Senior GRC & IT Audit
Job Description

Senior GRC & IT Audit Consultant

Job Description

 

The Senior GRC & IT Audit Consultant leads cybersecurity governance, risk management, compliance, and IT audit engagements for clients across various industries.

The role is responsible for assessing cybersecurity maturity, identifying and mitigating risks, ensuring compliance with regulatory and industry standards, and providing strategic advisory services to strengthen clients' security posture.

The consultant works closely with stakeholders to deliver high-quality assessments, audits, and recommendations that align cybersecurity initiatives with business objectives.

Key Responsibilities

· Lead cybersecurity governance, risk management, compliance, and IT audit engagements.

· Conduct cybersecurity and IT risk assessments, gap analyses, and maturity assessments.

· Develop and review cybersecurity policies, standards, and governance frameworks.

· Perform IT and information security audits, evaluate controls, and provide remediation recommendations.

· Lead compliance assessments against frameworks and regulations such as ISO 27001, NIST CSF, NCA ECC, SAMA, GDPR, and PCI DSS.

· Maintain risk registers, monitor remediation plans, and support enterprise risk management initiatives.

· Support incident response governance, post-incident reviews, and regulatory reporting requirements.

· Prepare executive reports, dashboards, audit reports, and customer deliverables.

· Build strong client relationships, provide trusted security advisory services, and present findings to senior management.

· Mentor junior consultants and contribute to the continuous improvement of GRC and audit methodologies.

· Lead ITSM implementation and process improvement aligned with ISO/IEC 20000 and ITIL best practices.

· Conduct ITSM assessments and support ISO/IEC 20000 readiness and compliance.

Skills and Qualifications:

  • In-depth knowledge of routing and switching and security technologies is required.
  • Baseline Systems Engineering skills in at least one of the following areas of specialization: Security, Unified Communications, and Wireless.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Minimum 4–6 years of experience in Cybersecurity GRC, IT Audit, Information Security, or Cybersecurity Consulting.
  • Professional certifications such as CISA, CRISC, CISSP, CISM, or ISO 27001 Lead Auditor/Implementer are preferred.
  • Strong knowledge of cybersecurity frameworks and regulations, including ISO 27001, NIST CSF, NCA ECC, SAMA, GDPR, PCI DSS, and COBIT.
  • Experience with GRC platforms, IT audit methodologies, and cybersecurity technologies.
  • Excellent analytical, communication, stakeholder management, and report-writing skills.
  • Fluency in English is required; Arabic and/or French is an advantage.

 

APPLY NOW

Want to stay in the
know?

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.