الوصف الوظيفي
وصف الوظيفة:
المتخصص في الحوكمة والمخاطر والامتثال (GRC) مسؤول عن الإشراف على حوكمة أمن المعلومات وإدارة المخاطر والامتثال في جامعة الإمارات العربية المتحدة للعلوم والبحوث (UAEU). كونه يتيح لمسؤول أمن المعلومات، يضمن هذا الدور الالتزام بالمتطلبات التنظيمية والسياسات المؤسسية والمعايير الدولية، مع دعم تقييم المخاطر وتخطيط التخفيف واستعداد التدقيق. يشمل المنصب identificación وتحليل والإبلاغ عن فجوات التوافق، وتنسيق التدقيقات الداخلية والخارجية، وتقديم توصيات قابلة للتنفيذ لتحسين وضع المخاطر في الجامعة. يتطلب الدور معرفة عميقة بإطارات العمل التنظيمية، ومنهجيات إدارة المخاطر، وأفضل ممارسات الامتثال، مع التركيز على دمج الحوكمة في عمليات تكنولوجيا المعلومات والأعمال، والحفاظ على الشفافية التشغيلية، وتحسين موقف الأمن السيبراني والامتثال في UAEU باستمرار. • دعم مدير أمن المعلومات في تنفيذ وصيانة إطار GRC في UAEU متوافق مع ISO/IEC 27001:2022، ومعايير الإمارات للأمن السيبراني الحكومية، واللوائح الحكومية المطبقة. • تطوير ومراجعة وتحديث سياسات وأسس وإجراءات وتوجيهات أمن المعلومات والحوكمة والامتثال. • إجراء تقييمات مخاطر الأمن المعلوماتي وتكنولوجيا المعلومات والعمليات والحفاظ على سجل المخاطر. • متابعة الامتثال للسياسات الداخلية ولوائح الأمن السيبراني الإماراتية وقانون حماية البيانات الإماراتي والمعايير الدولية. • تنسيق ودعم التدقيقات الداخلية والخارجية، والتأكد من أن الأدلة والوثائق تفي بالمتطلبات التنظيمية والمعيارية. • متابعة نتائج التدقيق وخطط التخفيف من المخاطر والت actions التصحيحية لضمان الإغلاق في الوقت المناسب. • إجراء تقييمات مخاطر الجهات الثالثة والموردين، ومراجعة العقود، ومراقبة الامتثال المستمر. • تقديم توصيات قابلة للتنفيذ للإدارة حول معالجة المخاطر وفجوات الامتثال وتحسين الحوكمة. • تيسير الوعي بـ GRC والتعليم والتدريب للموظفين وأصحاب المصلحة. • إجراء تقييمات فجوات الرقابة والتوصية بخطط تصحيح عملية. • إعداد تقارير الامتثال والمخاطر والحوكمة الدوربة لمدير أمن المعلومات والإدارة العليا والهيئات التنظيمية. • التعاون مع وحدات تقنية المعلومات والأمن والأعمال لدمج ممارسات الحوكمة وإدارة المخاطر والامتثال في العمليات. • إجراء مراقبة مستمرة لتغيرات التنظيمات والمعايير لتحديث السياسات والعمليات وفقاً لذلك. • التأكد من أن عمليات UAEU متوافقة مع المتطلبات القانونية والتعاقدية والتنظيمية. • تعزيز التحسن المستمر في وضع الحوكمة وإدارة المخاطر والامتثال في UAEU. • أداء أية واجبات أو مسؤوليات إضافية تتعلق بـ GRC كما يوكلها مدير أمن المعلومات أو الإدارة.
المؤهلات الدنيا:
درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني
الخبرة/المهارات:
3+ سنوات في دور مماثل.
المؤهلات المفضلة:
درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني
Job description
Job Description:
The GRC (Governance, Risk, and Compliance) Specialist is responsible for overseeing UAEU’s information security governance, risk management, and compliance activities. Acting as a key enabler for the Information Security Manager, this role ensures adherence to regulatory requirements, institutional policies, and international standards, while supporting risk assessment, mitigation planning, and audit readiness. The position involves identifying, analyzing, and reporting on compliance gaps, coordinating internal and external audits, and providing actionable recommendations to improve the University’s risk posture. The role requires in-depth knowledge of regulatory frameworks, risk management methodologies, and best compliance practices, with a focus on embedding governance into IT and business processes, maintaining operational transparency, and continuously enhancing UAEU’s cybersecurity and compliance posture. • Support the Information Security Manager in implementing and maintaining UAEU’s GRC framework aligned with ISO/IEC 27001:2022, UAE IA Standards, and applicable government regulations. • Develop, review, and update information security, governance, and compliance policies, standards, procedures, and guidelines. • Conduct information security, IT, and operational risk assessments and maintain the risk register. • Monitor compliance with internal policies, UAE cybersecurity regulations, UAE Data Protection Law, and international standards. • Coordinate and support internal and external audits, ensuring evidence and documentation meet regulatory and standard requirements. • Track and follow up on audit findings, risk mitigation plans, and corrective actions to ensure timely closure. • Conduct third-party and vendor risk assessments, review contracts, and monitor ongoing compliance. • Provide actionable recommendations to management on risk treatment, compliance gaps, and governance improvements. • Facilitate GRC awareness, education, and training programs for staff and stakeholders. • Conduct control gap assessments and recommend practical remediation plans • Prepare periodic compliance, risk, and governance reports for the Information Security Manager, senior management, and regulatory bodies. • Collaborate with IT, security, and business units to embed governance, risk management, and compliance practices into processes. • Perform continuous monitoring of regulatory and standards changes to update policies and processes accordingly. • Ensure that UAEU’s operations maintain alignment with legal, contractual, and regulatory requirements. • Promote continuous improvement of UAEU’s governance, risk management, and compliance posture. • Perform any additional duties or responsibilities related to GRC as assigned by the Information Security Manager or management.
Minimum Qualifications:
Bachelor’s degree in computer science, Information Technology, Cybersecurity
Experience/Skills:
3+ years in a similar role.
Preferred Qualifications:
Bachelor’s degree in computer science, Information Technology, Cybersecurity