Managed.sa is seeking a motivated GRC Specialist to support a cybersecurity project based in Jeddah.
The ideal candidate will have practical experience in Governance, Risk, and Compliance, with a strong interest in cybersecurity risk management. This role requires working closely with business and technical stakeholders to assess risks, maintain compliance documentation, and support the implementation of cybersecurity controls.
Key Responsibilities- Conduct cybersecurity risk assessments and document identified risks.
- Maintain risk registers, treatment plans, and follow-up actions.
- Support the development and review of cybersecurity policies, procedures, and standards.
- Assess compliance with applicable cybersecurity frameworks and regulatory requirements.
- Identify control gaps and recommend appropriate remediation actions.
- Collect, organize, and review compliance evidence.
- Prepare risk and compliance reports for management and project stakeholders.
- Monitor remediation activities and follow up with relevant teams.
- Support internal and external cybersecurity audits and assessments.
- Coordinate with business, IT, cybersecurity, and project stakeholders.
Requirements
- Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field.
- Approximately 1.5–3 years of relevant experience in cybersecurity GRC.
- Practical experience in cybersecurity risk assessment and risk management.
- Familiarity with cybersecurity frameworks and standards such as:
- NCA ECC
- ISO 27001
- ISO 31000
- NIST Cybersecurity Framework
- Strong documentation, reporting, and stakeholder communication skills.
- Ability to work independently and follow up on multiple risk and compliance activities.
- Professional certifications in GRC, cybersecurity, or risk management are preferred.
- Availability to work full-time on-site in Jeddah.
- Candidates who can join within a short timeframe will be prioritized.
Skills Required
- Bachelor's degree in Cybersecurity, Information Security, IT, Computer Science, or related field
- 1.5 - 3 years of relevant experience in cybersecurity GRC
- Practical experience in cybersecurity risk assessment and risk management
- Familiarity with NCA ECC, ISO 27001, ISO 31000, and NIST Cybersecurity Framework
- Strong documentation, reporting, and stakeholder communication skills
- Ability to work independently and manage multiple risk and compliance activities
- Professional certifications in GRC, cybersecurity, or risk management
- Availability to work full-time on-site in Jeddah
- Ability to join within a short timeframe
What We Do
Managed Services Company is a startup specializes in providing bespoke services in the field of Cyber Security. These services range from identifying threats and vulnerabilities to planning, designing and implementing the relevant technological, organizational and risk-based countermeasures. We supply vendor-independent security services through our consultants and a wide network of partnerships. It can therefore provide in-depth expertise in the most widely used security technologies on the market and select the most suitable solution for any given case. In addition, Managed Services company is a managed service provider specializing in cyber threat intelligence, brand protection solutions, and security-management for complex systems. Our portfolio includes security assessment, real-time management and monitoring of security systems. Managed security also has expertise in advanced technologies like Blockchain, Internet of Things, and Smart Cities. We help our customer to secure those technologies by developing the right strategies and manage their security.







