Direct message the job poster from VaporVM
Saudi National GRC Consultant
We are seeking a highly skilled Saudi National GRC Consultant to support the Governance, Risk & Compliance (GRC) initiatives for one of EY’s key clients in Riyadh. The selected candidate will play a critical role in strengthening the organization’s ISO 27001 : 2022 Information Security Management System (ISMS) , ensuring ongoing compliance, maintaining documentation, and supporting audit readiness.
Key Responsibilities
- Develop, review, and update ISMS policies, procedures, standards, and governance documentation.
- Ensure alignment of all documentation and processes with ISO 27001 : 2022 controls and best practices.
- Drive continuous improvement across ISMS implementations.
- Conduct and support periodic risk assessments , update risk registers, and maintain security‑related documentation.
- Manage ISMS records, logs, and evidence repositories to support control validation.
- Lead and support the organization in internal and external ISO 27001 audits .
- Coordinate with internal teams, external auditors, and stakeholders to provide required evidence and responses.
- Ensure full compliance with ISO control requirements.
Reporting & Governance
Prepare professional governance materials including audit summaries, compliance tracking sheets, and provide continuous visibility to leadership on ISMS performance and risks.Technical Advisory
Provide technical input and guidance on firewall and network security solutions.WAF, load balancers, and SIEM technologies.Collaborate with technical teams to validate controls, review configurations, and ensure security compliance.Candidate Requirements
Minimum 8+ years of experience in Cybersecurity, GRC, and ISMS implementations.Demonstrated expertise in implementing, managing, and maintaining ISO 27001 frameworks.Strong background in security documentation, governance activities, and audit support.Solid understanding of firewalls, WAF, SIEM platforms, and network security components.Hands‑on experience with Windows & Linux server environments.Knowledge of cloud security principles across major cloud providers (Azure / AWS / GCP).Seniority level : Mid‑Senior level
Employment type : Full‑time
Job function : Information Technology
Industries : IT Services and IT Consulting
#J-18808-Ljbffr