Cybersecurity GRC Specialist at Tibah Airports Operation Co.
Medina, Medina Province, Saudi Arabia -
Full Time


Start Date

Immediate

Expiry Date

17 Oct, 26

Salary

0.0

Posted On

19 Jul, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Cybersecurity GRC, Risk Assessment, Compliance Management, IT/OT Security, Policy Development, ISO 27001, NIST, CIS, Incident Management, Audit Support, Program Management, Regulatory Compliance

Industry

Airlines and Aviation

Description
Tibah Airports Operation Co. is a leading aviation management company responsible for the operation of Prince Mohammad Bin Abdulaziz International Airport in Madinah, Saudi Arabia. Committed to excellence and operational integrity, Tibah places strong emphasis on risk management and regulatory compliance to maintain safe and efficient airport operations. We are seeking a highly skilled Risk & Compliance Senior Specialist to join our team and drive the identification, assessment, and mitigation of risks while ensuring compliance with all relevant laws, regulations, and internal policies. This role plays a critical part in safeguarding the organization's reputation and operational continuity within a complex and regulated aviation environment. The successful candidate will collaborate with multiple departments to embed a culture of compliance and risk awareness throughout the organization. Job Purpose The Cybersecurity GRC Specialist is responsible for supporting the organization’s cybersecurity governance, risk management, and compliance (GRC) activities. The role ensures that cybersecurity strategies, policies, standards, and controls are effectively implemented, monitored, and aligned with regulatory, operational, and business requirements, including IT and OT/ICS environments. Responsibilities Manage and oversee the implementation of cybersecurity strategies, policies, standards, and procedures across the organization. Conduct cybersecurity risk assessments to identify threats, vulnerabilities, and risks across IT and OT/ICS environments. Develop, track, and monitor cybersecurity risk treatment and mitigation plans, ensuring timely remediation of identified risks. Ensure IT activities, processes, and procedures comply with approved cybersecurity policies, standards, and regulatory requirements. Identify, document, review, and periodically update cybersecurity policies and procedures, including those related to OT/ICS infrastructure. Support cybersecurity compliance with applicable laws, regulations, standards, and frameworks. Support cybersecurity functions in integrating security requirements into new and changed systems, services, and projects. Provide GRC advisory support to IT, OT, and business stakeholders to ensure secure and compliant operations. Prepare periodic cybersecurity compliance and risk status reports and present updates to the Cybersecurity Manager. Monitor the overall cybersecurity compliance posture and recommend improvements where gaps are identified. Implement and support cybersecurity training and awareness programs to promote a strong security culture. Support internal and external cybersecurity audits, assessments, and reviews. Stay informed about emerging cybersecurity risks, threats, and regulatory changes relevant to airport and critical infrastructure environments. Perform other related cybersecurity GRC duties as assigned. Education requirements: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field. Certification Requirements: Certified in Risk and Information Systems Control (CRISC). Experience: Minimum of 3 years of overall cybersecurity-related experience. 1–2 years of hands-on experience in Cybersecurity GRC roles. Experience in regulated environments, critical infrastructure, or airport operations is an advantage. Languages: Fluent in Arabic & English (required). Technical Skills: Strong knowledge of cybersecurity domains and best practices. Excellent knowledge of Governance, Risk, and Compliance (GRC) frameworks and program management. Good understanding of cybersecurity incident management practices. Familiarity with cybersecurity standards and frameworks (e.g., ISO 27001, NIST, CIS). Understanding of IT and OT/ICS security concepts.
Responsibilities
The specialist will manage cybersecurity governance, risk, and compliance activities across IT and OT/ICS environments. This includes conducting risk assessments, developing security policies, and ensuring alignment with regulatory requirements.
Loading...