
Lucidya
Enterprise Governance, Risk & Compliance (GRC) Manager
- Permanent
- Riyadh, Saudi Arabia
- Experience 5 - 10 yrs
Job expiry date: 02/01/2026
Job overview
Date posted
18/11/2025
Location
Riyadh, Saudi Arabia
Salary
Undisclosed
Compensation
Comprehensive package
Experience
5 - 10 yrs
Seniority
Manager
Qualification
Bachelors degree
Expiration date
02/01/2026
Job description
The role leads the organizationās enterprise-wide governance, risk, and compliance framework, ensuring transparency, accountability, and regulatory alignment across all business units and operational systems. Responsibilities include establishing and maintaining the Enterprise Governance Framework, leading policy governance across departments with version control, ownership, approval workflows, and lifecycle management, and facilitating cross-functional committees such as the Risk Committee and Compliance Steering Group. The position develops and implements a comprehensive risk management framework integrating strategic, operational, financial, and compliance risk domains, maintains the Enterprise Risk Register, leads risk assessments and workshops, and oversees Business Continuity Planning and Crisis Management exercises. Compliance responsibilities include overseeing regulatory adherence to national, regional, and international frameworks such as PDPL, NCA standards, ISO certifications, labor regulations, financial reporting rules, and corporate governance requirements, supervising the Data Protection & Privacy Officer, coordinating internal audits and certification efforts, and maintaining a Regulatory Obligations Register mapping applicable laws and controls. Legal coordination includes liaising with internal and external counsel to operationalize regulatory requirements, reviewing compliance implications of client contracts, MSAs, and DPAs, coordinating responses to client audits and regulatory inquiries, and monitoring regulatory developments relevant to SaaS operations, AI applications, and cross-border hosting. Ethics and internal control responsibilities include overseeing the Code of Conduct, whistleblowing channels, fraud prevention, conflicts of interest, procurement integrity, and due diligence for vendors, partnerships, and acquisitions. The role drives a risk-aware, compliance-first culture, partnering with HR on training programs and ensuring departmental ownership of governance responsibilities. Continuous improvement duties include monitoring emerging regulations, improving governance maturity, enhancing audit readiness, refining control design, and delivering periodic reports to executive leadership and the board on risk posture and compliance performance.
Required skills
Key responsibilities
- Establish and maintain the Enterprise Governance Framework aligning policies, processes, and decision-making with corporate objectives
- Lead policy governance including version control, ownership, approval workflows, and lifecycle management
- Facilitate governance committees such as the Risk Committee and Compliance Steering Group
- Define key governance indicators and performance metrics
- Develop and implement a comprehensive enterprise risk management framework covering strategic, operational, financial, and compliance risks
- Maintain the Enterprise Risk Register and coordinate organization-wide risk identification and mitigation
- Conduct risk assessments and workshops with business units
- Lead Business Continuity Planning and Crisis Management exercises
- Oversee compliance with regulatory frameworks including PDPL, NCA, ISO, labor laws, financial reporting standards, and corporate governance requirements
- Integrate regulatory and contractual compliance obligations into operational workflows
- Supervise the Data Protection & Privacy Officer and ensure privacy governance alignment
- Coordinate internal audits, certifications, compliance monitoring, and remediation efforts
- Maintain the Regulatory Obligations Register mapping laws, standards, and controls
- Act as compliance advisor to department heads to ensure functional policies remain current and compliant
- Coordinate with Legal and external counsel to interpret and operationalize regulatory requirements
- Review client contracts, MSAs, and DPAs for compliance and data protection implications
- Coordinate responses to client audits, regulatory inquiries, and due diligence requests
- Monitor regulatory developments affecting SaaS operations, AI applications, and cross-border hosting
- Develop and oversee the Code of Conduct, whistleblowing mechanisms, and ethics initiatives
- Implement internal controls covering fraud prevention, conflicts of interest, and procurement integrity
- Support due diligence for partnerships, vendors, and acquisitions
- Promote a risk-aware and compliance-first culture across departments
- Partner with HR to deliver governance and compliance training
- Provide periodic governance, risk, and compliance reports to executive management and the board
- Lead continuous improvement efforts in governance, audit readiness, and control design
Experience & skills
- Hold a Bachelorās degree in Business, Law, or a related field
- Bring 4ā6 years of experience in Governance, Risk, and Compliance (GRC)
- Possess experience in auditing and handling corporate incidents
- Demonstrate experience building governance frameworks, policies, and risk management processes
- Have strong knowledge of PDPL and ISO standards such as ISO 27001 and ISO 9001
- Show strong stakeholder management and cross-functional leadership abilities
- Possess experience in creating and delivering compliance training programs
- Be familiar with global regulatory frameworks and business continuity planning
- Exhibit curiosity, an investigative mindset, and strong communication skills
- Preferred qualifications include experience in IPOs or public companies, familiarity with ESG principles, Arabic proficiency, and experience in SaaS or B2B technology environments