About the Role
The Head of Cyber Governance, Risk and Compliance (GRC) is a key leadership position within the IT GRC team, serving as the central coordination point for all internal and external audits, as well as regulatory engagements related to the first and first-and-a-half lines of defense (1LOD/1.5LOD). This role is integral to managing general risk and control activities as described within the enterprise risk management framework.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Principal Accountabilities
- Govern the 1LOD control environment, ensuring compliance with 2LOD policies, and provide independent reporting on 1LOD risk posture and control performance.
- Execute the 1LOD GRC mandate to ensure that the first line meets obligations and operates controls correctly, focusing on control performance and operational readiness.
- Define and maintain 1LOD Security Standards, Baselines, and Control Procedures aligned with 2LOD Policies and Control Objectives.
- Manage standards lifecycle, coordinate compliance/audit, and facilitate the exception process within 1LOD; implement and monitor adherence to policies and frameworks set by 2LOD.
- Coordinate and execute the 1LOD Risk and Control Self-Assessments (RCSAs) by leading the risk assessment process, control validation, conducting 1.5LOD thematic reviews, and delivering executive reporting.
- Monitor and report operational performance and compliance status (KPIs) of the 1LOD.
- Conduct quality assurance (QA) checks and internal control reviews (1.5LOD audits) on 1LOD activities.
- Maintain the 1LOD Cyber Risk Register and track the status of risk treatment plans.
- Manage the Control Library & Attestation process and execute the 1.5LOD assurance plan, including internal security audits (1.5LOD Control Reviews) and developing Continuous Controls Monitoring (CCM).
- Facilitate submission of exception requests initiated by 1LOD and track their lifecycle.
- Provide Regulatory Intelligence & Advisory services, interpreting regulatory changes and advising 1LOD on compliance readiness.
- Aggregate KPIs and risk data to prepare independent 1.5LOD executive risk and control reports, tracking Key Performance Indicators (KPIs).
Personnel Specifications
- 10+ years of experience in IT/cyber GRC, IT audit, or security management within financial services.
- Minimum of 4 years in leading GRC functions.
- Experience with GRC platforms.
- Familiarity with enterprise risk management and control frameworks, and core processes (e.g., RCSAs).
- Strong understanding of Three Lines of Defence and regulatory requirements.
- Proven track record in driving process improvements related to operational risk management, particularly in cyber, technology, and resilience risk and control.
- Experience in establishing 1.5LOD assurance capabilities.
- Bachelor’s degree in Information Systems, Computer Science, or a related field (Master's preferred).
- CISA, CISM, or CRISC certification is required.
- Knowledge of CBO regulations and banking standards.
- GRC platform certifications are advantageous.