GRC Consultant – Cybersecurity Governance, Risk & Compliance | Tabuk, Saudi Arabia

Website Dsshield

Location

Tabuk, Saudi Arabia

Job Category

  • Information Technology (IT) & Software
  • Legal & Compliance
  • Government & Public Sector
  • Security & Defence

Job Overview

An opportunity is available for an experienced GRC Consultant (Governance, Risk & Compliance) to support a project with the Tabuk Emirate in Tabuk, Saudi Arabia. The position is focused on cybersecurity governance, risk management, compliance, security controls, and regulatory requirements.

The role is suited to professionals with at least 3 years of GRC experience and practical exposure to implementing and assessing cybersecurity frameworks and controls. Knowledge of Saudi cybersecurity regulatory requirements, particularly the NCA Essential Cybersecurity Controls (NCA ECC), is considered an advantage.

This position provides an opportunity for career growth and professional development through exposure to cybersecurity governance and compliance activities within a government project environment. Candidates can further strengthen their expertise in cybersecurity frameworks, risk management, controls, policies, and regulatory compliance.

Key Responsibilities

  • Support cybersecurity governance, risk, and compliance activities.
  • Implement and assess cybersecurity frameworks and controls.
  • Identify, assess, and manage cybersecurity risks.
  • Review and maintain cybersecurity policies and procedures.
  • Assess organizational controls against applicable cybersecurity requirements.
  • Support compliance assessments and regulatory requirements.
  • Contribute to cybersecurity risk and control documentation.
  • Support implementation and assessment activities related to NCA ECC.
  • Contribute to ISO/IEC 27001 implementation and assessment activities where applicable.
  • Prepare clear and accurate GRC documentation and reports.
  • Coordinate with stakeholders on cybersecurity governance and compliance matters.
  • Identify gaps and support appropriate remediation activities.
  • Maintain effective communication with project stakeholders.

Requirements & Qualifications

  • Minimum 3 years of professional experience in GRC.
  • Practical experience across cybersecurity governance, risk management, and compliance.
  • Hands-on experience implementing and assessing cybersecurity frameworks and controls.
  • Experience with NCA Essential Cybersecurity Controls (NCA ECC) is an advantage.
  • Knowledge or implementation experience with ISO/IEC 27001 is an advantage.
  • Strong understanding of:
    • Cybersecurity risks
    • Security controls
    • Policies and procedures
    • Compliance requirements
    • Governance frameworks
  • Strong analytical and problem-solving capabilities.
  • Excellent documentation and reporting skills.
  • Strong communication and stakeholder-management skills.
  • Saudi nationality is mandatory for this position.

Salary, Benefits & Career Growth

Salary and compensation details have not been provided for this position.

The role offers opportunities for career growth and professional development through hands-on exposure to cybersecurity governance, risk management, compliance frameworks, security controls, and Saudi regulatory requirements.

Professionals can further develop their expertise in areas such as NCA ECC, ISO/IEC 27001, cybersecurity risk assessment, control implementation, governance, and regulatory compliance through practical project experience.

Specific employee benefits, training programs, and certification support have not been specified in the vacancy.

Application Process

Application Process – Website

No official job website or Apply Now link was provided in the vacancy.

Candidates should apply directly through the recruitment email below.

HR Email for Application

Send your updated CV directly

Eligibility: Saudi nationals only.

To apply for this job email your details to Career@dsshield.com