We are looking for a Global Cybersecurity GRC Manager to manage and coordinate cybersecurity governance, risk, and compliance activities across the company under the direction of the CISO. You will be responsible for the day-to-day operation of the GRC program translating cybersecurity frameworks, regulatory obligations, and business risks into practical controls, clear ownership, measurable remediation plans, and decision-ready reporting. This is a high-visibility, cross-functional role working closely with Cybersecurity, Technology, Product, Legal, Privacy, Internal Audit, and business teams across the group, while supporting company Pay cybersecurity compliance activities where required.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Manage and coordinate the group cybersecurity governance, risk, and compliance program under the direction of the CISO, including day-to-day GRC activities, priorities, operating cadence, and continuous improvement initiatives.
- Conduct, coordinate, and track gap assessments against ISO 27001, SOC 2, NCA ECC, SAMA CSF, KSA PDPL, and other applicable cybersecurity, privacy, regulatory, and contractual requirements.
- Translate regulatory and framework requirements into practical controls, implementation actions, accountable owners, target dates, and measurable evidence requirements.
- Maintain the cybersecurity policy framework, including policies, standards, procedures, control owners, supporting evidence, review cycles, approved exceptions, and related governance records.
- Own and maintain the cybersecurity risk register, facilitate risk assessments, and drive follow-up on treatment plans, risk acceptance, and overdue actions with business and technology owners.
- Monitor control implementation and remediation progress, challenge weak or incomplete responses, and escalate material risks, recurring gaps, and overdue actions when necessary.
- Coordinate internal audits, external audits, customer cybersecurity due diligence, certification activities, and readiness assessments, ensuring requests and evidence are handled consistently and efficiently.
- Support company cybersecurity compliance activities where required, including control mapping, evidence coordination, remediation tracking, audit support, and management reporting.
- Prepare cybersecurity GRC dashboards, KPIs, KRIs, risk summaries, compliance status reports, and materials for management and cybersecurity governance committees.
- Partner with control owners across Technology, Product, Operations, HR, Legal, Privacy, Procurement, and other functions to embed cybersecurity requirements into business processes and initiatives.
- Maintain a clear compliance calendar and ensure recurring assessments, reviews, evidence collection, policy updates, risk reviews, and audit commitments are completed within agreed timelines.
- Improve the efficiency and quality of the GRC program through standardized templates, control libraries, automation, tooling, and stronger evidence-management practices.
Requirements
- 10+ years of professional experience in cybersecurity governance, risk, compliance, audit, or a closely related field, with demonstrated experience managing enterprise GRC activities and working with senior cybersecurity leadership.
- Strong hands-on knowledge of ISO 27001 and SOC 2, with practical experience conducting gap assessments, mapping controls, collecting evidence, and driving remediation to closure.
- Good working knowledge of Saudi cybersecurity and privacy requirements, particularly NCA ECC and KSA PDPL, with the ability to interpret requirements and translate them into actionable controls.
- Demonstrated experience owning or managing cybersecurity risk registers, risk assessments, treatment plans, risk acceptance, exceptions, and management escalation.
- Experience maintaining cybersecurity policies, standards, procedures, control libraries, control ownership, evidence repositories, and compliance documentation.
- Proven ability to coordinate internal and external audits, manage evidence requests, respond to customer security assessments, and support certification or assurance readiness.
- Strong analytical skills and the ability to turn complex risk and compliance information into clear dashboards, executive summaries, and decision-ready committee reporting.
- Stakeholder management skills, with the confidence to challenge control owners constructively, drive accountability, and follow actions through to completion.
- Strong written and verbal communication in English, including the ability to write clear policies, risk statements, assessment findings, remediation actions, and management reports.
- Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, or a related discipline, or equivalent relevant professional experience.
Nice to Have
- Experience working in FinTech, payments, SaaS, or another regulated and technology-driven environment.
- Experience with SAMA cybersecurity requirements or supporting cybersecurity compliance activities for a regulated payment or financial-services entity.
- Professional certifications such as ISO 27001 Lead Implementer / Lead Auditor, CISM, CRISC, CISA, CISSP, or equivalent.
- Experience with PCI DSS, third-party cybersecurity risk management, privacy compliance, or other regional and international security frameworks.
- Hands-on experience with GRC platforms, evidence automation, compliance tooling, or building structured control and risk reporting workflows.
- Experience operating across multiple business entities, countries, or regulatory environments.
- Arabic language skills for engaging with stakeholders, regulators, and documentation.
Work Conditions
We offer highly competitive compensation packages, including bonuses and the potential for shares. We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment. Join a talented team of over 30 nationalities working in 14 countries, and gain valuable experience in an exciting industry. We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.