GRC Team Leader

Be among the first applicants.
CONNECT Professional Services
Saudi Arabia
SAR 150,000 - 200,000
Be among the first applicants.
6 days ago
Job description

Job Description:

Responsible for overseeing the execution of the GRC program in collaboration with the executive team as well as maintaining the organization's library of security controls.

Delivery of Security GRC management and processes that align with Security Strategy.

Create, implement, and monitor information security policies, processes, exceptions, and change management requests assessment to automate and continuously monitor information security controls, risks, testing, and incidents.

Implement and monitor cybersecurity measures that are in line with the GRC program and business objectives.

Define the organization's information security policy, design risk and vulnerability assessments, and develop information security policies.

Monitor the organization's compliance with all regulations and standards necessary, identify any compliance gaps, and work to mitigate them.

Carry out the risk management program for the organization and serve as a resource for risk management across various departments, including identifying, mitigating, and monitoring risks.

Implement security controls within the IT system in coordination with the cybersecurity analyst(s).

Develop goals for data privacy based on legal regulations and other compliance needs, design and implement privacy policies and practices, and assess these practices for effectiveness.

Develop and maintain a risk register and risk management framework.

Perform end-to-end IT solutioning/workflow risk assessment to identify potential risks and propose mitigation solutions.

Schedule regular assessments and testing of the effectiveness and efficiency of controls and create security metrics and dashboards.

Ensure that requirements in PCI Standards, IT Audit, Security Standards, Policy, Compliance, and Risk controls are met.

Update security controls and provide support to all stakeholders on security controls covering internal assessments, laws, and regulations.

Perform and investigate internal and external information security risk and exceptions assessments.

Maintain a deep knowledge of risk mitigation principles and techniques of the international risk and security standards to manage compliance with such standards and regulations including ISO 27001, ISO 27005, NIST, PCI/DSS, and more frameworks.

Remain current on best practices and technological advancements and act as the corporate technical resource for security assessment and regulatory compliance.

Support the management of information security governance for the organization, ensuring adherence to policies and standards.

Coordinate periodic security assessments and prioritize and manage response activities.

Assist with the client management aspects of the Information Security team, including client and potential client questionnaires; help design a more effective process including a self-service process and a library of standard responses.

Develop relevant metrics, analyze data, identify trends, and help drive improvements to the control environment.

Perform other related duties as assigned.

Job Requirements:

  1. Bachelor's degree in Engineering, Computer Science, or equivalent.
  2. 8+ years in cybersecurity; relevant IT certification is a plus.
  3. Experience implementing security policies and procedures within a multinational organization is a MUST.
  4. Very good communication skills.
  5. Certifications: ITIL, PMP, CISSP, or CISM (preferred).
  6. Proven leadership in managing large-scale cybersecurity operations.
  7. Strong stakeholder management and strategic planning skills.
  8. Experience leading an ISMS as part of an ISO27001 certified program.
  9. Experience leading PCI compliance and certification program.
  10. Recent experience working in a similar capacity in a financial services organization.
  11. Excellent interpersonal skills, comfortable working at all levels within an organization and in a wide variety of situations.
  12. The ability to work across multiple frameworks and regulatory standards including, but not limited to: NIST, PCI, ISO, and GDPR.
  13. Experience with information security frameworks and standards as well as risk management processes is a must.
  14. Experienced with performing information security audit processes or risk assessments.
  15. Expertise with security policy development, deployment, and adoption acceleration.
Get a free, confidential resume review.
Select file or drag and drop it
Avatar
Free online coaching
Improve your chances of getting that interview invitation!
Be the first to explore new GRC Team Leader jobs in Saudi Arabia