Gentis
Gentis
Home

JobsMissionsMediaUse cases
You can reach us anytime via
hello@gentis.com

Vacancies

Find your dream job

Security Solution Analyst - GRC Cybersecurity

30/10/2024
PermanentSaudi ArabiaOn site17000 SR21000 SR
Copied to clipboard
Job description

A leading organization in Saudi Arabia is seeking a Cybersecurity Compliance Officer to join their GRC team. The role focuses on developing and maintaining security governance frameworks, policies, and procedures to ensure alignment with regulatory requirements. The candidate will drive compliance with national cybersecurity regulations, data protection laws, and international security standards.


Key responsibilities include monitoring regulatory compliance, conducting internal security assessments, managing GRC technology platforms, and coordinating external audit engagements. The position requires regular reporting to GRC leadership and supporting organizational certification initiatives.


The ideal candidate will have experience in implementing and maintaining comprehensive security compliance programs while ensuring adherence to industry and regulatory requirements.


Detailed Responsibilities:

  • Develop and maintain comprehensive cybersecurity governance frameworks, policies, and procedures ensuring alignment with regulatory requirements, including NCA controls.
  • Drive compliance with key security standards and regulations including PDPL, ISO 27001, and other applicable frameworks. Monitor and implement emerging requirements.
  • Perform technical security reviews of system configurations, network architecture, and control implementations to validate compliance and security best practices.
  • Lead internal security assessments and compliance reviews to identify and remediate control gaps.
  • Implement and administer GRC automation platforms to enhance compliance monitoring efficiency and reporting capabilities.
  • Design and oversee control attestation procedures, working with control owners to validate and document control effectiveness.
  • Develop and execute third-party security assessment program to evaluate and monitor vendor security practices.
  • Generate regular security status reports for GRC management. Effectively communicate security risks, issues and recommendations to key stakeholders.
  • Manage external audit engagements and certification processes to ensure successful outcomes and continued compliance.
Profile description

Key Competencies:

  • Information Security Governance: Advanced knowledge of security frameworks, policies, and strategic integration of security with business operations. Strong understanding of cyber resilience principles.
  • Regulatory & Standards Expertise: Comprehensive understanding of data protection laws, international security standards (ISO), and industry regulations. Ability to interpret and apply evolving requirements.
  • Technical Security Knowledge: Proficiency in assessing system security configurations, network architecture, and control implementations. Deep understanding of security best practices.
  • Security Assessment: Expert capability in conducting security assessments and compliance reviews. Strong analytical skills in control effectiveness evaluation.
  • GRC Technology: Advanced knowledge of GRC platforms and automation solutions. Expertise in optimizing compliance monitoring and reporting processes.
  • Control Framework: Deep understanding of control validation procedures and attestation processes. Knowledge of control documentation best practices.
  • Third-Party Security: Expert knowledge of vendor security assessment methodologies and supply chain risk management principles.
  • Strategic Communication: Strong ability to articulate complex security concepts to various stakeholders. Excellence in security status reporting and presentation.
  • Audit Management: In-depth knowledge of external audit and certification processes. Strong understanding of audit evidence requirements and remediation approaches.
  • Policy Architecture: Expert understanding of control frameworks and their relationship to organizational policies. Proficiency in mapping security requirements to operational controls.


Core Responsibilities:

  • Information Security Governance: Develop and oversee security frameworks, policies, and procedures aligned with business objectives. Integrate security strategy with operations to maintain business continuity and cyber resilience.
  • Regulatory & Standards Management: Ensure adherence to data protection laws, international security standards (ISO), and industry regulations. Monitor evolving requirements and update security practices accordingly.
  • Technical Security Oversight: Assess and validate system security configurations, network architecture, and control implementations against security requirements and industry best practices.
  • Security Assurance: Lead internal security assessments and compliance reviews. Evaluate control effectiveness and drive continuous improvement initiatives.
  • Technology & Process Optimization: Implement and manage GRC platforms and automation solutions to enhance compliance monitoring and reporting efficiency.
  • Control Management: Design and maintain control validation procedures, ensuring proper documentation and attestation from control owners.
  • Third-Party Risk Management: Develop and execute vendor security assessment programs. Evaluate and monitor external partner security postures to manage supply chain risks.
  • Stakeholder Management: Deliver regular status updates to GRC leadership on security posture and program effectiveness. Drive clear communication channels with key stakeholders.
  • Audit Coordination: Support external audit engagements and certification processes. Partner with auditors and internal teams to facilitate successful outcomes.
  • Policy Framework Administration: Maintain unified control framework mapping security requirements to organizational policies. Establish clear relationships between policies, standards, and operational controls.


Education & Professional Certifications:


· Advanced degree in Computing/Technology field (Bachelor's/Master's in Computer Science or related)

· Governance, Risk & Compliance certification (ISC2 GRC)

· CISSP (Certified Information Security Professional)

· CISA (Certified Information Systems Auditor)

· Security Controls Framework certification (SANS SEC566)

· OSCP (Offensive Security Certified Professional)

Copied to clipboard

Similar jobs

Engineering
02/07/2025

Project Manager – High & Medium Voltage

Day-to-day responsibilities:Manage multiple high and medium voltage projects valued between €500,000 and €10 million, under the guidance of a senior project manager.Oversee projects from the pricing phase—including quotation requests and contract signing—through successful completion and delivery.Coordinate and supervise execution, ensuring safety, quality, financial targets, and timely delivery are met.Prepare project offers, negotiate with clients, suppliers, and subcontractors, and ensure effective contract management.Generate regular financial progress reports for management, identifying risks and opportunities.Lead and guide teams of supervisors and technicians, fostering strong teamwork in daily tasks and project challenges.Collaborate closely with engineering teams to develop appropriate technical concepts for each project.Organize planning meetings with project managers and supervisors to optimize resource deployment.Scope and objectives:Take full ownership of assigned projects within set budgets and deadlines, reporting to senior management.Focus on continual improvement in project control, contract management, and document preparation.Emphasize the use of Microsoft Office 365 and Microsoft Teams for planning, communication, and documentation.Apply advanced risk assessment methods to maintain high project standards.Ensure effective people management and motivational leadership within project teams.Languages required: Excellent Dutch; good French and English.

PermanentBelgiumOn site
Engineering
30/06/2025

Project Manager Medium Voltage

As a Project Manager specializing in Medium Voltage, you will reinforce our dynamic Electrification & Automation team. Your main responsibility is the end-to-end management of medium voltage projects, ensuring technical and operational excellence at each stage.Analyze technical project specifications to understand customer requirements and ensure technical alignment.Verify and clarify solutions by directly interacting with clients through meetings to address technical questions and confirm expectations.Oversee engineering launch and management, guiding technical teams from concept through execution.Configure electrical boards using specialized configuration tools to meet project specifications.Initiate orders to manufacture and monitor production processes to ensure timely and accurate delivery.Coordinate project planning with various stakeholders, aligning schedules and resources for seamless execution.Maintain consistent communication with clients, providing technical updates throughout the project lifecycle.Manage resources such as technicians and subcontractors, ensuring everyone works towards project goals.Participate in Factory Acceptance Tests (FAT) to verify system conformity before delivery.Organize on-site deliveries and Site Acceptance Test (SAT) activities, ensuring project handover meets standards.Monitor financial and quality KPIs, tracking progress and cost-effectiveness against set benchmarks.Enforce project safety standards to uphold and cultivate a safety-first culture across all activities.Provide regular project progress updates to both clients and internal teams, ensuring transparency and alignment.The scope of this role includes analyzing medium voltage systems, hands-on project planning, technical and economic solution optimization, and stringent adherence to industry regulations. The successful project manager will be required to work interchangeably in French, Dutch, and English, facilitating communication with clients nationwide and internationally.Qualification requirements include a Bachelor's or Master's degree in Electrical Engineering (or related field), solid experience in project management for medium voltage systems, and a strong command of medium voltage regulations and technical standards. Proficiency in MS Office tools and knowledge of German are advantageous.

PermanentBelgiumOn site
ICT
30/06/2025

Cybersecurity Engineer – Railway Systems (Hybrid, Charleroi)

Location: Charleroi · Hybrid, with 3 days on-site per week · Limited travel (<10%), mainly within EuropePosition Overview: This role focuses on cybersecurity risk assessment and secure architecture design specifically for railway systems. The responsibilities are strategic and analytical — not operational or hands-on.Conduct risk analyses for railway subsystems and components.Define secure system architectures and establish security requirements across critical areas.Identify protection points and recommend robust risk mitigation strategies.Ensure compliance with relevant cybersecurity standards and regulations (IEC 62443, ISO 27001, NIS2).Work collaboratively with systems, software, and safety teams to align cybersecurity efforts.Validate cybersecurity implementations through structured reviews, analysis, and testing.Support the development of cybersecurity validation strategies and confirm system resilience.Coordinate with internal stakeholders, clients, and suppliers as part of multidisciplinary project teams.Prepare comprehensive documentation, including security cases, compliance reports, and risk management plans.Essential Requirements:Master’s degree in cybersecurity, engineering, computer science, or related field.Strong knowledge of cybersecurity principles, risk assessment, and secure system design.Understanding of security systems and regulatory compliance for safety-critical environments.Proficient in technical documentation and regulatory reporting.Fluent in English; knowledge of French, German, or Italian is advantageous.Valuable Experience:Familiarity with railway signaling or other complex safety-critical infrastructure.Experience with ISO 27001 and IEC standards in transportation or industrial domains.Insight into security governance, validation, and compliance processes for large-scale systems.

Fixed termBelgiumHybrid

The perfect match is only one step away.

Send us your CV directly and we will put you in touch with one of our specialised recruiter who will guide you in the search of your dream job!

Phone number
Phone
Candidates

Testimonials

Join our vibrant community of professionals and discover your potential to make a difference in the world.

Stay up to date with our latest news!