Arab Calibers is hiring an IT GRC Consultant for a Payment Company in Riyadh. The ideal candidate should have 7-10 years of experience in Data Governance/Compliance within financial services and be proficient in global data governance standards.
Key Highlights
Technical Skills Required
Benefits & Perks
Job Description
[Relocation: KSA - Arabic Speakers]
We are hiring IT GRC Consultant (Managed Service Resource) for Payment Company located @ Riyadh
Required Skills:
- Minimum of 7–10 years’ experience in Data Governance/Compliance within financial services.
- Arabic Speaker.
- Proven expertise in DPIA, RoPA, Privacy Law (such as GDPR, Saudi Data Protection Law).
- Proficiency in global data governance standards (DAMA-DMBOK, ISO 38505, ISO 27001).
- Certifications: CDMP, CIPP/E, ISO 27001 Lead Implementer or equivalent.
*Scope of Work
The Managed Service Provider will deliver professional support in the following GRC domains:
A. Documentation Management
1. Review, and maintain policies, processes, and procedures aligned with SAMA ITG and NCA frameworks.
2. Implement approval workflows, maintain version control, and ensure documentation is audit-ready.
3. Conduct periodic reviews to reflect NCA and SAMA regulatory updates.
*Risk Reviews
1. Perform comprehensive and recurring risk assessments across IT, operations, compliance, and third parties.
2. Maintain a unified enterprise risk register with consistent scoring aligned with SAMA ITG and NCA methodologies.
3. Deliver risk reports and visual dashboards for management and regulatory review.
*Compliance Monitoring
1. Develop and execute a compliance monitoring plan consistent with SAMA ITG, NCA cybersecurity controls, and local financial regulations.
2. Test controls and identify gaps against both regulatory frameworks.
3. Provide horizon scanning for new SAMA and NCA directives with structured impact analyses.
D. Internal Controls
1. Assess and test the adequacy and effectiveness of existing IT and operational controls.
2. Recommend control enhancements ensuring compliance with SAMA ITG and NCA ECC/CCC standards.
3. Perform control maturity assessments and document remediation actions.
*Reporting
1. Develop and deliver monthly and quarterly GRC performance reports.
2. Provide dashboards and summaries suitable for executive and board-level governance.
3. Ensure reports explicitly reference compliance posture against both SAMA and NCA domains.
*Audits
1. Conduct internal GRC and control audits to verify alignment with regulatory requirements.
2. Assist the Institution during SAMA inspections and NCA cybersecurity compliance reviews.
3. Maintain an auditable trail of remediation actions and closure evidence.
If anyone is interested, please send your CV to [email protected] with Email subject as "IT GRC_SA"
Similar Jobs
Explore other opportunities that match your interests