Consultant –GRC

CPX

Abu Dhabi

On-site

AED 180,000 - 240,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CPX in Abu Dhabi is seeking a Consultant – Cyber Consulting Services to support governance, risk, and compliance, information security initiatives for a government regulatory entity and its regulated sector, aligning with ADHICS and UAE requirements.

You will work under senior guidance to develop policies, perform risk assessments, support audits, and help raise the organization’s information security maturity in healthcare.

Qualifications

  • Minimum 5 years in governance, risk, compliance, and information security.
  • Experience in UAE healthcare sector or healthcare regulatory environment preferred.
  • Bachelor’s degree in information technology, cybersecurity, CS, risk management, business administration, or related field.

Responsibilities

  • Develop, implement, and maintain information security policies, standards, procedures, guidelines, and templates aligned to ADHICS and ISO/IEC 27001.
  • Assist assessments and evidence gathering, document control effectiveness against standards and regulatory requirements.
  • Support risk management program including risk assessments, risk registers, and treatment actions.
  • Assist internal and external information security audits and assessments, preparing documentation and evidence.
  • Coordinate with internal functions and regulatory bodies on information security matters and incidents; follow up on actions.
  • Support awareness, training, and GRC documentation; report progress and deviations to senior consultants.

Skills

GRC processes
Risk assessment methods
Compliance monitoring
Stakeholder communication

Education

Bachelor’s degree in IT / Cybersecurity / CS
Related fields like Risk Management

Job description

The Consultant – Cyber Consulting Services is responsible for supporting the delivery, implementation, and monitoring of Governance, Risk and Compliance (GRC) and Information Security initiatives for a leading government regulatory entity and its regulated sector. Working under the guidance of senior consultants and the engagement lead, the role holder executes assigned GRC and Information Security tasks, contributes to the development and maintenance of policies, risk assessments, compliance activities, and audit support, and helps improve the Information Security maturity of the organization and its wider regulated sector. Operating within a healthcare regulatory environment, the role requires alignment of day-to-day deliverables with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and applicable UAE regulatory requirements.

Key Responsibilities:

Support the development, implementation, and maintenance of Information Security policies, standards, procedures, guidelines, and templates for the organization and its regulated sector, aligned to legal, regulatory, and international best practices, including the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and ISO/IEC 27001.

Execute assigned compliance management activities and assessments under guidance; help gather evidence, assess operational capabilities, and document compliance and control effectiveness levels against applicable standards and regulatory requirements.

Support the Information Security Risk Management Program for the organization and its regulated sector by conducting risk assessments, maintaining risk registers, and tracking treatment actions under the direction of senior consultants, helping manage Information Assurance, Information Security, and Cyber Security risks.

Support internal and external Information Security audits and assessments for the organization and its regulated sector by preparing documentation, collating evidence, and tracking findings through to closure under the guidance of senior consultants.

Support coordination with internal business functions, sector stakeholders, and regulatory bodies on Information Security matters, deviations, exemptions, and incidents, ensuring timely and accurate follow-up on assigned actions.

Support awareness, training, and outreach activities; prepare and maintain accurate GRC documentation, trackers, and reports; and report progress, deviations, and issues on assigned tasks to senior consultants and the engagement lead.

Skills/Certifications (Technical & Non-Technical) :

Working understanding of GRC processes, control frameworks, risk assessment methods, and compliance monitoring practices, with the ability to execute assigned tasks accurately under guidance. Working knowledge of, or demonstrable exposure to, the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard, together with familiarity with UAE healthcare regulatory and information security requirements, is required. Preferred certifications: ISO/IEC 27001 Lead Implementer or Lead Auditor; Certified in Risk and Information Systems Control (CRISC); Certified Information Systems Auditor (CISA); Certified Information Systems Security Professional (CISSP) or equivalent. Foundational certifications (e.g., ISO/IEC 27001 Foundation, CompTIA Security+) are advantageous.

Risk-Based Thinking; Policy and Documentation; Analytical Skills; Time and Task Management; Stakeholder Communication; Team Collaboration; Attention to Detail; Willingness to Learn; Integrity and Confidentiality.

Minimum Work Experience & Education :

Minimum of 5 years of experience in governance, risk, compliance, and Information Security, including exposure to cybersecurity, technology risk, regulatory compliance, or audit support activities. A demonstrable portion of this experience should be within the UAE healthcare sector or a healthcare regulatory environment, with hands‑on exposure to implementing, assessing, or supporting compliance against the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard.

Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business Administration, or a related field.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Consultant- GRC
Lead Consultant- GRC

CPX • Abu Dhabi

On-site
AED 300,000 - 460,000
Manager - GRC
Manager - GRC

CPX • Abu Dhabi

On-site
AED 350,000 - 480,000
Healthcare GRC & InfoSec Consultant (ADHICS)
Healthcare GRC & InfoSec Consultant (ADHICS)

CPX • Abu Dhabi

On-site
AED 180,000 - 240,000
Senior Consultant Information Security GRC
Senior Consultant Information Security GRC

Paramount Computer Systems • Dubai

On-site
AED 300,000 - 600,000
Senior Consultant – Information Security (GRC)
Senior Consultant – Information Security (GRC)

Paramount Computer Systems • Dubai

On-site
AED 300,000 - 420,000
Senior Consultant – Information Security (GRC)
Senior Consultant – Information Security (GRC)

Paramount Computer System • Dubai

On-site
AED 350,000 - 500,000
Senior GRC & Information Security Delivery Lead
Senior GRC & Information Security Delivery Lead

CPX • Abu Dhabi

On-site
AED 300,000 - 460,000
Cybersecurity Consultant
Cybersecurity Consultant

Mada Media • Dubai

On-site
AED 300,000 - 600,000
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services
Security Manager – Orient | Group Tech &Dig Platforms | Corporate Services

Jobsatdubai • Dubai

On-site
AED 334,800 - 502,200
Cybersecurity Consultant
Cybersecurity Consultant

Dubai Careers - A Smart Dubai Initiative • Dubai

On-site
AED 300,000 - 420,000