Overview
GRC Consulting Lead Jobs in Riyadh, Saudi Arabia at EjadTech – إيجاد التقنية
Title: GRC Consulting Lead
Company: EjadTech – إيجاد التقنية
Location: Riyadh, Saudi Arabia
The GRC Consulting Lead is responsible for leading the consulting project from both the strategic and governance perspectives, serving as the primary point of contact with the client. The role ensures that the Governance, Risk, and Compliance (GRC) framework aligns with international standards (ISO 38500 – ISO 20000) and the requirements of the Digital Government Authority (DGA), while guiding the technical team in implementing solutions on the ServiceNow and Archer platforms.
Key Duties and Responsibilities
- Lead the design of an integrated GRC framework for the client and ensure alignment with organizational objectives.
- Manage the project plan, timelines, and deliverables in coordination with stakeholders.
- Provide periodic executive reports to the client’s senior management.
- Identify project risks and critical issues and propose immediate mitigation plans.
- Apply ISO 38500 IT Governance standards at the board and executive level.
- Guide the design of risk management policies in accordance with ISO 31000 and DGA requirements.
- Review compliance audit results and verify the effectiveness of implemented controls.
- Lead awareness workshops and capability-building sessions for client teams.
- Oversee the configuration of GRC / IRM modules in ServiceNow in line with client requirements.
- Review the design of risk registers, service catalogs, and remediation plans in Archer.
- Ensure integration of both platforms with operational processes according to ITIL and ISO 20000 standards.
- Approve delivery and review documentation before submission to the client.
Requirements and Qualifications
Education and Experience:
- Bachelor’s degree in Information Technology, Business Administration, or a related field.
- Minimum of 7 years of experience in GRC or IT Governance.
- At least 3 years of experience leading consulting projects with government entities or large organizations.
Required Professional Certifications:
- CGEIT or CRISC
- CISA or CISSP
- ISO 38500 Foundation or Lead Implementer
- ISO 20000 Lead Auditor / Lead Implementer
- PMP or Prince2/
Technical Competencies:
- Strong expertise in designing GRC frameworks and risk/compliance policies.
- Deep understanding of Digital Government Authority (DGA) and National Cybersecurity Authority (NCA) requirements.
- Hands-on experience with ServiceNow and Archer GRC/IRM modules.
- Familiarity with ISO 27001, ITIL v4, COBIT 2019, and NIST standards.