Turn this role into an interview — a resume and cover letter built around what this employer wants.
Tanqeeb is seeking an experienced Cybersecurity Compliance / GRC Consultant to support a 12-week client engagement in Dubai. The role centers on NIST SP 800-171 and CMMC Level 2, reviewing the client’s controls, policies, and configurations to identify gaps and craft a practical remediation roadmap.
You will work onsite in Dubai for the full engagement, collaborating with client stakeholders to document findings and propose target-state controls and a roadmap for readiness.
Location: Dubai, UAE – Onsite
Duration: 12 Weeks
Engagement: Contract / Full-time onsite
Resources: 1–2
We are looking for an experienced Cybersecurity Compliance / GRC Consultant to support a 12-week client engagement in Dubai.
The consultant will conduct a cybersecurity assessment and gap analysis of the client's IT environment, with a primary focus on NIST SP 800-171 and CMMC Level 2 requirements. The role will involve reviewing existing security controls, policies, procedures, and technical configurations, identifying gaps, and developing a practical roadmap for remediation and future compliance readiness.
The environment includes approximately 4 systems and 60–80 servers.
Conduct cybersecurity and compliance gap assessments.
Assess alignment with NIST SP 800-171 and CMMC Level 2 requirements.
Review security controls, policies, procedures, and technical configurations.
Identify security gaps, risks, and remediation requirements.
Review infrastructure, access control, vulnerability management, logging, incident response, and configuration management.
Prepare assessment findings and documentation.
Develop a target-state remediation and compliance roadmap.
Work directly with client stakeholders during discovery and assessment.
Support discussions regarding potential cybersecurity engineering and remediation activities.
3+ years of experience in cybersecurity, GRC, security assessment, compliance, or infrastructure security.
Hands‑on experience with NIST SP 800-171, NIST SP 800-53, CMMC, or similar frameworks.
Experience conducting cybersecurity gap, compliance, or readiness assessments.
Strong understanding of enterprise infrastructure and security controls.
Experience preparing security assessment documentation and remediation recommendations.
Strong communication and client‑facing skills.
Willingness to work onsite in Dubai for the full 12-week engagement.
CMMC Registered Practitioner (RP), CMMC Certified Assessor (CCA), or relevant CMMC training.
Experience with DoD contractors or CUI environments.
Experience with NIST 800-171A, SSPs, POA&Ms, or SPRS.
Experience across Windows/Linux, cloud, network, and enterprise security environments.
Previous cybersecurity consulting or client‑facing assessment experience.
This engagement is focused on cybersecurity gap analysis, discovery, and target-state planning. The client is not currently undergoing a formal CMMC assessment.
Relevant NIST / CMMC / cybersecurity assessment experience