Skip to content

Open nowPosted 138 days ago

Director of Governance, Risk, and Compliance

Workable (global search)108,016 open roles

Where
Riyadh, Riyadh Province, Saudi Arabia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector of Governance, Risk, and ComplianceWorkable (global search) · Riyadh, Riyadh Province, Saudi Arabia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 138 days ago

Workable (global search) median: 7 days open

The posting

Do you want to love what you do at work? Do you want to make a difference, an impact, and transform peoples lives? Do you want to work with a team that believes in disrupting the normal, boring, and average?

If yes, then this is the job you are looking for , webook.com is Saudi’s #1 event ticketing and experience booking platform in terms of technology, features, agility, revenue serving some of the largest mega events in the Kingdom surpassing over 2 billion in sales.

Role Overview: The Director of Governance, Risk & Compliance will establish and lead webook.com's GRC function, building the frameworks, processes, and culture needed to manage risk and ensure compliance across our operating markets.

This is a foundational role for the company. The successful candidate will be responsible for designing, implementing, and embedding the governance, risk, compliance, policy, and internal control frameworks needed to support webook.com’s continued growth, international expansion, and transition into a more structured corporate environment.

The role requires someone who is both highly experienced and highly hands-on. The right candidate must be comfortable operating as an individual contributor: drafting policies, building risk registers, preparing board materials, setting up controls, running compliance reviews, and working directly with teams to close gaps. Over time, the Director will build and lead the GRC function as the business scales.

Key Responsibilities:

Governance Framework & Board Support

  • Design and implement webook.com’s enterprise governance framework, including policies, approval authorities, decision-making protocols, committees, reporting cadences, and escalation paths.
  • Support the company’s transition from founder-led/startup-style operations to a more structured governance model without slowing down execution unnecessarily.
  • Establish clear accountability structures across departments, markets, and leadership forums.
  • Develop and maintain a company-wide policy framework and policy library covering key operational, financial, legal, technology, data, people, and regulatory areas.
  • Support board governance requirements by preparing clear, structured reporting on key risks, compliance matters, governance gaps, and mitigation plans.
  • Work with executive leadership to ensure board decisions, actions, and follow-ups are tracked and implemented.
  • Help establish governance routines such as risk committees, compliance reviews, policy approval processes, and management reporting cycles.

Enterprise Risk Management

  • Build and own the company’s Enterprise Risk Management framework from scratch.
  • Develop and maintain the enterprise risk register, including strategic, operational, financial, regulatory, technology, cyber, third-party, reputational, and market-specific risks.
  • Define risk assessment methodologies, scoring criteria, risk ownership, risk appetite, escalation thresholds, and mitigation planning processes.
  • Partner with business leaders to identify, assess, prioritize, and manage risks across functions and geographies.
  • Embed risk management into business planning, international expansion, product launches, vendor selection, major commercial deals, and operational decision-making.
  • Provide regular risk reporting to executive leadership and the Board, including key risk indicators, emerging risks, mitigation progress, and areas requiring attention.
  • Ensure risk management is practical, business-focused, and suitable for a fast-moving growth environment.

Compliance

  • Establish and manage the company’s compliance framework across all operating markets, and future international markets.
  • Identify applicable laws, regulations, licensing requirements, contractual obligations, and internal policies relevant to the business.
  • Monitor regulatory developments and assess their impact on webook.com’s operations, platform, commercial activities, data practices, and international expansion.
  • Lead compliance gap assessments and develop practical remediation plans.
  • Create compliance calendars, checklists, registers, and reporting mechanisms to ensure obligations are tracked and met.
  • Partner with Legal, Finance, People, Product, Engineering, Commercial, and Operations teams to ensure compliance requirements are understood and implemented.
  • Manage relationships with external advisors, regulators, auditors, and consultants where required.
  • Ensure compliance is embedded into everyday operations rather than treated as a separate administrative exercise.

Internal Controls, Policies & Audit Readiness

  • Design and implement practical internal controls across key business areas, including finance, procurement, contracting, approvals, vendor management, data protection, information security governance, and operational processes.
  • Develop clear policy ownership, review cycles, approval workflows, and communication processes.
  • Establish procedures for monitoring control effectiveness and tracking remediation actions.
  • Prepare the company for internal audits, external audits, investor due diligence, regulatory reviews, and board-level governance reviews.
  • Work with Finance, Legal, Operations, and Technology to ensure appropriate documentation, evidence, and control records are maintained.
  • Identify control gaps and work with teams to implement solutions that are pragmatic, scalable, and appropriate for the company’s stage of growth.

Technology, Data & Platform Compliance

  • Oversee data privacy and protection compliance (PDPL, GDPR, and equivalent regulations)
  • Partner with Product and Engineering to ensure platform features meet regulatory requirements
  • Lead information security governance in coordination with the technology team

Team Building & Leadership

  • Build and lead the GRC team from the ground up
  • Act as the internal subject matter expert on all governance, risk, and compliance matters
  • Foster a culture of integrity, accountability, and risk awareness across the organization

Reporting & Executive Engagement

  • Provide regular GRC updates and risk reports to executive leadership
  • Prepare board-level reporting on key risks, compliance posture, and governance health
  • Develop dashboards and metrics to track GRC performance

Requirements

  • 10+ years of experience in governance, risk, compliance, or a related field
  • Demonstrated experience building or significantly scaling a GRC function
  • Strong knowledge of regulatory frameworks relevant to tech platforms, marketplaces, or e-commerce
  • Familiarity with data privacy regulations, including PDPL and GDPR
  • Experience operating across multiple markets, ideally within the MENA region
  • Excellent stakeholder management and executive communication skills
  • Relevant certifications are a plus (e.g. CISA, CRISC, CISM, ICA)
  • Comfortable with ambiguity and able to move fast in a high-growth environment
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.