Senior Cybersecurity Risk & Resilience Consultant

Posted 4hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior cybersecurity risk consultant assessing technology, cloud, and third-party risks. Strengthening risk frameworks and advising stakeholders on resilience, compliance, and remediation.

Responsibilities:

  • Assist with planning and delivering Risk & Resilience engagements in line with approved methodologies, project plans, and timelines
  • Perform cybersecurity, technology, and enterprise risk assessments covering customer systems, platforms, digital services, technology initiatives, regulatory-driven assessments, NCA compliance activities, and ad hoc risk reviews
  • Create, maintain, and improve risk registers throughout the full risk lifecycle
  • Develop, track, and report on risk treatment plans, mitigation initiatives, and remediation activities
  • Coordinate risk acceptance and exception management processes, including impact assessments, compensating controls, stakeholder engagement, approvals, and revalidation
  • Assess technology changes, cloud deployments, digital transformation initiatives, third-party services, and strategic projects for emerging risks
  • Deliver risk advisory services across infrastructure, cloud security, cybersecurity controls, secure software development, digital platforms, data protection, and emerging technologies
  • Improve cybersecurity risk management frameworks, methodologies, standards, templates, and governance processes
  • Contribute to cybersecurity risk strategies, roadmaps, risk appetite statements, and mitigation priorities
  • Work with business, technology, cybersecurity, and project teams to provide actionable recommendations
  • Track KRIs, risk trends, emerging threats, and overdue remediation actions
  • Prepare and present risk reports, dashboards, management updates, and executive-level insights
  • Promote a risk-aware culture through stakeholder engagement, awareness activities, workshops, and advisory sessions
  • Ensure alignment with internal policies, regulatory requirements, and industry standards

Requirements:

  • 8–10 total years of experience
  • Proven experience in cybersecurity risk and resilience consulting
  • Strong experience conducting cybersecurity and technology risk assessments across systems, digital services, cloud environments, and technology projects
  • Hands-on experience managing risk registers and the full risk lifecycle, including assessment, treatment, acceptance, exceptions, and ongoing monitoring
  • Experience developing and tracking risk treatment and remediation plans, including evaluation of control gaps and compensating controls
  • Ability to advise on risks related to infrastructure, cloud security, third parties, secure software development, and data protection
  • Experience developing or improving cybersecurity risk frameworks, methodologies, risk appetite statements, and key risk indicators (KRIs)
  • Knowledge of NCA ECC, SAMA requirements, and ISO 27001
  • Fluency in Arabic and English, written and spoken

Benefits:

  • 2-year project engagement
  • Global Consulting Bootcamp information provided
  • MC Club information provided