Governance, Risk Management, and Compliance Manager (GRC Manager)
Department : Risk & Compliance / Corporate Governance
Company Type : Publicly Listed – Food Delivery / Q-Commerce / Super-App
The GRC Manager is responsible for establishing and maintaining the organization’s governance, risk management, and compliance framework. The role ensures that the company operates in line with regulatory requirements, stock‑market rules, data privacy laws, and internal policies—while enabling secure and compliant scaling of our food‑delivery and digital commerce operations.
Key Responsibilities
Governance
- Develop, implement, and maintain corporate governance frameworks aligned with stock exchange requirements and board expectations.
- Manage policy lifecycle : creation, review, approval, communication, and enforcement.
- Support Board Committees (Risk Committee, Audit Committee) with dashboards, reports, and follow‑up actions.
- Ensure cross‑department alignment with governance standards (Tech, Operations, Finance, Commercial).
- Lead the Enterprise Risk Management (ERM) program across the company.
- Identify, assess, and monitor operational, financial, cybersecurity, delivery‑operations, and reputational risks.
- Build and maintain the company’s risk register; track mitigation plans with owners.
- Conduct risk assessments for new features, partnerships, restaurants, delivery models, and markets.
- Perform business continuity planning (BCP) and disaster recovery (DR) oversight with Tech & Operations.
- Provide regular reports to C‑level and board committees on key risks and incidents.
Compliance
Ensure compliance with all applicable regulatory and exchange requirements (e.g., CMA, Tadawul, PDPL, cybersecurity standards).Monitor compliance with food‑industry regulations (SFDA), delivery‑driver regulations, e‑commerce laws, consumer protection, and data‑privacy rules.Design and run internal compliance audits; follow up on corrective measures.Oversee vendor compliance : restaurants, last‑mile partners, payment providers, and cloud vendors.Coordinate regulatory inspections and external audit engagements.Manage whistleblowing channels and ethics program.Information Security & Data Privacy (in partnership with IT / Security)
Ensure compliance with data privacy laws (PDPL / GDPR‑equivalent), including customer, courier, and restaurant partner data.Support InfoSec in implementing cybersecurity frameworks (ISO 27001, NCA ECC, PCI‑DSS if applicable).Review security risks for new app features, APIs, integrations, and digital payment services.Oversee data protection impact assessments (DPIAs).Incident & Crisis Management
Lead incident reporting, investigations, and root‑cause analysis.Coordinate with Operations, Tech, and Customer Experience teams during high‑impact service outages, data breaches, or operational disruptions.Maintain crisis‑management playbooks and communication protocols.Training and Awareness
Deliver training to employees, riders, and restaurant partners on governance standards, data privacy, anti‑fraud, cybersecurity, and compliance obligations.Promote a strong culture of risk awareness and ethical behavior.Qualifications & Experience
Bachelor’s degree in Business, Law, IT, Risk Management, or related field.Professional certifications preferred : CRISC, CISA, CISSP, ISO 27001 Lead Implementer / Auditor, CIA, CGEIT, or PMP.5–8+ years of experience in GRC, ideally within tech, e‑commerce, logistics, fintech, or a regulated sector.Experience working in or supporting a publicly listed company is a strong advantage.Familiarity with MENA regulatory frameworks (CMA, PDPL, SFDA, NCA cybersecurity standards).Strong understanding of digital platforms, mobile apps, delivery operations, cloud environments, and data flows.Job Details
Seniority level : Mid‑Senior levelEmployment type : Full‑timeJob function : Finance and SalesIndustries : Advertising Services#J-18808-Ljbffr