COGNNA Logo

COGNNA

GRC Expert

Reposted 8 Hours Ago
Be an Early Applicant
Remote
4 Locations
Mid level
Remote
4 Locations
Mid level
Looking for a GRC Expert to support compliance management, identity and access governance, and risk management within a GRC department.
The summary above was generated by AI

We are seeking a GRC Expert with 4+ years of hands-on experience to support the operation of our GRC department. This role requires a strong background in international certification frameworks (ISO 27001, SOC 2), comprehensive Risk Management experience, and specific expertise in Identity and Access Management (IAM) governance. You will be instrumental in leveraging our automated compliance platform (Vanta) to streamline evidence collection, manage audits, and ensure continuous compliance.

Compliance & Certification Management
  • Lead the preparation and execution of external audits for ISO 27001 and SOC 2 (Type 1 & 2) certifications.
  • Manage compliance with local Saudi regulations, specifically NCA ECC and SAMA cybersecurity frameworks.
  • Utilize the Vanta platform to map internal controls to regulatory requirements (Custom Frameworks) and automate evidence collection.
  • Monitor compliance posture daily, ensuring all automated tests in Vanta are passing and remediating gaps promptly.
Identity & Access Management (IAM) Governance
  • Oversee the IAM lifecycle from a governance perspective, ensuring "Least Privilege" and "Need-to-Know" principles are enforced.
  • Manage and execute Quarterly Access Reviews (User Access Reviews) campaigns within Vanta.
  • Monitor Identity Provider (IdP) integrations (e.g., Okta, Azure AD, Google Workspace) to ensure 100% MFA adoption and timely offboarding of terminated users.
  • Review and approve privileged access requests and ensure proper documentation of business needs.
Risk Management
  • Maintain and update the organizational Risk Register.
  • Conduct periodic risk assessments, identifying threats and vulnerabilities, and tracking risk treatment plans to closure.
  • Perform Third-Party Risk Management (TPRM) assessments for new and existing vendors.
Policy & Audit Operations
  • Review and update information security policies and procedures annually or as needed.
  • Coordinate internal audits and pre-assessments to ensure readiness for external certification bodies.
  • Assist in responding to client security questionnaires and maintaining the Vanta Trust Center.

Requirements
  • Minimum of 4 years of dedicated experience in GRC, Information Security, or IT Audit.
  • Deep understanding of ISO 27001 and SOC 2 controls.
  • Familiarity with NCA ECC and SAMA regulations.
  • Experience with automated GRC platforms.
  • Solid understanding of IAM concepts (RBAC, SSO, MFA, PAM).
  • Proficiency in risk assessment methodologies (e.g., ISO 27005, NIST SP 800-30).
Certifications
  • Holding at least one relevant certification is preferred (e.g., CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor).
Soft Skills
  • Excellent communication skills in English (Arabic is a strong plus).
  • Ability to work independently and manage multiple audit timelines simultaneously.
  • Strong analytical and problem-solving skills.

Benefits

💰 Competitive Package – Salary + equity options + performance incentives
🧘 Flexible & Remote – Work from anywhere with an outcomes-first culture
🤝 Team of Experts – Work with designers, engineers, and security pros solving real-world problems
🚀 Growth-Focused – Your ideas ship, your voice counts, your growth matters
🌍 Global Impact – Build products that protect critical systems and data

Top Skills

Azure Ad
Google Workspace
Iso 27001
Mfa
Okta
Pam
Rbac
Soc 2
Sso
Vanta

Similar Jobs

Yesterday
Remote or Hybrid
Cairo, EGY
5-5 Annually
Senior level
5-5 Annually
Senior level
Big Data • Cloud • Food • Machine Learning • Software • Database • Analytics
As a Responsible Sourcing Manager, you will lead human rights sourcing strategies, engage with stakeholders, conduct risk assessments, and ensure compliance with regulations across the East region.
Top Skills: AuditsCompliance RequirementsEsg ReportingFmcgRisk Assessment
2 Days Ago
Remote or Hybrid
Cairo, EGY
Mid level
Mid level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
As an HR Shared Services Rep, you will support the employee journey globally, manage HR cases, maintain data integrity, and promote self-service HR processes.
Top Skills: Ai-Powered ToolsHuman Resource Tools And TechnologySmart Recruiters Platform
3 Days Ago
Remote or Hybrid
Cairo, EGY
Entry level
Entry level
Big Data • Cloud • Food • Machine Learning • Software • Database • Analytics
The Scientific & Regulatory Affairs Coordinator will assist in regulatory reviews, scientific research, documentation activities, and collaborate with teams on compliance projects.
Top Skills: Compliance RecordsRegulatory Database

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account