The consultant will perform cybersecurity and technology risk assessments while managing risk registers and treatment plans across cloud and digital environments. They will also provide advisory services to stakeholders and ensure compliance with regulatory frameworks like NCA ECC and SAMA.
The consultant will manage third-party risks across the vendor lifecycle, including due diligence, ongoing monitoring, and remediation tracking. They will collaborate with cross-functional teams to evaluate cybersecurity, operational, and compliance risks while maintaining risk registers and governance documentation.
The consultant will operate and enhance a centralized GRC request intake platform using ServiceNow and Archer. They will design automated workflows, integrate AI-powered classification, and manage service performance metrics across risk and compliance functions.
The consultant will assess and validate the effectiveness of cybersecurity controls against regulatory requirements, security frameworks, and MBSS. They will also manage compliance evidence, support audits, and develop technical reports, dashboards, and policies to ensure ongoing organizational compliance.
The consultant will develop and improve the organization's cybersecurity governance framework, strategy, and policies while managing the control library. They are also responsible for facilitating policy exception processes and providing governance reporting to senior management.