Solidrange
Website:
solidrange.com
Job details:
Senior GRC Business AnalystJob Title: Senior GRC Business Analyst
Career Level: Senior
Location: Remote
Employment Type: Full-Time
Company Description
Solidrange is a cybersecurity company based in Riyadh, specializing in developing modern platforms to address cybersecurity and enterprise Governance, Risk, and Compliance (GRC) challenges. Our vision is to transform the GRC technology landscape, helping organizations modernize their practices and reduce operational overhead. Our mission centers on reducing human-driven cybersecurity risks, simplifying compliance and risk management, and facilitating seamless business continuity.
About the RoleWe are seeking a capable Senior GRC Business Analyst to help enhance and deliver our Governance, Risk, and Compliance (GRC) platform.
The ideal candidate has a strong academic background in Cybersecurity or Information Security, practical exposure to GRC, audit, risk, or compliance, and the ability to translate regulatory and business needs into clear product requirements. You will work closely with compliance professionals, product, design, development, and QA teams to build scalable GRC capabilities.
Key Responsibilities· Gather, analyze, and document business requirements with clients, compliance officers, risk managers, auditors, and IT/security teams.
· Translate GRC, cybersecurity, audit, and compliance requirements into functional specifications, user stories, workflows, use cases, and acceptance criteria.
· Analyze Saudi Arabian regulatory requirements, including SAMA, NCA, NDMO, CST, CMA, MOF, CBAHI, and other applicable authorities.
· Map international standards—including ISO 27001, ISO 22301, NIST CSF, NIST 800-53, SOC 2, PCI DSS, and similar frameworks—into platform features.
· Define and enhance requirements for GRC modules such as:
o Risk and control management
o Framework and compliance management
o Policy and document management
o Audit, findings, and corrective action management
o Evidence collection and review
o Incident management and business continuity
o Dashboards, reports, notifications, and escalations
· Conduct gap analyses between regulatory obligations, client processes, and existing platform functionality.
· Collaborate with development and QA teams to clarify requirements, validate delivered functionality, and resolve functional queries.
· Support UAT, document defects, coordinate retesting, and ensure requirements are met.
· Contribute to product documentation, implementation guides, training material, and knowledge-base articles.
Qualifications — Must Have· Master’s degree in Cybersecurity, Information Security, Information Assurance, or a related field with a cybersecurity specialization.
· At least 1–2 years of practical experience in GRC, information-security auditing, cybersecurity compliance, risk management, internal controls, regulatory compliance, or information-security consulting.
· Knowledge of Saudi cybersecurity, data governance, or compliance regulations; or international standards such as ISO 27001, NIST, SOC 2, PCI DSS, ISO 22301, or CIS Controls.
· Ability to interpret regulations, control requirements, and audit findings and convert them into system or process requirements.
· Experience preparing business and functional documentation, including user stories, BRDs, workflows, requirements specifications, and acceptance criteria.
· Strong analytical, problem-solving, stakeholder-management, and communication skills.
· Understanding of SaaS product lifecycles and Agile/Scrum methodologies.
· Ability to work independently in a remote, cross-functional environment.
Nice to Have· Experience using or implementing a GRC platform.
· Exposure to risk assessments, control testing, audit management, policy management, business continuity, incident management, or third-party risk management.
· Familiarity with ServiceNow GRC, RSA Archer, MetricStream, OneTrust, LogicGate, or similar platforms.
· Relevant certifications such as ISO 27001 Lead Implementer/Lead Auditor, CISA, CRISC, CISM, or COBIT.
· Experience supporting Saudi-based organizations or Saudi regulatory compliance programs.
· Experience creating compliance dashboards, management reports, and audit-ready documentation.
· Arabic proficiency is an advantage.
Click on Apply to know more.