GRC Consultant

CyberA Solutions

Dubai

On-site

AED 420,000 - 660,000

Full time

12 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CyberA Solutions is seeking a focused security professional to lead ISO 27001 and UAE compliance engagements for mid-market clients. You will manage scoping through audit and serve as the day-to-day security contact on vCISO retainers.

In this role you’ll chair governance meetings, present to management, and work with engineering to validate/implement Microsoft 365 security controls. Dubai-based visa sponsorship available.

Qualifications

  • 3-5 years in information security roles with at least 2 years delivering GRC or compliance work
  • Personally delivered at least one full-cycle engagement on ISO 27001 or a comparable framework
  • Practical command of risk assessment methodology and control implementation
  • Working technical familiarity with enterprise identity and endpoint environment to validate controls
  • Fluent spoken and written English; strong report writing and client presenting skills
  • Comfortable travelling to client sites in the UAE and based in Dubai on CyberA-sponsored visa

Responsibilities

  • Lead ISO 27001 and UAE compliance engagements from scoping to audit
  • Act as day-to-day security point of contact on vCISO retainers
  • Chair client governance meetings and present to management
  • Configure or validate Microsoft 365 security controls when needed
  • Produce client-ready deliverables: policies, procedures, risk registers, SOAs and assessment reports
  • Contribute to proposals, scoping and effort estimation
  • Manage two to three engagements in parallel with clear progress updates

Skills

Information security
GRC
Risk assessment
English proficiency

Education

ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM, or Microsoft SC-series certification

Tools

Entra ID
Intune
Defender

Job description

You will lead ISO 27001 and UAE compliance engagements for mid-market clients from scoping to audit, and act as the day-to-day security point of contact on vCISO retainers. There is real room to run here: within a few months you'll be chairing client governance meetings and presenting to management on CyberA's behalf. And you won't stop at the paperwork — when a control needs configuring in a client's Microsoft 365 tenant, you can do it yourself or validate it with the engineering team.

What you will do
Role summary

You will lead ISO 27001 and UAE compliance engagements for mid-market clients from scoping to audit, and act as the day-to-day security point of contact on vCISO retainers. There is real room to run here: within a few months you'll be chairing client governance meetings and presenting to management on CyberA's behalf. And you won't stop at the paperwork — when a control needs configuring in a client's Microsoft 365 tenant, you can do it yourself or validate it with the engineering team.

What you will do
  • Deliver ISO/IEC 27001:2022 readiness and certification-support engagements end to end: scoping, gap and risk assessment, ISMS documentation, control implementation tracking, internal audit, and certification audit support.
  • Assess clients against UAE and regional frameworks (UAE IA, ADHICS, PDPL, DESC ISR, CBUAE, NCA ECC, SAMA CSF) and produce gap reports and prioritised remediation roadmaps.
  • Serve as the security point of contact on vCISO engagements: governance meetings, policy reviews, awareness programmes, management and board reporting.
  • Translate framework controls into technical requirements, validate implementation with the Security Engineer, and configure or verify Microsoft 365 security controls (Entra ID, Intune, Defender) when the engagement calls for it.
  • Produce client-ready deliverables: policies, procedures, risk registers, Statements of Applicability, assessment reports, executive summaries.
  • Contribute to proposals, scoping and effort estimation, and to CyberA's internal control mappings and methodologies.
  • Run two to three engagements in parallel and keep clients informed on progress, risks and dependencies.
Qualifications
REQUIRED
  • 3-5 years in information security roles, with at least 2 years delivering GRC or compliance work
  • Personally delivered at least one full-cycle engagement on ISO 27001 or a comparable framework (NCA ECC, SAMA CSF, NIST CSF, CIS Controls, SOC 2), from gap assessment through audit or certification
  • Practical command of risk assessment methodology and control implementation, not documentation alone
  • Working technical familiarity with an enterprise identity and endpoint environment (Active Directory, Entra ID, GCP or AWS IAM, Intune or equivalent) sufficient to validate controls and read configurations
  • Fluent spoken and written English; strong report writing and confident presenting to client management
  • Comfortable working across several clients at once and travelling to client sites in the UAE
  • Willing to be based in Dubai on a CyberA-sponsored visa
PREFERRED
  • Direct experience with UAE frameworks: UAE IA, ADHICS, PDPL, DESC ISR, CBUAE
  • Hands-on Entra ID, Intune or Defender administration; familiarity with the Microsoft 365 Business Premium security baseline
  • ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM, or Microsoft SC-series certification
  • Consultancy or MSSP background serving multiple clients simultaneously
  • Exposure to Acronis, WatchGuard or Fortinet, SIEM or MDR services
  • Arabic speaking
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Consultant - ISO 27001 & UAE Compliance Lead
GRC Consultant - ISO 27001 & UAE Compliance Lead

CyberA Solutions • Dubai

On-site
AED 420,000 - 660,000
Director - Cyber Consulting Services (CPX)
Director - Cyber Consulting Services (CPX)

Showcify, Inc. • Abu Dhabi

On-site
AED 800,000 - 1,100,000
Consultant GRC
Consultant GRC

Cpx Affiliate • Abu Dhabi

On-site
AED 180,000 - 300,000
Director - Cyber Consulting Services CPX
Director - Cyber Consulting Services CPX

CPX • Abu Dhabi

Hybrid
AED 600,000 - 1,000,000
Manager - Cyber Consulting Services CPX
Manager - Cyber Consulting Services CPX

CPX • Abu Dhabi

On-site
AED 300,000 - 520,000
Lead Consultant- GRC
Lead Consultant- GRC

Cpx Affiliate • Abu Dhabi

On-site
AED 350,000 - 550,000
Director - Cyber Consulting Services
Director - Cyber Consulting Services

CPX • Abu Dhabi

On-site
AED 420,000 - 660,000
Lead Consultant- GRC
Lead Consultant- GRC

CPX • Abu Dhabi

On-site
AED 300,000 - 460,000
Manager - Cyber Consulting Services (CPX)
Manager - Cyber Consulting Services (CPX)

Showcify, Inc. • Abu Dhabi

On-site
AED 300,000 - 460,000
Consultant –GRC
Consultant –GRC

CPX • Abu Dhabi

On-site
AED 180,000 - 240,000