The consultant will develop and improve the organization's cybersecurity governance framework, strategy, and policies while managing the control library. They are also responsible for facilitating policy exception processes and providing governance reporting to senior management.
Location: remote. Years of Experience: 8-10 years. Project Duration: 2 years. Language Requirements: Fluency in Arabic & English (written and spoken).
We are seeking a Senior Cybersecurity Governance Consultant to develop and improve the organization’s cybersecurity governance framework, strategy, roadmap, policies, and standards. The role will manage the cybersecurity control library and Minimum Baseline Security Standards (MBSS), coordinate policy approvals and exception processes, and maintain documentation for audits and regulatory reviews. The consultant will work across business and technical teams and provide governance reporting and insights to senior management.
Key Requirements
Strong experience developing and improving cybersecurity governance frameworks, strategies, and roadmaps.
Experience drafting, reviewing, and managing approval cycles for cybersecurity policies, standards, procedures, and guidelines.
Experience developing and maintaining a cybersecurity control library aligned with regulatory and business requirements.
Familiarity with Minimum Baseline Security Standards (MBSS), including reviewing and updating baseline requirements and templates.
Experience managing policy exceptions, waivers, and risk acceptance processes, including documentation and periodic review.
Ability to maintain governance records and supporting evidence for audits, assessments, and regulatory reviews.
Experience developing governance KPIs, KRIs, dashboards, and executive reports.
Experience coordinating governance work with infrastructure, legal, quality, and business stakeholders.
Key Responsibilities
Facilitate policy exception management processes and ensure approved exceptions, waivers, and risk acceptance requests are documented, monitored, reviewed, and managed in accordance with governance requirements.
Develop, implement, maintain, and continuously improve the organization's cybersecurity governance framework, strategy, roadmap, and related initiatives.
Develop, review, update, and manage approval cycles for cybersecurity policies, standards, frameworks, procedures, guidelines, and governance artifacts.
Develop, maintain, and manage the Cybersecurity Control Library to ensure alignment with governance, regulatory, and business requirements.
Review and manage updates to Minimum Baseline Security Standards (MBSS), including template development and continuous enhancement.
Ensure cybersecurity governance documentation, deliverables, records, and supporting artifacts are maintained and readily available for audits, assessments, and regulatory reviews.
Prepare governance reports, dashboards, presentations, and executive briefings for senior management, governance committees, and key stakeholders.
Develop, monitor, report, and improve cybersecurity governance Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs).
Facilitate engagement and coordination with Infrastructure, Quality, Legal, Business Units, and other stakeholders during the development, review, and approval of governance artifacts.
Manage governance-related communications, consultations, clarifications, and coordination activities across internal stakeholders.
Support awareness and communication initiatives related to cybersecurity governance, policies, standards, controls, and organizational responsibilities.
Drive continuous improvement initiatives to enhance cybersecurity governance eUectiveness, compliance posture, and organizational maturity.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”