Information security GRC Senior Specialist
Zakat, Tax and Customs Authority
Date: 3 weeks ago
City: Riyadh
Contract type: Full time

Purpose of Job
Jobholders at this level are capable of operating with minimal supervision. They work within guidelines and procedures in order to prepare more complex, specialized or ad-hoc reports in their related field. They contribute to the completion of milestones or operational targets within the assigned functional area. They undertake operational activities including designing information security procedures and frameworks, supporting in developing information security, governance, risk and compliance programs, preparing cybersecurity awareness and education plan, conducting cybersecurity assessment to identify potential risks, assisting in developing related mitigation plan and managing the implementation. Conduct security risk assessments, build risk heat maps and quarterly risk reports
Job Responsibilities
Information Security Governance
Communication and Contacs
Education
Bachelor’s degree in Science in Cybersecurity or equivalent is required
Experience
A minimum of 2 years of relevant experience
Competencies
Vendor Management - Developing
Collaboration and Communication - Developing
Professionalism - Developing
IT Operations Management - Developing
Cybersecurity Incident and Investigation - Developing
Project Management - Developing
IT Compliance - Proficient
Results Oriented - Developing
Information Security - Proficient
Customer Focus - Developing
Enablement of Change and Innovation - Developing
Jobholders at this level are capable of operating with minimal supervision. They work within guidelines and procedures in order to prepare more complex, specialized or ad-hoc reports in their related field. They contribute to the completion of milestones or operational targets within the assigned functional area. They undertake operational activities including designing information security procedures and frameworks, supporting in developing information security, governance, risk and compliance programs, preparing cybersecurity awareness and education plan, conducting cybersecurity assessment to identify potential risks, assisting in developing related mitigation plan and managing the implementation. Conduct security risk assessments, build risk heat maps and quarterly risk reports
Job Responsibilities
Information Security Governance
- Set information security policies, standards and develop accordingly related processes ensuring alignment with cybersecurity regulatory requirements
- Design information security procedures and frameworks to ensure consistency in the implementation of security control
- Develop information security, governance, risk and compliance programs for effective management of IT and security risks meeting compliance requirements
- Prepare cybersecurity awareness programs and develop education plan including workshops, seminars, etc. regarding standards, policies and governance processes foster attentiveness and knowledge in cybersecurity topics across ZATCA’s employees
- Conduct cybersecurity risk assessment to identify potential risks and related daily changes initiating the development of needed mitigation plan
- Develop risk mitigation plan and remediation plan to effectively manage risk in accordance with ZATCA’s risk appetite
- Manage cybersecurity risks and risks register to identify, log and track potential risks ensuring compliance with cybersecurity standards and governance policies and procedures
- Follow-up on the implementation of corresponding mitigating controls as per set plan ensuring update of risk register
- Conduct risk assessment for the identified non-conformities during security audits and recommend accordingly needed improvement action for protection and detection capabilities
- Perform information security audit, semiannually assessment against NCA and annually assessment against ISO 27001 to recognize patterns and cases of non-compliance with cybersecurity policies and recommend accordingly areas of improvement
- Manage non-compliance cases improving business process and operations by supporting external assessments against NCA framework
- Develop periodic report consolidating the status of information security compliance and report it with regulates (ISO 27001 & NCA)
- Follow all relevant policies, processes and standard operating procedures so that work is carried out in a controlled and consistent manner
- Help in solving escalated problems and provide needed support for junior team to ensure work is carried out in an efficient manner
- Escalate complex problems to the relevant person to ensure cases/issues are closed properly
- Perform other duties as requested
- Train junior staff on the different job activities to ensure transfer of know-how, when applicable
- Provide clear direction, prioritize tasks, assign and delegate responsibility, and monitor the workflow of subordinates/ junior staff
- Support junior staff or direct reports in order to execute their duties according to set policies and processes
Communication and Contacs
Education
Bachelor’s degree in Science in Cybersecurity or equivalent is required
Experience
A minimum of 2 years of relevant experience
Competencies
Vendor Management - Developing
Collaboration and Communication - Developing
Professionalism - Developing
IT Operations Management - Developing
Cybersecurity Incident and Investigation - Developing
Project Management - Developing
IT Compliance - Proficient
Results Oriented - Developing
Information Security - Proficient
Customer Focus - Developing
Enablement of Change and Innovation - Developing
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Sr. Marketing Associate, Medical Saudi Arabia
Stryker,
Riyadh
1 hour ago
What You Will Do:Understands competitor positioning, collects customer intelligence, and identifies customer needs to inform marketing efforts.Contributes to strategic documents (e.g., marketing plans, launch plans), uses templates and metrics to support planning, and collaborates on segmentation and positioning.Manages budgets, explains their purposes, performs pricing and financial analyses, and contributes to forecasting and demand planning.Supports value proposition development, segmentation, and positioning;...

Permit Reviewer (Saudization)
WSP in the Middle East,
Riyadh
19 hours ago
Job Description""At WSP, you can access our global scale, contribute to landmark projects and connect with the brightest minds in your field to do the best work of your life. You can embrace your curiosity in a culture that celebrates new ideas and diverse perspectives. You can experience a world of opportunity and the chance to shape a career as...

Senior Manager - Customer & Growth - Business Consulting - Riyadh 1
EY,
Riyadh
20 hours ago
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. In a world of dramatic and fast-paced change, the ability to deliver seamless and innovative customer experiences...
