Lead Consultant- GRC

CPX Piceance

Abu Dhabi

On-site

AED 180,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CPX Piceance is seeking a Lead Consultant – Cyber Consulting Services to own the governance, risk and compliance initiatives for a UAE government-regulated healthcare sector, aligning with ADHICS and UAE requirements. This senior individual-contributor and delivery-lead role sets technical direction, enforces standards, and acts as the senior client liaison.

You will guide consultants, mentor juniors, drive risk management programs, and orchestrate audits and continuous improvement across the

Qualifications

  • Minimum 9 years in governance, risk, compliance, and Information Security with UAE healthcare exposure.
  • Proven experience leading GRC workstreams and delivering quality deliverables.
  • Bachelor's degree in IT/cybersecurity; Master's preferred.

Responsibilities

  • Own end-to-end delivery of GRC and InfoSec workstreams for the client.
  • Define and enforce information security policies, standards and templates.
  • Lead Information Security risk management and coordinate with assurance programs.
  • Drive compliance initiatives and lead security audits with stakeholders.
  • Mentor consultants and guide junior team members; train delivery staff.

Skills

GRC leadership
Information Security
ADHICS
Regulatory compliance
Risk management
Stakeholder management
Mentoring
Policy & documentation

Education

Bachelor's degree in IT / Cybersecurity / CS
Master's degree preferred

Tools

ISO/IEC 27001 knowledge
ADHICS Standard knowledge
ERM / IRM tools

Job description

Job Purpose

The Lead Consultant – Cyber Consulting Services is a senior individual-contributor and delivery-lead role responsible for owning and driving the definition, enforcement, and monitoring of Governance, Risk and Compliance (GRC) and Information Security initiatives for a leading government regulatory entity and its regulated sector. The role holder leads GRC workstreams end-to-end, sets the technical direction and quality standards for deliverables, and acts as the senior point of contact with the client and regulatory stakeholders. Operating within a healthcare regulatory environment, the role ensures compliance with, and continuous improvement of, the Information Security maturity of the organization and its wider regulated sector in alignment with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and applicable UAE regulatory requirements. The role holder is expected to independently plan and execute programs, guide and quality-assure the work of consultants, and mentor junior team members, without carrying full people-management accountability.



Key Responsibilities


  • Own and lead the end-to-end delivery of assigned GRC and Information Security workstreams for the organization and its regulated sector, acting as the senior point of contact with the client and regulatory stakeholders. Plan and sequence activities, set technical direction and quality standards for deliverables, manage workstream risks, dependencies, and timelines, and ensure that milestones are met and outcomes exceed stakeholder expectations

  • Lead the development, implementation, and continuous improvement of Information Security policies, standards, procedures, guidelines, and templates for the organization and its regulated sector, aligned to legal, regulatory, and international best practices, including the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and ISO/IEC 27001.

  • Lead and mature the Information Security Risk Management Program for the organization and its regulated sector; drive risk identification, assessment, treatment, and monitoring, and coordinate with mission assurance programs to manage Information Assurance, Information Security, and Cyber Security risks, escalating significant risks with clear remediation recommendations.

  • Define and execute compliance management initiatives and lead Information Security audits for the organization and its regulated sector. Establish measures to assess operational capabilities, determine compliance and control effectiveness levels, and coordinate audits with internal and external agencies, tracking findings through to closure.

  • Serve as a senior liaison with internal business functions, local and international sector stakeholders, and regulatory bodies on Information Security matters, deviations, exemptions, and incidents, ensuring timely, well-informed, and professionally represented engagement on behalf of the organization.

  • Guide, review, and quality-assure the work of consultants and junior team members within assigned workstreams, providing technical direction, coaching, and constructive feedback. Mentor junior staff to foster growth and a healthy delivery culture, and support resource and knowledge-sharing across the team, without carrying full line-management accountability.

  • Provide expert advisory by reviewing contracts, MoUs, agreements, and documents, and represent Information Security on relevant committees and forums. Define and report performance, deviations, challenges, and risks with remedial proposals, and elevate matters to the Information and Cyber Security Office Leadership as required.



Skills/Certifications (Technical & Non-Technical)


  • Advanced understanding of GRC processes, control frameworks, risk assessment methods, and compliance monitoring practices, with a proven ability to lead workstreams and quality-assure deliverables.

  • In-depth, working knowledge of the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and its application, together with familiarity with UAE healthcare regulatory and information security requirements, is mandatory.

  • Preferred certifications: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Information Systems Auditor (CISA); Certified in Risk and Information Systems Control (CRISC); ISO/IEC 27001 Lead Implementer or Lead Auditor; ISO 31000 Risk Manager or equivalent; Certified in the Governance of Enterprise IT (CGEIT).

  • Workstream and Delivery Leadership

  • Risk-Based Thinking

  • Quality Assurance and Review

  • Policy and Documentation

  • Analytical Skills

  • Stakeholder and Expectation Management

  • Mentoring and Coaching

  • Communication

  • Attention to Detail

  • Integrity and Confidentiality



Minimum Work Experience & Education

Minimum of 9 years of experience in governance, risk, compliance, and Information Security, including demonstrable experience leading GRC workstreams or teams and quality-assuring deliverables. A substantial and demonstrable portion of this experience must be within the UAE healthcare sector or a healthcare regulatory environment, and must include cybersecurity, technology risk, regulatory compliance, or audit management activities, along with hands-on experience implementing, assessing, or advising against the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard.


Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business Administration, or a related field. A Master's degree or relevant postgraduate qualification is preferable.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Consultant- GRC
Lead Consultant- GRC

CPX • Abu Dhabi

On-site
AED 300,000 - 460,000
Consultant GRC
Consultant GRC

CPX Piceance • Abu Dhabi

On-site
AED 250,000 - 450,000
Consultant –GRC
Consultant –GRC

CPX • Abu Dhabi

On-site
AED 180,000 - 240,000
Manager - GRC
Manager - GRC

CPX • Abu Dhabi

On-site
AED 350,000 - 480,000
Director - Cyber Consulting Services
Director - Cyber Consulting Services

CPX • Abu Dhabi

On-site
AED 420,000 - 660,000
Director - Cyber Consulting Services (CPX)
Director - Cyber Consulting Services (CPX)

Showcify, Inc. • Abu Dhabi

On-site
AED 800,000 - 1,100,000
Director - Cyber Consulting Services CPX
Director - Cyber Consulting Services CPX

CPX • Abu Dhabi

Hybrid
AED 600,000 - 1,000,000
Information Security Consultant / Expert – GRC | 12–15+ Years | Sharjah, UAE
Information Security Consultant / Expert – GRC | 12–15+ Years | Sharjah, UAE

Dautom • United Arab Emirates

On-site
AED 180,000 - 300,000
GRC Consultant
GRC Consultant

Paramount Computer Systems • Dubai

On-site
AED 240,000 - 420,000
Junior GRC Consultant
Junior GRC Consultant

Paramount Computer Systems • Dubai

On-site
AED 120,000 - 180,000