COGNNA

    GRC Expert

    COGNNA
    Posted 11/25/2025Senior Level
    Full-time
    Technology
    GRC
    ISO 27001
    SOC 2
    Risk Management
    Identity and Access Management

    ⭐ Join thousands of remote professionals with full access • From $4/week

    Job Description

    We are seeking a GRC Expert with 4+ years of hands-on experience to support the operation of our GRC department. This role requires a strong background in international certification frameworks (ISO 27001, SOC 2), comprehensive Risk Management experience, and specific expertise in Identity and Access Management (IAM) governance. You will be instrumental in leveraging our automated compliance platform (Vanta) to streamline evidence collection, manage audits, and ensure continuous compliance. Compliance & Certification Management Lead the preparation and execution of external audits for ISO 27001 and SOC 2 (Type 1 & 2) certifications. Manage compliance with local Saudi regulations, specifically NCA ECC and SAMA cybersecurity frameworks. Utilize the Vanta platform to map internal controls to regulatory requirements (Custom Frameworks) and automate evidence collection. Monitor compliance posture daily, ensuring all automated tests in Vanta are passing and remediating gaps promptly. Identity & Access Management (IAM) Governance Oversee the IAM lifecycle from a governance perspective, ensuring "Least Privilege" and "Need-to-Know" principles are enforced. Manage and execute Quarterly Access Reviews (User Access Reviews) campaigns within Vanta. Monitor Identity Provider (IdP) integrations (e.g., Okta, Azure AD, Google Workspace) to ensure 100% MFA adoption and timely offboarding of terminated users. Review and approve privileged access requests and ensure proper documentation of business needs. Risk Management Maintain and update the organizational Risk Register. Conduct periodic risk assessments, identifying threats and vulnerabilities, and tracking risk treatment plans to closure. Perform Third-Party Risk Management (TPRM) assessments for new and existing vendors. Policy & Audit Operations Review and update information security policies and procedures annually or as needed. Coordinate internal audits and pre-assessments to ensure readiness for external certification bodies. Assist in responding to client security questionnaires and maintaining the Vanta Trust Center. Minimum of 4 years of dedicated experience in GRC, Information Security, or IT Audit. Deep understanding of ISO 27001 and SOC 2 controls. Familiarity with NCA ECC and SAMA regulations. Experience with automated GRC platforms. Solid understanding of IAM concepts (RBAC, SSO, MFA, PAM). Proficiency in risk assessment methodologies (e.g., ISO 27005, NIST SP 800-30). Certifications Holding at least one relevant certification is preferred (e.g., CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor). Soft Skills Excellent communication skills in English (Arabic is a strong plus). Ability to work independently and manage multiple audit timelines simultaneously. Strong analytical and problem-solving skills. 💰 Competitive Package – Salary + equity options + performance incentives 🧘 Flexible & Remote – Work from anywhere with an outcomes-first culture 🤝 Team of Experts – Work with designers, engineers, and security pros solving real-world problems 🚀 Growth-Focused – Your ideas ship, your voice counts, your growth matters 🌍 Global Impact – Build products that protect critical systems and data

    💼 Want More Jobs Like This?

    Get similar opportunities delivered to your inbox. Free, no account needed!

    Similar Jobs You Might Like

    Technical Account Manager

    Fortive
    Not specifiedabout 5 hours ago
    Full-time
    Technical Account Management
    Customer Success
    Problem Solving
    Communication
    Technical Support

    IT Project Manager (REMOTE)

    NTT DATA
    Not specifiedabout 5 hours ago
    Full-time
    Project Management
    Stakeholder Collaboration
    Jira
    Confluence
    MS Office

    Senior Solutions Consultant

    PTC
    Not specifiedabout 5 hours ago
    Full-time
    Solution Engineering
    Field Service
    CRM
    Cloud Computing
    Technical Architecture

    Data Scientist

    MyShell
    Not specifiedabout 5 hours ago
    Full-time
    Data Architecture
    Data Infrastructure
    Experimentation Methodology
    SQL
    Python

    Want to see all 29,843 jobs?

    You're currently viewing 1 out of 29,843 available remote opportunities

    🔒 29,842 more jobs are waiting for you

    Unlock All Jobs

    Access every remote opportunity

    Advanced Filters

    Find your perfect match faster

    Daily Updates

    New opportunities every day

    Save & Alerts

    Never miss an opportunity

    Weekly
    $4
    Perfect for quick searches
    POPULAR
    Monthly
    $12
    Best for active job seekers
    Yearly
    $48
    Save 67% • Best value
    Unlock All 29843 Jobs

    Join thousands of remote workers who found their dream job

    Frequently Asked Questions

    What's included in premium access?

    Premium members get unlimited access to all remote job listings, advanced search filters, job alerts, and the ability to save favorite jobs.

    Can I cancel anytime?

    Yes! You can cancel your subscription at any time from your account settings. You'll continue to have access until the end of your billing period.

    Do you offer refunds?

    We offer a 7-day money-back guarantee on all plans. If you're not satisfied, contact us within 7 days for a full refund.

    Is my payment secure?

    Absolutely! We use Stripe for payment processing, which is trusted by millions of businesses worldwide. We never store your payment information.