About this role
Location: remote.
Years of Experience: 8-10 years.
Project Duration: 2 years.
Language Requirements: Fluency in Arabic & English (written and spoken).
We are seeking a Senior Cybersecurity Risk & Resilience Consultant with 8–10 years of experience to deliver cybersecurity and technology risk assessments and advise on risks across systems, cloud environments, digital initiatives, and third-party services. The consultant will manage risk registers, treatment plans, and exception processes; strengthen risk management frameworks; and provide clear reporting to senior stakeholders. The role requires knowledge of NCA ECC, SAMA requirements, and ISO 27001.
Key Requirements
- 8–10 total years of experience.
- Proven experience in cybersecurity risk and resilience consulting.
- Strong experience conducting cybersecurity and technology risk assessments across systems, digital services, cloud environments, and technology projects.
- Hands-on experience managing risk registers and the full risk lifecycle , including assessment, treatment, acceptance, exceptions, and ongoing monitoring.
- Experience developing and tracking risk treatment and remediation plans , including evaluation of control gaps and compensating controls.
- Ability to advise on risks related to infrastructure, cloud security, third parties, secure software development, and data protection .
- Experience developing or improving cybersecurity risk frameworks, methodologies, risk appetite statements, and key risk indicators (KRIs) .
- Knowledge of applicable frameworks and regulations, particularly NCA ECC, SAMA requirements, and ISO 27001 .
Key Responsibilities
- Assist with planning and delivering Risk & Resilience engagements in line with approved methodologies, project plans, and timelines.
- Perform cybersecurity, technology, and enterprise risk assessments covering customer systems, platforms, digital services, and technology initiatives, as well as regulatory-driven assessments, including NCA compliance activities, and ad hoc risk reviews.
- Create, maintain, and improve risk registers, tracking risks from identification and assessment through treatment, acceptance, and ongoing monitoring.
- Develop, track, and report on risk treatment plans, mitigation initiatives, and remediation activities to support timely closure of identified risks and control gaps.
- Coordinate risk acceptance and exception management processes, including impact assessments, evaluation of compensating controls, stakeholder engagement, approvals, and periodic revalidation.
- Assess major technology changes, cloud deployments, digital transformation initiatives, third-party services, and strategic projects to identify emerging risks and recommend appropriate risk responses.
- Deliver risk advisory services across enterprise infrastructure, cloud security, cybersecurity controls, secure software development, digital platforms, data protection, and emerging technologies.
- Help maintain and continuously improve the customer’s cybersecurity risk management framework, methodologies, standards, templates, and governance processes.
- Contribute to developing and periodically updating cybersecurity risk strategies, risk roadmaps, risk appetite statements, and risk mitigation priorities in alignment with business objectives.
- Work with business, technology, cybersecurity, and project teams to offer actionable risk recommendations and enable informed, risk-based decisions.
- Track key risk indicators (KRIs), risk trends, emerging threats, and overdue remediation actions, providing insights for proactive risk management.
- Prepare and present risk reports, dashboards, management updates, and executive-level insights to relevant stakeholders and governance forums.
- Encourage a risk-aware culture through stakeholder engagement, awareness activities, workshops, and advisory sessions across customer business units.
- Ensure alignment with applicable internal policies, regulatory requirements, and industry standards, including NCA ECC, SAMA requirements, ISO 27001, and other relevant frameworks.
---
If you would like to know more about the Global Consulting Bootcamp Visit: https://caseinpointco.com/global-consultant-bootcamp/
If you would like to know more about the MC Club Visit: https://menaconsultant.com/mc-club/