Direct message the job poster from VaporVM
Saudi National GRC Consultant We are seeking a highly skilled
Saudi National GRC Consultant
to support the Governance, Risk & Compliance (GRC) initiatives for one of EY’s key clients in Riyadh. The selected candidate will play a critical role in strengthening the organization’s
ISO 27001 : 2022 Information Security Management System (ISMS) , ensuring ongoing compliance, maintaining documentation, and supporting audit readiness.
Key Responsibilities
Develop, review, and update ISMS policies, procedures, standards, and governance documentation.
Ensure alignment of all documentation and processes with
ISO 27001 : 2022
controls and best practices.
Drive continuous improvement across ISMS implementations.
Conduct and support periodic
risk assessments , update risk registers, and maintain security‑related documentation.
Manage ISMS records, logs, and evidence repositories to support control validation.
Lead and support the organization in
internal and external ISO 27001 audits .
Coordinate with internal teams, external auditors, and stakeholders to provide required evidence and responses.
Ensure full compliance with ISO control requirements.
Reporting & Governance
Prepare professional governance materials including audit summaries, compliance tracking sheets, and provide continuous visibility to leadership on ISMS performance and risks.
Technical Advisory
Provide technical input and guidance on firewall and network security solutions.
WAF, load balancers, and SIEM technologies.
Collaborate with technical teams to validate controls, review configurations, and ensure security compliance.
Candidate Requirements
Minimum 8+ years of experience in Cybersecurity, GRC, and ISMS implementations.
Demonstrated expertise in implementing, managing, and maintaining ISO 27001 frameworks.
Strong background in security documentation, governance activities, and audit support.
Solid understanding of firewalls, WAF, SIEM platforms, and network security components.
Hands‑on experience with Windows & Linux server environments.
Knowledge of cloud security principles across major cloud providers (Azure / AWS / GCP).
Seniority level : Mid‑Senior level
Employment type : Full‑time
Job function : Information Technology
Industries : IT Services and IT Consulting
#J-18808-Ljbffr
Grc Consultant • Riyadh, Saudi Arabia