Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
https://bayt.page.link/v1TUmrkCw1dqRip19
Back to the job results

Cybersecurity GRC Manager

Yesterday 2026/08/17
Full time
500 Employees or more · Accounting
Create a job alert for similar positions
Job alert turned off. You won’t receive updates for this search anymore.

Job description

About the Role:

As a Cybersecurity GRC Manager based in the United Arab Emirates, you will lead the development, implementation, and oversight of our Governance, Risk, and Compliance framework. You will ensure alignment with regional and international standards, drive risk assessment and remediation activities, manage GRC tool deployments, engage with regulatory bodies, and build a strong security culture through leadership and training.


Responsibilities:
  • Develop and maintain the Cybersecurity GRC framework aligned with ISO 27001, NIST CSF, COBIT, NCA ECC, SAMA CSF, and UAE IA Standards
  • Conduct enterprise-wide risk assessments and business impact analyses to identify, evaluate, and prioritize security risks
  • Design, implement, and update information security policies, standards, and procedures
  • Lead the implementation and optimization of GRC tools including ServiceNow GRC, MetricStream, and Archer
  • Monitor compliance with UAE regulatory requirements and engage with local regulatory bodies
  • Coordinate and deliver organization-wide security awareness training programs
  • Develop and track GRC metrics and dashboards to report on program performance
  • Manage, mentor, and develop a high-performing GRC team
  • Collaborate with IT, legal, audit, and business stakeholders to integrate GRC processes into business operations
  • Stay current on emerging cybersecurity regulations, best practices, and industry trends in the UAE

Required Qualifications:
  • 8–12 years of hands-on experience in cybersecurity GRC roles
  • Deep technical knowledge of ISO 27001, NIST CSF, COBIT, NCA ECC, SAMA CSF, and UAE IA Standards
  • Proven experience conducting risk assessments and business impact analyses
  • Strong expertise in developing and implementing information security policies and procedures
  • Hands-on experience implementing and managing ServiceNow GRC, MetricStream, and Archer platforms
  • Demonstrated ability to engage with regulatory bodies and ensure compliance with regional regulations
  • Experience designing and delivering security awareness training programs
  • Proven leadership skills with experience managing and mentoring teams
  • Excellent communication, stakeholder management, and presentation skills

Preferred Qualifications:
  • Certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer
  • Experience with additional GRC platforms or custom tool integrations
  • Advanced degree in Cybersecurity, Information Security, or a related field
  • Familiarity with other compliance frameworks such as PCI DSS or GDPR
  • Prior experience in the financial services or government sector within the UAE

This job post has been translated by AI and may contain minor differences or errors.
You’ve reached the maximum limit of 15 job alerts. To create a new alert, please delete an existing one first.
Job alert created for this search. You’ll receive updates when new jobs match.
Are you sure you want to unapply?

You'll no longer be considered for this role and your application will be removed from the employer's inbox.