GRC Expert (NCA & ISO 27001/9001) – Kingston Stanley – Saudi Arabia
Kingston Stanley invites applications for GRC Expert (NCA & ISO 27001/9001) in Saudi Arabia
Job Title:
GRC Expert (NCA & ISO 27001/9001)
This role aims to empower Governance and Cybersecurity Risk Management to enhance compliance with cybersecurity standards across various controls. The service includes the following:
- Providing support in continuously updating the cybersecurity strategy to align with core cybersecurity controls ECC-1:2018, sensitive system controls CSCC-1:2019, data cybersecurity controls DCC-1:2022, and ISO27001/9001 standards.
- Monitoring and evaluating systems’ compliance with cybersecurity requirements, resilience, and reliability, and conducting periodic reviews to ensure adherence to cybersecurity controls and audit procedures.
- Conducting technical assessments of software applications, systems, or networks and documenting their compliance with cybersecurity requirements.
- Developing policies and procedures for cybersecurity risk management, establishing and updating risk registers, and reviewing these documents to ensure the risk level for each application, system, and network is within acceptable limits.
- Conducting security status audits for networks and systems according to cybersecurity policies, and providing recommendations to address discovered vulnerabilities.
- Identifying and documenting the impact of implementing new systems or new communication interfaces between systems on the current security status of the environment.
- Ensuring that cybersecurity audit operations test all aspects related to the organization’s infrastructure and compliance with policies.
- Ensuring that application, network, and system configurations comply with organizational cybersecurity policies.
- Assessing the effectiveness of policies, standards, or procedures in achieving the organization’s strategy.
- Interpreting and implementing laws, regulations, policies, or procedures as needed.
- Developing policies, procedures, and guidelines for implementing relevant cybersecurity controls.