Skip to content

Open nowPosted 39 days ago

Global Cybersecurity GRC Manager

Workable (global search)108,016 open roles

Where
Riyadh, Riyadh Province, Saudi Arabia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGlobal Cybersecurity GRC ManagerWorkable (global search) · Riyadh, Riyadh Province, Saudi Arabia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 39 days ago

Workable (global search) median: 7 days open

The posting

Who Are We❓

We Are Foodics! a leading restaurant management ecosystem and payment tech provider. Founded in 2014 with headquarters in Riyadh and offices across 5 countries, including UAE, Egypt, Jordan and Kuwait. We are currently serving customers and partners in over 35 different countries worldwide. Our innovative products have successfully processed over 6 billion (yes, billion with a B) orders so far! making Foodics one of the most rapidly evolving SaaS companies to ever emerge from the MENA region. Also, Foodics has achieved three rounds of funding, with the latest raising $170 million in the largest SaaS funding round in MENA, boosting its innovation capabilities to better serve business owners.

The Job in a Nutshell💡

We are looking for a Global Cybersecurity GRC Manager to manage and coordinate cybersecurity governance, risk, and compliance activities across the Foodics Group under the direction of the CISO. You will be responsible for the day-to-day operation of the GRC program translating cybersecurity frameworks, regulatory obligations, and business risks into practical controls, clear ownership, measurable remediation plans, and decision-ready reporting. This is a high-visibility, cross-functional role working closely with Cybersecurity, Technology, Product, Legal, Privacy, Internal Audit, and business teams across the group, while supporting Foodics Pay cybersecurity compliance activities where required.

What you will do💡

  • Manage and coordinate the group cybersecurity governance, risk, and compliance program under the direction of the CISO, including day-to-day GRC activities, priorities, operating cadence, and continuous improvement initiatives.
  • Conduct, coordinate, and track gap assessments against ISO 27001, SOC 2, NCA ECC, SAMA CSF, KSA PDPL, and other applicable cybersecurity, privacy, regulatory, and contractual requirements.
  • Translate regulatory and framework requirements into practical controls, implementation actions, accountable owners, target dates, and measurable evidence requirements.
  • Maintain the cybersecurity policy framework, including policies, standards, procedures, control owners, supporting evidence, review cycles, approved exceptions, and related governance records.
  • Own and maintain the cybersecurity risk register, facilitate risk assessments, and drive follow-up on treatment plans, risk acceptance, and overdue actions with business and technology owners.
  • Monitor control implementation and remediation progress, challenge weak or incomplete responses, and escalate material risks, recurring gaps, and overdue actions when necessary.
  • Coordinate internal audits, external audits, customer cybersecurity due diligence, certification activities, and readiness assessments, ensuring requests and evidence are handled consistently and efficiently.
  • Support Foodics cybersecurity compliance activities where required, including control mapping, evidence coordination, remediation tracking, audit support, and management reporting.
  • Prepare cybersecurity GRC dashboards, KPIs, KRIs, risk summaries, compliance status reports, and materials for management and cybersecurity governance committees.
  • Partner with control owners across Technology, Product, Operations, HR, Legal, Privacy, Procurement, and other functions to embed cybersecurity requirements into business processes and initiatives.
  • Maintain a clear compliance calendar and ensure recurring assessments, reviews, evidence collection, policy updates, risk reviews, and audit commitments are completed within agreed timelines.
  • Improve the efficiency and quality of the GRC program through standardized templates, control libraries, automation, tooling, and stronger evidence-management practices.

What Are We Looking For❓

Required

  • 10+ years of professional experience in cybersecurity governance, risk, compliance, audit, or a closely related field, with demonstrated experience managing enterprise GRC activities and working with senior cybersecurity leadership.
  • Strong hands-on knowledge of ISO 27001 and SOC 2, with practical experience conducting gap assessments, mapping controls, collecting evidence, and driving remediation to closure.
  • Good working knowledge of Saudi cybersecurity and privacy requirements, particularly NCA ECC and KSA PDPL, with the ability to interpret requirements and translate them into actionable controls.
  • Demonstrated experience owning or managing cybersecurity risk registers, risk assessments, treatment plans, risk acceptance, exceptions, and management escalation.
  • Experience maintaining cybersecurity policies, standards, procedures, control libraries, control ownership, evidence repositories, and compliance documentation.
  • Proven ability to coordinate internal and external audits, manage evidence requests, respond to customer security assessments, and support certification or assurance readiness.
  • Strong analytical skills and the ability to turn complex risk and compliance information into clear dashboards, executive summaries, and decision-ready committee reporting.
  • Stakeholder management skills, with the confidence to challenge control owners constructively, drive accountability, and follow actions through to completion.
  • Strong written and verbal communication in English, including the ability to write clear policies, risk statements, assessment findings, remediation actions, and management reports.
  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, Risk Management, or a related discipline, or equivalent relevant professional experience.

Nice to have

  • Experience working in FinTech, payments, SaaS, or another regulated and technology-driven environment.
  • Experience with SAMA cybersecurity requirements or supporting cybersecurity compliance activities for a regulated payment or financial-services entity.
  • Professional certifications such as ISO 27001 Lead Implementer / Lead Auditor, CISM, CRISC, CISA, CISSP, or equivalent.
  • Experience with PCI DSS, third-party cybersecurity risk management, privacy compliance, or other regional and international security frameworks.
  • Hands-on experience with GRC platforms, evidence automation, compliance tooling, or building structured control and risk reporting workflows.
  • Experience operating across multiple business entities, countries, or regulatory environments.
  • Arabic language skills for engaging with stakeholders, regulators, and documentation.

What We Offer You❗

We believe you will love working at Foodics!

  • We offer highly competitive compensation packages, including bonuses and the potential for shares.
  • We prioritize personal development and offer regular training and an annual learning stipend to tackle new challenges and grow your career in a hyper-growth environment.
  • Join a talented team of over 30 nationalities working in 14 countries, and gain valuable experience in an exciting industry.
  • We offer autonomy, mentoring, and challenging goals that create incredible opportunities for both you and the company.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.