: Riyadh, Saudi Arabia
Job Summary:
The Cybersecurity GRC Senior Specialist is responsible for implementing, maintaining, and continuously enhancing the organization's Cybersecurity Governance, Risk, and Compliance (GRC) framework. The role ensures alignment between cybersecurity initiatives, business objectives, regulatory requirements, and international best practices while supporting the organization's overall cybersecurity maturity.
The successful candidate will play a key role in developing cybersecurity governance processes, ensuring compliance with applicable regulations and standards, coordinating audit activities, managing cybersecurity risks, and supporting continuous improvement initiatives across the organization.
Key Responsibilities
- Implement and maintain the organization's Cybersecurity Governance, Risk, and Compliance (GRC) framework.
- Ensure compliance with applicable cybersecurity laws, regulations, and standards, including the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC), ISO/IEC 27001, and the NIST Cybersecurity Framework.
- Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines to ensure alignment with regulatory and business requirements.
- Conduct cybersecurity compliance assessments and monitor the implementation of required security controls.
- Coordinate internal and external cybersecurity audits and regulatory assessments.
- Manage audit readiness activities, including evidence collection, documentation management, and follow-up on audit findings.
- Track remediation plans and ensure timely closure of compliance gaps and audit observations.
- Perform cybersecurity risk assessments and collaborate with business and technical teams to identify, assess, and mitigate information security risks.
- Support enterprise risk management initiatives related to cybersecurity.
- Prepare compliance reports, executive dashboards, risk metrics, and performance indicators for senior management.
- Collaborate with internal stakeholders to ensure security controls are effectively implemented across business functions.
- Support incident governance activities by ensuring security incidents are documented, reported, and managed in accordance with regulatory requirements.
- Participate in continuous improvement initiatives to enhance governance processes and compliance maturity.
- Monitor emerging cybersecurity regulations, standards, and industry best practices and recommend necessary improvements.
- Support cybersecurity awareness and compliance training initiatives across the organization.
- Participate in special projects and perform other related duties as assigned.
Qualifications
Education
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
Professional Certifications (Preferred)
- CISSP
- CISM
- CISA
- CRISC
- ISO/IEC 27001 Lead Implementer or Lead Auditor (preferred)
Experience
- Minimum of 4 years of experience in Cybersecurity Governance, Risk, and Compliance (GRC), Information Security, IT Risk, or related cybersecurity functions.
- Experience working with regulatory frameworks and international standards such as:
- NCA Essential Cybersecurity Controls (ECC)
- ISO/IEC 27001
- NIST Cybersecurity Framework
- COBIT (preferred)
- Experience in cybersecurity audits, compliance assessments, governance implementation, and risk management.
- Experience preparing compliance documentation and executive-level reporting.
Technical Competencies
- Cybersecurity Governance
- Information Security Risk Management
- Cybersecurity Compliance
- Regulatory Compliance
- Security Policies & Standards Development
- Cybersecurity Audit Management
- Risk Assessment & Risk Treatment
- Internal Control Assessment
- Third-Party Risk Management
- Compliance Monitoring
- Security Metrics & Reporting
- GRC Platforms (preferred)
- Security Awareness Programs
- Continuous Compliance Improvement
Behavioral Competencies
- Strong analytical and problem-solving skills.
- Excellent communication and presentation skills.
- High attention to detail.
- Strong organizational and time management abilities.
- Accountability and ownership.
- Ability to manage multiple priorities simultaneously.
- Excellent stakeholder management and interpersonal skills.
- Ability to work collaboratively across cross-functional teams.
- Continuous learning mindset and adaptability.
Success Measures (KPIs)
- Regulatory compliance status.
- Successful completion of internal and external audits.
- Timely closure of audit findings.
- Compliance maturity improvement.
- Reduction in cybersecurity compliance gaps.
- Risk assessment completion and remediation effectiveness.
- Quality and timeliness of executive reporting.
- Continuous enhancement of cybersecurity governance processes.