Senior Cybersecurity GRC Officer
Skills
About This Role
Job Purpose
The Senior Cybersecurity GRC Officer is responsible for leading and executing cybersecurity governance, risk, compliance, policy management, control assessment and audit support activities. The role identifies, assesses, monitors and reports cybersecurity risks; ensures the cybersecurity program complies with applicable requirements, policies and standards; develops and maintains cybersecurity policies; assesses cybersecurity control effectiveness; and supports cybersecurity audits and assurance activities.
Cybersecurity Risk Management
Conduct cybersecurity risk assessments for systems, applications, infrastructure, third parties, projects and major technology changes.
Develop cybersecurity risk profiles by assessing threats, vulnerabilities, likelihood, impact and existing controls.
Develop risk mitigation strategies, countermeasures and residual risk statements in line with risk appetite.
Maintain cybersecurity risk registers and confirm whether risk levels remain within acceptable limits.
Coordinate with risk owners to assign ownership, agree treatment actions, define target dates and track remediation status.
Provide input to the cybersecurity risk management framework, scoring methodology and related documentation.
Use continuous monitoring outputs, metrics and evidence to support ongoing cybersecurity risk awareness.
Communicate cybersecurity risks and posture to management in clear, concise and actionable reporting.
Compliance Management and Regulatory Assurance
Monitor and evaluate cybersecurity program compliance with applicable requirements, policies, standards and controls.
Analyze cybersecurity defense policies and configurations to evaluate compliance with regulations and organizational directives.
Develop methods to monitor and measure risk, compliance and assurance activities.
Maintain awareness of applicable cybersecurity legislation, regulatory requirements, accreditation standards and compliance documentation.
Coordinate with relevant regulatory agencies, external auditors and authorized parties during compliance
reviews or investigations.
Collect evidence, track remediation and maintain audit-ready documentation for compliance activities.
Develop cybersecurity compliance processes and audits for services provided by third parties where applicable.
Cybersecurity Policy and Documentation Governance
Develop cybersecurity policies and related documentation.
Review existing and proposed policies and related documentation with stakeholders.
Analyze the organization’s cybersecurity policy environment and identify improvement requirements.
Work with stakeholders to develop cybersecurity policies aligned with the organization’s cybersecurity strategy.
Create, update, publish and maintain cybersecurity policies, standards, procedures and supporting governance documents.
Provide policy guidance to cybersecurity management, staff and users.
Ensure policies are periodically reviewed and remain aligned with organizational objectives, cybersecurity strategy and regulatory requirements.
Security Control Assessment and Effectiveness Reviews
Assess the effectiveness of cybersecurity controls across technology, process and governance areas.
Perform cybersecurity reviews and identify security gaps in security architecture, system design and control implementation.
Assess configuration management processes and verify that system, application and network configurations comply with cybersecurity policies.
Review risk registers, accreditation packages and supporting documentation to assess whether risk and control evidence are complete and accurate.
Provide technical and procedural evaluations of applications, systems or networks and document compliance against agreed cybersecurity requirements.
Recommend cost-effective security controls and remediation strategies to mitigate identified risks and control gaps.
Ensure security design and cybersecurity development activities are appropriately documented.
Track remediation of vulnerabilities and control deficiencies to support control maturity improvement.
Cybersecurity Audit Support and Assurance Reporting
Plan, support, conduct and manage cybersecurity audits or reviews of systems, networks, applications, services and cybersecurity processes.
Prepare cybersecurity assessment and audit reports that identify technical and procedural findings with recommended remediation actions.
Track audit findings and recommendations to ensure appropriate mitigation actions are taken.
Maintain an audit log and evidence repository for cybersecurity controls and assurance activities.
Ensure cybersecurity audits test relevant aspects of infrastructure and policy compliance.
Develop secure information-sharing processes with external auditors when required.
Communicate audit findings, risk implications and remediation status to authorized stakeholders.
Third-Party, Procurement and Supply Chain GRC
Evaluate cybersecurity aspects of contracts to ensure compliance with financial, contractual, legal
and regulatory requirements.
Ensure products implemented to manage cybersecurity risks are evaluated and authorized for use.
Determine and document supply chain risks for critical system elements.
Support cybersecurity reviews of third-party services, outsourced arrangements and supplier-provided technology solutions.
Develop and review cybersecurity compliance processes and audits for third-party services.
Identify cybersecurity and privacy issues related to connections with internal and external third parties and their supply chains.
Stakeholder Engagement and Advisory
Establish and maintain appropriate communication channels with stakeholders.
Present risk, compliance and control assessment results to technical and non-technical audiences.
Provide cybersecurity guidance to business, IT and control functions on governance, risk and compliance matters.
Work with stakeholders to resolve cybersecurity incidents, vulnerability compliance issues and control weaknesses from a GRC perspective.
Promote cybersecurity policy and strategy awareness among management and relevant users.
Support management reporting on cybersecurity risks, readiness, compliance status and progress against plans.
Your resume, rewritten
for this exact role.
Sign up free — Base Career tailors your CV to this job description in 60 seconds.
01 / 05
Resume Tailored to This Job

Your keywords, structure, and story — rewritten to match this exact role and pass ATS filters.
Free · No card · 60 seconds
02 / 05
Cover Letter for This Role, Done

Job-specific cover letters written in Gulf professional tone — ready in seconds, not hours.
Free · No card · 60 seconds
03 / 05
See How Well You Fit This Role

AI match score with clear reasons — know your fit before investing time in the application.
Free · No card · 60 seconds
04 / 05
Apply in One Click

Autofill any application form on Workday, LinkedIn, Bayt, Greenhouse — with your tailored content.
Free · No card · 60 seconds
05 / 05
Track It. Follow Up at the Right Time.

Visual pipeline for every application with AI-timed follow-up reminders so nothing slips.
Free · No card · 60 seconds
Similar Jobs
Senior Cybersecurity Specialist (f/m/d)
Deutsche Bahn · Riyadh
Railways for the world of tomorrow. DB Engineering & Consulting is a part of the DB group, a world-leading global railway company with an extensive organization in Germany and projects around the world. Our company offer
Skills
SENIOR CYBERSECURITY ANALYST - GRC
Johns Hopkins Aramco Healthcare · Eastern Province
Implement and maintain cybersecurity infrastructure, manage governance and compliance programs, and respond to incidents while ensuring adherence to policies.
Skills
3 days ago
Apply Now↗Apply Now ↗Senior Cybersecurity Lead
HAMS.AI | همس · Riyadh
Company description Hams.AI is an AI company building enterprise automation platforms for large organizations across Saudi Arabia and the region. We work with organizations in government, healthcare, insurance, telecom,
Skills
6 days ago
Apply Now↗Apply Now ↗Senior Cybersecurity Engineer
BAE Systems · Riyadh
Design and implement security measures, manage Security Information Event Management, respond to breaches, and conduct vulnerability assessments for data protection.
Skills
1 weeks ago
Apply Now↗Apply Now ↗Senior Cybersecurity GRC Specialist
TAWANTECH · Riyadh
Conduct cybersecurity risk assessments, develop governance frameworks, ensure compliance, and possess strong analytical skills in cybersecurity GRC.
Skills
2 weeks ago
Apply Now↗Apply Now ↗Senior Cybersecurity GRC Specialist
TAWANTECH · الرياض
Summary: Manage cybersecurity governance, risk, and compliance activities aligned with SAMA CSF, NCA, and ISO 27001, ensuring effective security controls and regulatory compliance. Responsibilities: Conduct cybersecurity
Skills
2 weeks ago
Apply Now↗Apply Now ↗Senior Cybersecurity GRC Specialist
TAWANTECH · Riyadh
Summary: Manage cybersecurity governance, risk, and compliance activities aligned with SAMA CSF, NCA, and ISO 27001, ensuring effective security controls and regulatory compliance. Responsibilities: Conduct cybersecurity
Skills
2 weeks ago
Apply Now↗Apply Now ↗Senior Cybersecurity Specialist (Penetration Testing & Compliance)
EaseHawk Technologies · Riyadh
Job Title: Senior Cybersecurity Specialist (Penetration Testing & Compliance) Location: Riyadh, Saudi Arabia (On-site) Working Hours: 8-hour rotational shifts (24/7 coverage) ⸻ Job Summary We are looking for an experienc
Skills
3 weeks ago
Apply Now↗Apply Now ↗Senior Cybersecurity Analyst
LeadingEdge HR Solutions · Riyadh
Job Title: Senior Cybersecurity Analyst Location : Riyadh, Saudi Arabia Job Summary: Our client is seeking a Senior Cybersecurity Analyst to support our cybersecurity operations, assisting in threat monitoring, detection
Skills
1 months ago
Apply Now↗Apply Now ↗2.2K+
Cover Letters & Follow-ups
1.8K+
Resumes Tailored
190.5K+
Jobs Tracked
Trusted by professionals at
Stop applying blindly.
Start getting hired.
Base Career automates the hardest parts of job searching — apply smarter, not harder.
AI Resume in 60s
Your resume rewritten for this exact role using the job description as the brief.
ATS-Optimized
Get past automated screening filters with the right keywords matched to each job.
Application Tracker
Track every job, follow-up, and interview in one visual kanban board.
Free plan · No credit card required