Tasnee Circular Logo

Specialist II, IT Security GRC

Tasnee Riyadh, Saudi Arabia Posted: 19 Jun 2025

Financial

  • Estimate: $40k - $60k*
  • Zero income tax location

Accessibility

  • Office Only
  • Apply from abroad
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional

Position

An exciting opportunity is available for the position of Specialist II, IT Security GRC at TASNEE, located in Riyadh. The role involves reporting to the Section Head of Security Assurance & Awareness. The primary function of this position is to assist TASNEE in implementing, facilitating, and maintaining ISO 27001 and local cybersecurity regulations, as well as the requirements of the KSA National Cybersecurity Authority (NCA).

Key responsibilities include developing and maintaining an information security management system (ISMS) that covers IS objectives, risk management, ISMS roles and responsibilities, documentation control, records management, performance evaluation, audits, and continual improvement efforts.

Role Responsibilities:

  • Lead and manage the development and maintenance of information security management policies and procedures.
  • Drive upgrades and continuous improvement projects for information security.
  • Develop and maintain a risk register and risk management framework.
  • Perform internal audits for information security and service management systems.
  • Lead the development of service continuity plans and related policies and procedures.
  • Act as a process manager for one or more SMS and ISMS processes.
  • Host, coordinate, and facilitate IT-related external and third-party audits.
  • Control ISMS documentation and records.
  • Lead or coordinate corrective and preventive actions following major incidents, audit findings, or other means.
  • Produce and maintain ISO 27001 required documents and records.
  • Conduct and manage IT Disaster Recovery Exercises.

Qualifications and Requirements:

  • Bachelor’s degree in Computer Science or Information Systems.
  • Minimum of 4 years of experience in the field.
  • Certification as a Information Security Manager (CISM) or equivalent.
  • Good knowledge of information security management policies, procedures, and ISO 27001.
  • Fair knowledge of COBIT and ISO 20000 is a plus.
  • Hands-on experience in implementing and maintaining an information security management system.
  • Strong negotiation and communication skills.
  • Planning and organizing abilities.
  • Fluency in English (written and spoken).

Work Conditions:
On-site, Full-time
Location:
Riyadh Region, Saudi Arabia

Apply now

Jobs you might like   View all jobs

About Tasnee

Tasnee was established in 1985 as the first Saudi private sector's fully owned joint stock industrial company with the aim of advancing economic diversification in Saudi Arabia. It is one of Saudi Arabia's largest industrial companies and one of the world's largest investors in titanium dioxide. Tasnee is committed to innovation and supports product innovation through its global research and development centers.