Job Description
Roles & Responsibilities
Deliver cybersecurity and technology risk consulting engagements across various industries.
Conduct cybersecurity and technology risk assessments covering applications, infrastructure, cloud environments, and business processes. Ability to develop risks, controls, compliance requirements and implementation guidance
Ability to review regulatory circulars, notices, standards and guidelines and identify applicable technology and cybersecurity obligations
Perform cybersecurity governance, compliance, maturity, and control effectiveness assessments against industry standards and regulatory requirements.
Assess and enhance governance structures, risk management frameworks, and cybersecurity operating models.
Develop and review cybersecurity policies, standards, procedures, and supporting governance documentation.
Support clients in establishing and improving compliance monitoring, risk management, and assurance programs.
Conduct gap assessments and develop remediation roadmaps aligned with leading frameworks and regulations.
Support resilience initiatives including business continuity, disaster recovery, and operational resilience assessments.
Identify risks, evaluate controls, analyze findings, and provide practical recommendations to improve security and risk posture.
Develop detailed reports, executive presentations, and management summaries tailored to both technical and business audiences.
Facilitate stakeholder workshops, interviews, and working sessions with technology, security, risk, and business teams.
Manage multiple engagements, ensuring timely delivery, quality assurance, and adherence to leading practices.
Mentor and coach junior team members, contributing to capability development and knowledge sharing across the practice.
Stay updated on emerging cyber threats, technology trends, regulatory changes, and industry best practices
Desired Candidate Profile
To qualify for the role, you must have
A bachelor's or master’s degree in information technology, cyber security etc.
Excellent communication skills with a consulting mindset.
3-8 years of experience in cybersecurity, technology risk, IT risk, compliance, governance, resilience, or consulting services
A valid passport for travel.
Excellent communication skills with a consulting mindset.
Ideally, you’ll also have
Industry-recognized certifications such as CISSP, CRISC, CISM ISO 27001 LA/LI
Experience working with GRC platforms (e.g., Archer, ServiceNow GRC etc.).
Familiarity with cloud security, privacy, operational resilience, or third-party risk management programs
Experience supporting clients in highly regulated sectors such as financial services or government
Knowledge of regional frameworks and regulations within the Middle East