F

Cybersecurity Risk Management Consultant

Futurate

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
10+ yrs
Salary
Openings
1
Posted
1 മണിക്കൂർ മുൻപ്
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Overview

We are seeking an experienced Cybersecurity Risk Management Consultant to join our team in Riyadh, Saudi Arabia. This role involves overseeing governance, risk, and compliance aspects of cybersecurity, focusing on third-party risk management aligned with National Cybersecurity Authority (NCA) standards.

Key Responsibilities

  • Perform thorough third-party risk assessments for current and prospective vendors following NCA Cybersecurity Controls and Takamol criteria.
  • Analyze third-party cybersecurity policies, governance frameworks, procedures, and security controls implemented by vendors.
  • Evaluate vendor adherence to NCA regulations, identifying any cybersecurity compliance deficiencies.
  • Determine risk levels by assessing the impact and probability associated with compliance gaps.
  • Compile comprehensive risk assessment reports outlining methodology, findings, risk evaluations, and suggestions for enhancement.
  • Create a prioritized action plan recommending remediation steps to address discovered gaps and bolster compliance.
  • Present the results and proposed improvements to relevant stakeholders, facilitating clarification discussions as needed.
  • Provide assessment evidence, documentation, and working papers supporting internal audit findings and demonstrating adherence to NCA mandates.
  • Monitor and verify the implementation of corrective measures with responsible risk owners to ensure risks are mitigated adequately prior to closure.

Candidate Requirements

  • At least 10 years of professional experience in cybersecurity governance, risk management, and compliance.
  • Proven knowledge of NCA cybersecurity controls and third-party cybersecurity standards.
  • Hands-on expertise in conducting Third-Party Risk Assessments (TPRA) and Vendor Risk Management (VRM) processes.
  • Background evaluating vendor cybersecurity governance, policies, procedures, and technical safeguards.
  • Experience performing compliance gap analyses relative to regulatory and cybersecurity frameworks.
  • Relevant certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor or similar credentials.
  • Demonstrated experience working within large enterprises or regulated environments.

Industry

Cybersecurity

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help