Job Title :
Cybersecurity GRC Analyst
Employment Type : Full-time
Company Brief :
Circlys is a pioneering fintech company revolutionizing traditional monthly financial committees (ROSCA or Jameya), or as we call them Circles. Our innovative, authorized, and safe solution empowers individuals to achieve their financial goals with ease and peace of mind. With a robust user base of over 2 million and more than 8 billion SAR in savings, Circlys is a leader in its field. Our success is driven by a passionate and talented team of professionals who are committed to fostering financial well‑being in our community.
Job Summary :
The Cybersecurity GRC (Governance, Risk, and Compliance) Analyst is responsible for developing, implementing, and maintaining the company’s cybersecurity compliance framework. This role ensures adherence to regulatory requirements (e.g., SAMA CSF, PDPL, NCA ECC, ISO 27001) and alignment with Circlys’s internal cybersecurity policies and standards. The job also entails coordinating audits, risk assessments, and control testing activities to support a strong governance posture.
Responsibilities
Develop and maintain cybersecurity policies, procedures, and standards in alignment with local regulations and best practices
Conduct periodic risk assessments and maintain the cybersecurity risk register
Manage compliance with SAMA CSF, PDPL, and other regulatory frameworks
Coordinate internal and external cybersecurity audits and track remediation progress
Monitor and report on cybersecurity control effectiveness and compliance KPIs
Collaborate with IT, Legal, and Ops to ensure governance and data protection requirements are implemented
Support awareness and training programs related to cybersecurity compliance
Prepare evidence and documentation for regulatory submissions and assessments
Requirements
Bachelor’s degree in Cybersecurity, Information Technology, or a related field
Preferred certifications : ISO 27001 Lead Implementer, CRISC, or CISA
2–4 years of experience in cybersecurity compliance, risk management, or audit
Strong understanding of cybersecurity governance, risk management, and compliance frameworks
Knowledge of regulatory standards (SAMA CSF, NCA ECC, PDPL, ISO 27001)
Experience with GRC tools and compliance tracking systems
Analytical mindset with strong documentation and reporting skills
Seniority level Associate
Job function Information Technology
Industries Financial Services and Banking
#J-18808-Ljbffr
Security Specialist • Riyadh, Saudi Arabia